id,name,date_disclosed,status,confidence,category,severity,actor,actor_type,autonomy_level,ai_role,model_families,guardrail_bypass,mitre_atlas,mitre_attack,cve,countries,sectors,geo_points amazon-q-developer-extension-compromise,Amazon Q Developer VS Code extension compromise (data-wiping prompt injection),2025-07-23,confirmed,primary,infrastructure-abuse-supply-chain,high,lkmanka58,single-operator,not-applicable,significant,other,indirect-prompt-injection,AML.T0051; AML.T0081,,CVE-2025-8217,,, anthropic-cyber-evals-real-target-incidents,"Anthropic cybersecurity-evaluation agents reached real third-party systems (four incidents, 2026)",2026-07-30,confirmed,primary,autonomous-attack,high,"Anthropic evaluation agents (Claude Opus 4.7, Claude Mythos 5, an early Claude Opus 4.6 checkpoint and an internal research model) acting outside their intended scope during cybersecurity evaluations",lab-test-eval,fully-autonomous,load-bearing,claude,none-observed,,,,,technology, camoleak-github-copilot-chat,CamoLeak — GitHub Copilot Chat prompt-injection data exfiltration,2025-10-08,reported,primary,agent-hijack-prompt-injection,critical,Omer Mayraz (Legit Security),researcher,not-applicable,load-bearing,other,indirect-prompt-injection,AML.T0051.001; AML.T0057,,,,, clawhavoc-clawhub-malicious-skills,ClawHavoc: large-scale poisoning of the OpenClaw ClawHub skill marketplace with credential-stealing skills,2026-02-01,confirmed,primary,infrastructure-abuse-supply-chain,high,Unknown (operators identified only by ClawHub handles; financially motivated per Antiy CERT),cybercriminal,not-applicable,incidental,other,legitimate-tool-abuse,,,,,technology, clinejection-cline-triage-npm-publish,Clinejection: prompt injection of Cline's Claude issue-triage workflow led to an unauthorized npm release,2026-02-09,confirmed,primary,agent-hijack-prompt-injection,high,"Unknown (an ""unauthorized party"" per Cline; the researcher states a different actor reused his proof-of-concept)",unknown,not-applicable,significant,claude,indirect-prompt-injection,,,,,technology, coral-sleet-agentic-ai-workflow,Coral Sleet (North Korea) operationalizes agentic AI tools across its attack workflow,2026-03-06,reported,primary,ai-orchestrated-campaign,medium,"Coral Sleet (North Korean state actor, formerly Storm-1877, per Microsoft Threat Intelligence)",nation-state,unknown,significant,other,jailbreak; legitimate-tool-abuse,,,,,,origin:sponsor-attribution:KP dprk-it-worker-fraud-claude,North Korean IT-worker remote-employment fraud using Claude,2025-08-27,confirmed,primary,infrastructure-abuse-supply-chain,high,North Korean operatives (DPRK IT workers),nation-state,tool-assisted,significant,claude,legitimate-tool-abuse,,,,US,technology,origin:sponsor-attribution:KP; target:victim-location:US echoleak-m365-copilot,EchoLeak — zero-click prompt injection in Microsoft 365 Copilot,2025-06-11,confirmed,primary,agent-hijack-prompt-injection,critical,Aim Labs (Aim Security),researcher,not-applicable,load-bearing,openai-gpt,indirect-prompt-injection,AML.T0051.001; AML.T0057,,CVE-2025-32711,,, forcedleak-salesforce-agentforce,ForcedLeak — indirect prompt injection in Salesforce Agentforce,2025-09-25,reported,primary,agent-hijack-prompt-injection,critical,Noma Security (Noma Labs),researcher,not-applicable,load-bearing,other,indirect-prompt-injection,AML.T0051.001; AML.T0057,,,,, grok-bankr-prompt-injection-wallet-drain,Prompt injection of Grok drained a Grok-linked crypto wallet via the Bankr trading agent,2026-05-04,reported,secondary,agent-hijack-prompt-injection,medium,Unknown,unknown,not-applicable,load-bearing,other,indirect-prompt-injection,,,,,financial-services, gtg-10007-agent-swarm-intrusions,GTG-10007 Claude 'agent swarm' espionage and vulnerability-discovery program,2026-09-10,confirmed,primary,ai-orchestrated-campaign,high,"Chinese-speaking operators (tracked by Anthropic as GTG-10007), two identified as university undergraduates; no state sponsorship asserted",unknown,supervised-autonomous,load-bearing,claude,legitimate-tool-abuse,,,,CN,education; retail; energy; technology; healthcare; financial-services; government; manufacturing, gtg-1002-ai-espionage,GTG-1002 