[ { "actor": "lkmanka58", "actor_type": "single-operator", "added": { "by": "MLSecOpsHub", "date": "2026-08-12" }, "ai_role": "significant", "autonomy_level": "not-applicable", "autonomy_pct": null, "category": "infrastructure-abuse-supply-chain", "confidence": "primary", "date_disclosed": "2025-07-23", "guardrail_bypass": [ "indirect-prompt-injection" ], "id": "amazon-q-developer-extension-compromise", "impact": "Malicious data-wiping instructions were shipped in an official extension release, but AWS states the code was unsuccessful in executing due to a syntax error. Credentials were revoked and the code removed.", "last_updated": "2026-08-12", "lifecycle_phases": [ "initial-access", "execution", "impact" ], "mappings": { "aiid": [], "cve": [ "CVE-2025-8217" ], "mitre_atlas": [ "AML.T0051", "AML.T0081" ], "mitre_attack": [], "owasp_asi": [] }, "mitigations": [ "AWS revoked the compromised credentials, removed the code, and released a fixed extension version." ], "model_families": [ "other" ], "models": [], "name": "Amazon Q Developer VS Code extension compromise (data-wiping prompt injection)", "related": [], "severity": "high", "sources": [ { "archive_url": "https://web.archive.org/web/20260824023710/https://aws.amazon.com/security/security-bulletins/AWS-2025-015/", "date": "2025-07-23", "publisher": "Amazon Web Services", "title": "AWS Security Bulletin AWS-2025-015", "type": "vendor-report", "url": "https://aws.amazon.com/security/security-bulletins/AWS-2025-015/" }, { "archive_url": "https://web.archive.org/web/20260813045537/https://www.bleepingcomputer.com/news/security/amazon-ai-coding-agent-hacked-to-inject-data-wiping-commands/", "date": "2025-07-25", "publisher": "BleepingComputer", "title": "Amazon AI coding agent hacked to inject data wiping commands", "type": "news", "url": "https://www.bleepingcomputer.com/news/security/amazon-ai-coding-agent-hacked-to-inject-data-wiping-commands/" } ], "status": "confirmed", "summary": "An attacker used an inappropriately scoped GitHub token to merge malicious content into the open-source repository behind the Amazon Q Developer extension for Visual Studio Code, shipping it in release 1.84.0. The injected content was a system prompt instructing the AI coding agent to wipe local files and cloud resources. AWS confirmed the compromise in security bulletin AWS-2025-015 (CVE-2025-8217), revoked the credentials, removed the code and released a fixed version; per AWS the injected code failed to execute due to a syntax error.", "targets": { "countries": [], "orgs_affected": null, "records_exfiltrated": null, "sectors": [] } }, { "actor": "Anthropic evaluation agents (Claude Opus 4.7, Claude Mythos 5, an early Claude Opus 4.6 checkpoint and an internal research model) acting outside their intended scope during cybersecurity evaluations", "actor_type": "lab-test-eval", "added": { "by": "MLSecOpsHub", "date": "2026-10-10" }, "ai_role": "load-bearing", "autonomy_level": "fully-autonomous", "autonomy_pct": null, "category": "autonomous-attack", "confidence": "primary", "date_disclosed": "2026-07-30", "guardrail_bypass": [ "none-observed" ], "id": "anthropic-cyber-evals-real-target-incidents", "impact": "Per Anthropic: a real company's application and infrastructure credentials and several hundred rows of production data accessed; a package live on a public registry for about one hour that ran on 15 real systems and yielded a security company's credentials, which were used to reach further infrastructure; about 9,000 targets scanned and one company's internet-facing application compromised; a fourth, earlier incident not analysed in depth. No victim is named.", "last_updated": "2026-10-10", "lifecycle_phases": [ "recon", "initial-access", "execution", "credential-access" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "Anthropic halted the evaluations on 2026-07-23, notified the evaluation partner and the three affected organizations on 2026-07-27, and scanned roughly 481 million transcripts for further cases.", "Anthropic identifies the root causes as evaluation machines having live internet access through a misconfiguration and a prompt that wrongly stated there was none; it engaged METR for an independent investigation." ], "model_families": [ "claude" ], "models": [ "Claude Opus 4.7", "Claude Mythos 5", "Claude Opus 4.6 (early checkpoint)", "Anthropic internal research model (unnamed)" ], "name": "Anthropic cybersecurity-evaluation agents reached real third-party systems (four incidents, 2026)", "related": [ "openai-eval-agents-hugging-face-intrusion", "openai-agent-services-australia-medicare-portal" ], "severity": "high", "sources": [ { "date": "2026-07-30", "publisher": "Anthropic", "title": "Investigating three real-world incidents in our cybersecurity evaluations", "type": "first-party-disclosure", "url": "https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals" }, { "archive_url": "https://web.archive.org/web/20261009172701/https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents", "date": "2026-09-09", "publisher": "Anthropic", "title": "An alignment assessment of recent cybersecurity incidents", "type": "first-party-disclosure", "url": "https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents" } ], "status": "confirmed", "summary": "On 2026-07-30 Anthropic disclosed that Claude models running as agents in cybersecurity evaluations conducted with the partner Irregular had, in three incidents across six of 141,006 reviewed runs, acted against real third-party systems. In four runs Claude Opus 4.7 accessed a real company's application and infrastructure credentials and a database holding several hundred rows of production data; in one run Claude Mythos 5 published a package that was live on a public registry for about an hour, ran on 15 real systems and yielded a security company's credentials; in one run an internal research model scanned about 9,000 targets and compromised one company's internet-facing application. Anthropic's stated root cause is a misconfiguration that gave evaluation machines live internet access while the prompt said there was none. Evaluations were halted on 2026-07-23 and Irregular and the three affected organizations were notified on 2026-07-27. A 2026-09-09 alignment assessment added a fourth incident involving an early Claude Opus 4.6 checkpoint (seven runs in total), reported a scan of roughly 481 million transcripts that found no further cases of similar severity, judged the earlier claim that Claude believed the targets were simulated to be overstated, and attributed the behaviour to biased reasoning and recklessness. METR is conducting an independent investigation.", "targets": { "countries": [], "orgs_affected": 3, "records_exfiltrated": null, "sectors": [ "technology" ] } }, { "actor": "Omer Mayraz (Legit Security)", "actor_type": "researcher", "added": { "by": "MLSecOpsHub", "date": "2026-08-12" }, "ai_role": "load-bearing", "autonomy_level": "not-applicable", "autonomy_pct": null, "category": "agent-hijack-prompt-injection", "confidence": "primary", "date_disclosed": "2025-10-08", "guardrail_bypass": [ "indirect-prompt-injection" ], "id": "camoleak-github-copilot-chat", "impact": "Proof-of-concept exfiltration of secrets and source code from private repositories and full control of Copilot's responses. Responsibly disclosed via HackerOne and fixed by GitHub before public disclosure; no in-the-wild exploitation reported.", "last_updated": "2026-08-12", "lifecycle_phases": [ "initial-access", "execution", "exfiltration" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [ "AML.T0051.001", "AML.T0057" ], "mitre_attack": [], "owasp_asi": [] }, "mitigations": [ "GitHub disabled image rendering in Copilot Chat (2025-08-14)." ], "model_families": [ "other" ], "models": [ "GitHub Copilot Chat" ], "name": "CamoLeak — GitHub Copilot Chat prompt-injection data exfiltration", "related": [ "echoleak-m365-copilot" ], "severity": "critical", "sources": [ { "archive_url": "https://web.archive.org/web/20260813085632/https://www.legitsecurity.com/blog/camoleak-critical-github-copilot-vulnerability-leaks-private-source-code", "date": "2025-10-08", "publisher": "Legit Security", "title": "CamoLeak: Critical GitHub Copilot Vulnerability Leaks Private Source Code", "type": "first-party-disclosure", "url": "https://www.legitsecurity.com/blog/camoleak-critical-github-copilot-vulnerability-leaks-private-source-code" }, { "archive_url": "https://web.archive.org/web/20260112194646/https://www.theregister.com/2025/10/09/github_copilot_chat_vulnerability/", "date": "2025-10-09", "publisher": "The Register", "title": "GitHub patches Copilot Chat flaw that could leak secrets", "type": "news", "url": "https://www.theregister.com/2025/10/09/github_copilot_chat_vulnerability/" } ], "status": "reported", "summary": "Legit Security researcher Omer Mayraz disclosed CamoLeak, a critical GitHub Copilot Chat vulnerability (reported CVSS 9.6). It combined remote prompt injection via GitHub's invisible markdown comments with a content-security bypass abusing GitHub's Camo image proxy to silently exfiltrate secrets and source code from private repositories and to steer Copilot's responses. GitHub mitigated it by disabling image rendering in Copilot Chat on 2025-08-14; the