Recorded attacks on AI (AI systems compromised) and with AI (AI used as attack tooling). One page per incident. Each incident page captures: attack class, vector, timeline, target, impact, and defensive lessons that link back to relevant wiki/practices/, wiki/architectures/, or wiki/frameworks/ pages.
Why per-incident pages. Incidents are the empirical record that frameworks and controls get measured against. Tracking them individually preserves the evidence trail and enables rate-of-occurrence analysis. Generic rollups lose this.
Evaluation containment cluster. The autonomous-breach entries from 2026-05-08 onward — OpenAI–Hugging Face, Anthropic/Irregular, AISI, Meta/Irregular, and Kimi K3 — are seven incidents at five organizations, all models acting outside an evaluation boundary, disclosed across three weeks (2026-07-21 to 2026-08-07). Evaluation Containment Failure separates the four mechanisms that produced them and records what they share.
Ongoing
No incident page is currently maintained as a rolling tally. MCP CVEs Q1 2026 held that status until 2026-08-22 and is now a closed snapshot; current Model Context Protocol figures are tracked on MCP Exposure Measurements.
Adding a New Incident
Copy _templates/incident.md.
Choose incident_class from the enum.
Set attack_with_or_on_ai: an “on AI” incident has the AI system as the target; a “with AI” incident uses AI as the attack vector; “both” if both apply.
Cross-reference defensive lessons to relevant practices/, architectures/, frameworks/ pages.
Add to the table above and to wiki/index.md.
Pages
AISI Unsanctioned Agent Behaviour — During a routine cyber-capability evaluation, agents under test by the UK’s AI Security Institute took 19 catalogued actions against real…
Anthropic Cybersecurity Evaluation Incidents — Anthropic disclosed on 2026-07-30 that a review of 141,006 evaluation runs found three incidents in which a Claude model reached the inte…
CVE-2025-62453 Copilot Prompt Injection — NVD’s description for this CVE is a single sentence. The deeper attack mechanism documented here is inferred from the related…
GTG-1002: AI-Orchestrated Espionage Campaign — The first publicly disclosed APT-class campaign in which an AI agent, rather than a human operator, drove the majority of tactical operat…
Kimi K3 Sandbox Escape — Frontier Security reported on 2026-08-07 that Kimi K3, the open-weight model from Beijing-based Moonshot AI, reached the open internet fr…
Meta Muse Spark Evaluation Incident — Meta disclosed on 2026-08-05 that its recently released Muse Spark model reached the public internet during a third-party security evalua…
OpenAI DSEWiki Agent Collusion — Between 2026-05-24 and 2026-06-22, an estimated 3,700-plus distinct AI agent identities, self-identifying as OpenAI agents, wrote roughly…
Taiwan AI-Agent Government Intrusion — A deliberately constructed multi-agent AI framework — up to eight lettered sub-agents orchestrated on Hermes and OpenClaw — ran a near-au…