AI-orchestrated cyber-espionage campaign,2025-11-13,confirmed,primary,ai-orchestrated-campaign,high,Chinese state-sponsored group (tracked by Anthropic as GTG-1002),nation-state,supervised-autonomous,load-bearing,claude,jailbreak; legitimate-tool-abuse,AML.T0054; AML.T0102; AML.T0053,,,,technology; financial-services; chemical-manufacturing; government,origin:sponsor-attribution:CN gtg-20006-agentic-espionage,"GTG-20006 agentic espionage against government, defense and diplomatic targets (Russia-nexus)",2026-09-10,confirmed,primary,ai-orchestrated-campaign,high,Russia-nexus espionage actor (tracked by Anthropic as GTG-20006; attribution described as consistent with public reporting on Midnight Blizzard),nation-state,supervised-autonomous,significant,claude,legitimate-tool-abuse,,,,UA,government; defense; hospitality, gtg-2002-vibe-hacking-extortion,GTG-2002 'vibe hacking' AI-driven data-extortion operation,2025-08-27,confirmed,primary,ai-orchestrated-campaign,high,Unknown cybercriminal (tracked by Anthropic as GTG-2002),cybercriminal,supervised-autonomous,load-bearing,claude,legitimate-tool-abuse,AML.T0053; AML.T0102; AML.T0016.002,,,,government; healthcare; emergency-services; religious-institutions, gtg-50014-agentic-mass-exfiltration,GTG-50014 ShinyHunters-linked agentic mass data theft and extortion,2026-09-10,confirmed,primary,ai-orchestrated-campaign,critical,Suspected ShinyHunters affiliates (tracked by Anthropic as GTG-50014),cybercriminal,supervised-autonomous,load-bearing,claude,unknown,,,,FR,technology; energy; retail; telecommunications; aviation; nonprofit, gtg-50020-ai-vendor-api-key-theft,GTG-50020 autonomous exploitation pipeline against ~30 AI companies and theft of production API keys,2026-09-10,confirmed,primary,infrastructure-abuse-supply-chain,high,"Russian-speaking, financially motivated actor (tracked by Anthropic as GTG-50020)",cybercriminal,fully-autonomous,significant,claude,legitimate-tool-abuse,,,,,technology, gtg-50029-hacktivist-agentic-recon,GTG-50029 single hacktivist's Claude-built mass privacy attack on European political targets,2026-09-10,confirmed,primary,ai-orchestrated-campaign,high,Single French-speaking hacktivist (tracked by Anthropic as GTG-50029),single-operator,human-in-the-loop,significant,claude,legitimate-tool-abuse,,,,,political-parties; media; technology, gtg-5004-ai-ransomware-raas,GTG-5004 AI-assisted ransomware-as-a-service operation,2025-08-27,confirmed,primary,infrastructure-abuse-supply-chain,high,UK-based threat actor (tracked by Anthropic as GTG-5004),single-operator,tool-assisted,significant,claude,legitimate-tool-abuse,AML.T0016.002,,,,,origin:actor-location:GB gtig-ai-developed-zero-day-2fa-bypass,GTIG: criminal actor's AI-developed zero-day exploit against a web-based system administration tool,2026-05-12,reported,primary,ai-orchestrated-campaign,medium,"Unknown criminal threat actor (unnamed by GTIG), in partnership with a prominent cybercrime actor",cybercriminal,tool-assisted,significant,other,unknown,,,,,technology, hackerbot-claw-github-pr-campaign,hackerbot-claw: self-described autonomous 'security research agent' exploiting GitHub Actions across open-source projects,2026-03-01,confirmed,primary,autonomous-attack,medium,Unknown,unknown,unknown,disputed,claude,unknown,,,,,technology, jadepuffer-agentic-database-extortion,JADEPUFFER: agent-driven database extortion operation against an exposed AI-orchestration deployment,2026-07-01,reported,primary,autonomous-attack,high,Unknown,unknown,unknown,significant,other,unknown,,,CVE-2025-3248; CVE-2021-29441,,, miasma-worm-ai-coding-agent-configs,Miasma worm: Azure/durabletask commit weaponized AI coding-agent configuration files; 73 Microsoft repositories disabled,2026-06-05,reported,primary,infrastructure-abuse-supply-chain,high,"TeamPCP (per StepSecurity, via command-and-control infrastructure linked to the same account's earlier PyPI attack; the June commit is not directly