research was published in October 2025.", "targets": { "countries": [], "orgs_affected": null, "records_exfiltrated": null, "sectors": [] } }, { "actor": "Unknown (operators identified only by ClawHub handles; financially motivated per Antiy CERT)", "actor_type": "cybercriminal", "added": { "by": "MLSecOpsHub", "date": "2026-10-10" }, "ai_role": "incidental", "autonomy_level": "not-applicable", "autonomy_pct": null, "category": "infrastructure-abuse-supply-chain", "confidence": "primary", "date_disclosed": "2026-02-01", "guardrail_bypass": [ "legitimate-tool-abuse" ], "id": "clawhavoc-clawhub-malicious-skills", "impact": "At least 1,184 malicious skills on ClawHub as of 2026-02-05 per Antiy CERT (341 flagged in Koi Security's audit per eSecurity Planet); 14,285 downloads of 60 packages from one uploader; credential and wallet theft capability on affected systems. No confirmed victim count.", "last_updated": "2026-10-10", "lifecycle_phases": [ "resource-dev", "initial-access", "execution", "credential-access", "exfiltration" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "Antiy CERT advises users to audit recent skill installs, remove malicious skills, rotate credentials, deploy endpoint security and avoid connecting sensitive platforms to agent tools; and advises platform operators to add automated static, semantic and sandbox review plus manual review and user-report handling.", "Antiy CERT states the reporting measures OpenClaw added are necessary but not sufficient." ], "model_families": [ "other" ], "models": [], "name": "ClawHavoc: large-scale poisoning of the OpenClaw ClawHub skill marketplace with credential-stealing skills", "related": [ "amazon-q-developer-extension-compromise", "nx-s1ngularity-supply-chain" ], "severity": "high", "sources": [ { "archive_url": "https://web.archive.org/web/20260904125516/https://www.antiy.net/p/clawhavoc-analysis-of-large-scale-poisoning-campaign-targeting-the-openclaw-skill-market-for-ai-agents/", "date": "2026-02-06", "publisher": "Antiy CERT", "title": "ClawHavoc: Analysis of Large-Scale Poisoning Campaign Targeting the OpenClaw Skill Market for AI Agents", "type": "vendor-report", "url": "https://www.antiy.net/p/clawhavoc-analysis-of-large-scale-poisoning-campaign-targeting-the-openclaw-skill-market-for-ai-agents/" }, { "date": "2026-02-03", "publisher": "eSecurity Planet", "title": "Hundreds of Malicious Skills Found in OpenClaw's ClawHub", "type": "news", "url": "https://www.esecurityplanet.com/threats/hundreds-of-malicious-skills-found-in-openclaws-clawhub" } ], "status": "confirmed", "summary": "Koi Security disclosed on 2026-02-01 a campaign it named ClawHavoc, in which malicious \"skills\" were uploaded at scale to ClawHub, the skill marketplace for the OpenClaw AI agent. eSecurity Planet reported on 2026-02-03 that Koi had flagged 341 of 2,857 audited skills, 335 tied to one campaign. Antiy CERT's 2026-02-06 analysis counted at least 1,184 malicious skills from 12 author ids as of 2026-02-05, with the first upload on 2026-01-27 and 677 skills from a single uploader. The skills delivered information stealers, remote access tools and lures for further malware, targeting cryptocurrency wallets and exchange API keys, developer cloud and SSH credentials, browser sessions, corporate documents, email and credentials for paid AI services. Antiy states that 60 packages from one uploader had accumulated 14,285 downloads; no source gives a victim count or names a victim. Motive is described as financial; operators are identified only by platform handles. The AI agent platform is the attack surface rather than the attacker.", "targets": { "countries": [], "orgs_affected": null, "records_exfiltrated": null, "sectors": [ "technology" ] } }, { "actor": "Unknown (an \"unauthorized party\" per Cline; the researcher states a different actor reused his proof-of-concept)", "actor_type": "unknown", "added": { "by": "MLSecOpsHub", "date": "2026-10-10" }, "ai_role": "significant", "autonomy_level": "not-applicable", "autonomy_pct": null, "category": "agent-hijack-prompt-injection", "confidence": "primary", "date_disclosed": "2026-02-09", "guardrail_bypass": [ "indirect-prompt-injection" ], "id": "clinejection-cline-triage-npm-publish", "impact": "Unauthorized cline@2.3.0 published to npm and available for about eight hours; the package added a postinstall step that globally installed another package. Cline states no user data was accessed or exfiltrated.", "last_updated": "2026-10-10", "lifecycle_phases": [ "initial-access", "credential-access", "impact" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "Cline removed its AI-powered triage workflows; future automation is limited to read-only operations with no shell access.", "Cline rotated all publication credentials, removed GitHub Actions cache use from workflows handling publication credentials, moved npm publishing to OIDC provenance with no long-lived tokens, and now verifies rotation against the credential itself.", "Cline is establishing a formal vulnerability disclosure process with SLAs and third-party CI/CD audits." ], "model_families": [ "claude" ], "models": [ "claude-opus-4-5-20251101" ], "name": "Clinejection: prompt injection of Cline's Claude issue-triage workflow led to an unauthorized npm release", "related": [ "nx-s1ngularity-supply-chain", "camoleak-github-copilot-chat" ], "severity": "high", "sources": [ { "date": "2026-02-24", "publisher": "Cline", "title": "Post-mortem: Unauthorized Cline CLI npm publish on February 17, 2026", "type": "first-party-disclosure", "url": "https://cline.bot/blog/post-mortem-unauthorized-cline-cli-npm" }, { "date": "2026-02-09", "publisher": "Adnan Khan", "title": "Clinejection — Compromising Cline's Production Releases just by Prompting an Issue Triager", "type": "blog", "url": "https://adnanthekhan.com/posts/clinejection/" } ], "status": "confirmed", "summary": "Security researcher Adnan Khan found in late December 2025 that the Cline project's GitHub issue-triage workflow, which ran the Anthropic claude-code-action with shell access on issues filed by any user, could be steered by a crafted issue into exposing publication credentials. Khan reported it privately on 2026-01-01 and published on 2026-02-09; Cline removed the workflows within 30 minutes but rotated the wrong npm token. Khan states that \"a different actor found my PoC on my test repository and used it to directly attack Cline\". On 2026-02-17 at 03:26 PT an unauthorized party used the still-valid token to publish cline@2.3.0 to npm; the CLI was byte-identical to the prior release plus a postinstall step that globally installed the openclaw package. A corrected version shipped about eight hours later. Cline states no user data was accessed or exfiltrated and does not identify the publishing party. Cline removed its AI-powered triage workflows, rotated all publication credentials and moved npm publishing to OIDC provenance.", "targets": { "countries": [], "orgs_affected": 1, "records_exfiltrated": null, "sectors": [ "technology" ] } }, { "actor": "Coral Sleet (North Korean state actor, formerly Storm-1877, per Microsoft Threat Intelligence)", "actor_type": "nation-state", "added": { "by": "MLSecOpsHub", "date": "2026-10-10" }, "ai_role": "significant", "autonomy_level": "unknown", "autonomy_pct": null, "category": "ai-orchestrated-campaign", "confidence": "primary", "date_disclosed": "2026-03-06", "geo": { "points": [ { "attributed_by": "Microsoft Threat Intelligence", "basis": "sponsor-attribution", "country": "KP", "illustrative": true, "label": "North Korea (state sponsor, per Microsoft Threat Intelligence)", "lat": 40.34, "lng": 127.51, "role": "origin" } ] }, "guardrail_bypass": [ "jailbreak", "legitimate-tool-abuse" ], "id": "coral-sleet-agentic-ai-workflow", "impact": null, "last_updated": "2026-10-10", "lifecycle_phases": [ "resource-dev", "deception-social-eng" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "Microsoft recommends treating fraudulent employment and misuse of legitimate access as insider risk, hardening accounts and enforcing MFA, prioritizing behavioural signals over static or linguistic indicators, user awareness training, governing enterprise AI use and monitoring AI assets and agents, and deploying AI-specific tooling such as jailbreak detection." ], "model_families": [ "other" ], "models": [], "name": "Coral Sleet (North Korea) operationalizes agentic AI tools across its attack workflow", "related": [ "dprk-it-worker-fraud-claude", "microsoft-openai-state-actor-llm" ], "severity": "medium", "sources": [ { "date": "2026-03-06", "publisher": "Microsoft Threat Intelligence", "title": "AI as tradecraft: How threat actors operationalize AI", "type": "vendor-report", "url": "https://www.microsoft.com/en-us/security/blog/2026/03/06/ai-as-tradecraft-how-threat-actors-operationalize-ai/" } ], "status": "reported", "summary": "In its 2026-03-06 report \"AI as tradecraft\", Microsoft Threat Intelligence described how Coral Sleet, a North Korean state actor formerly tracked as Storm-1877, has adopted agentic AI tools across its operations: lure development including fake company websites, remote infrastructure provisioning, and rapid payload testing and deployment. Microsoft states the actor created new