attributed)",cybercriminal,not-applicable,significant,claude; gemini; other,indirect-prompt-injection; legitimate-tool-abuse,,,CVE-2026-45321,,technology, microsoft-openai-state-actor-llm,Microsoft/OpenAI disruption of state-affiliated actors misusing LLMs (2024),2024-02-14,confirmed,primary,infrastructure-abuse-supply-chain,medium,"Five state-affiliated actors: Forest Blizzard, Emerald Sleet, Crimson Sandstorm, Charcoal Typhoon, Salmon Typhoon",nation-state,tool-assisted,incidental,openai-gpt,legitimate-tool-abuse,AML.T0016.002,,,,,origin:sponsor-attribution:RU; origin:sponsor-attribution:KP; origin:sponsor-attribution:IR; origin:sponsor-attribution:CN morris-ii-genai-worm,Morris II — self-replicating worm targeting GenAI-powered applications,2024-03-05,test-eval,primary,lab-escape-eval,medium,"Researchers (Cohen, Bitton, Nassi — Technion / Intuit / Cornell Tech)",researcher,not-applicable,load-bearing,openai-gpt; gemini; other,indirect-prompt-injection,AML.T0051.001; AML.T0057,,,,, nx-s1ngularity-supply-chain,Nx 's1ngularity' npm supply-chain attack weaponising AI CLI tools,2025-08-27,confirmed,primary,infrastructure-abuse-supply-chain,critical,Unknown,unknown,tool-assisted,significant,claude; gemini; other,legitimate-tool-abuse,AML.T0053,T1567.001,,,, openai-agent-services-australia-medicare-portal,OpenAI research agent circumvented access controls on Services Australia's Medicare statistics portal,2026-09-24,confirmed,primary,autonomous-attack,medium,OpenAI internal research agent (unnamed model) operating in an internal research/evaluation context,lab-test-eval,fully-autonomous,load-bearing,other,unknown,,,,AU,government; healthcare,target:victim-location:AU openai-eval-agents-hugging-face-intrusion,OpenAI evaluation agents escaped their sandbox and compromised Hugging Face production infrastructure,2026-07-21,confirmed,primary,autonomous-attack,high,OpenAI evaluation agents (an internal-only research model and GPT-5.6 Sol) acting without authorization during ExploitGym cyber evaluations,lab-test-eval,fully-autonomous,load-bearing,openai-gpt; other,none-observed,,,CVE-2026-66384; CVE-2026-53362,,technology, openclaw-inbox-deletion,OpenClaw agent deleted a researcher's emails and ignored stop commands,2026-02-23,reported,secondary,autonomous-attack,low,OpenClaw agent (autonomous),unknown,fully-autonomous,load-bearing,other,none-observed,,,,,, promptflux-gemini-selfmod,PROMPTFLUX — experimental self-modifying malware abusing the Gemini API,2025-11-06,reported,primary,infrastructure-abuse-supply-chain,low,Unknown,unknown,supervised-autonomous,significant,gemini,legitimate-tool-abuse,AML.T0016.002; AML.T0102,,,,, promptlock-ai-ransomware-poc,PromptLock — first known AI-powered ransomware (academic proof-of-concept),2025-08-26,test-eval,primary,lab-escape-eval,medium,NYU Tandon School of Engineering research team,researcher,fully-autonomous,load-bearing,openai-gpt,open-weight-model,AML.T0102; AML.T0016.002,,,,, promptspy-gemini-android-agent,PROMPTSPY — Android backdoor that delegates on-device UI actions to the Gemini API,2026-05-12,confirmed,primary,autonomous-attack,medium,Unknown,unknown,supervised-autonomous,load-bearing,gemini,legitimate-tool-abuse,,,,,, promptsteal-apt28-lamehug,PROMPTSTEAL / LAMEHUG — LLM-enabled data miner used against Ukraine,2025-11-05,confirmed,primary,ai-orchestrated-campaign,high,"APT28 (FROZENLAKE), Russian government-backed",nation-state,supervised-autonomous,load-bearing,qwen,open-weight-model,AML.T0102; AML.T0016.002,,,UA,,origin:sponsor-attribution:RU; target:victim-location:UA replit-agent-database-deletion,Replit AI coding agent deleted a production database during a code freeze,2025-07-21,confirmed,secondary,autonomous-attack,high,Replit AI agent (autonomous),unknown,fully-autonomous,load-bearing,other,none-observed,,,,,technology, servicenow-now-assist-agent-injection,ServiceNow Now Assist agent-to-agent prompt injection (insecure defaults),2025-11-19,reported,primary,agent-hijack-prompt-injection,high,AppOmni (AO Labs),researcher,not-applicable,load-bearing,other,indirect-prompt-injection,AML.T0051.001; AML.T0053; AML.T0057,,,,,