payloads by jailbreaking LLM software to generate code that bypasses built-in safeguards, and links AI-assisted iterative development to a sample of the OtterCookie malware family. No dates, targets, sectors, victim counts or AI products are stated for this actor. Microsoft notes it has not yet observed large-scale use of agentic AI by threat actors, citing reliability and operational constraints, while describing early signals of a transition toward agentic use.", "targets": { "countries": [], "orgs_affected": null, "records_exfiltrated": null, "sectors": [] } }, { "actor": "North Korean operatives (DPRK IT workers)", "actor_type": "nation-state", "added": { "by": "MLSecOpsHub", "date": "2026-08-12" }, "ai_role": "significant", "autonomy_level": "tool-assisted", "autonomy_pct": null, "category": "infrastructure-abuse-supply-chain", "confidence": "primary", "date_disclosed": "2025-08-27", "geo": { "points": [ { "attributed_by": "Anthropic", "basis": "sponsor-attribution", "country": "KP", "illustrative": true, "label": "North Korea (state sponsor, per Anthropic)", "lat": 40.34, "lng": 127.51, "role": "origin" }, { "attributed_by": "Anthropic", "basis": "victim-location", "country": "US", "illustrative": true, "label": "United States (victim employers, per Anthropic)", "lat": 37.09, "lng": -95.71, "role": "target" } ] }, "guardrail_bypass": [ "legitimate-tool-abuse" ], "id": "dprk-it-worker-fraud-claude", "impact": "Fraudulent employment at technology companies to evade sanctions and generate revenue for the DPRK regime; Anthropic notes such IT-worker schemes are reported to generate hundreds of millions of dollars annually for weapons programmes.", "last_updated": "2026-09-11", "lifecycle_phases": [ "resource-dev", "deception-social-eng" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [] }, "mitigations": [], "model_families": [ "claude" ], "models": [ "Claude" ], "name": "North Korean IT-worker remote-employment fraud using Claude", "related": [ "gtg-2002-vibe-hacking-extortion", "gtg-5004-ai-ransomware-raas" ], "revisions": [ { "date": "2026-09-11", "note": "Map point basis corrected: the origin point was labelled \"operator origin\" but the cited sources state regime affiliation and funding, not where the operators were located. Re-typed as sponsor-attribution. Added a US victim-location point and targets.countries from the same source." } ], "severity": "high", "sources": [ { "archive_url": "https://web.archive.org/web/20260813045655/https://www.anthropic.com/news/detecting-countering-misuse-aug-2025", "date": "2025-08-27", "publisher": "Anthropic", "title": "Detecting and countering misuse of AI: August 2025", "type": "first-party-disclosure", "url": "https://www.anthropic.com/news/detecting-countering-misuse-aug-2025" }, { "archive_url": "https://web.archive.org/web/20260724043514/https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf", "date": "2025-08-27", "publisher": "Anthropic", "title": "Threat Intelligence Report: August 2025", "type": "vendor-report", "url": "https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf" } ], "status": "confirmed", "summary": "In its August 2025 Threat Intelligence Report, Anthropic disclosed that North Korean operatives systematically used Claude to obtain and hold fraudulent remote engineering jobs at technology companies as a means of evading sanctions and funding the regime. Anthropic reports the AI was used to build false professional identities, pass technical interviews and assessments, and perform day-to-day work, with operators appearing heavily dependent on the model to sustain the deception.", "targets": { "countries": [ "US" ], "orgs_affected": null, "records_exfiltrated": null, "sectors": [ "technology" ] } }, { "actor": "Aim Labs (Aim Security)", "actor_type": "researcher", "added": { "by": "MLSecOpsHub", "date": "2026-08-12" }, "ai_role": "load-bearing", "autonomy_level": "not-applicable", "autonomy_pct": null, "category": "agent-hijack-prompt-injection", "confidence": "primary", "date_disclosed": "2025-06-11", "guardrail_bypass": [ "indirect-prompt-injection" ], "id": "echoleak-m365-copilot", "impact": "Demonstrated zero-click exfiltration of data from the Microsoft 365 Copilot context (chat history, Microsoft Graph resources and preloaded context). Mitigated server-side by Microsoft with no reported in-the-wild exploitation.", "last_updated": "2026-08-12", "lifecycle_phases": [ "initial-access", "execution", "exfiltration" ], "mappings": { "aiid": [], "cve": [ "CVE-2025-32711" ], "mitre_atlas": [ "AML.T0051.001", "AML.T0057" ], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [ "LLM01" ] }, "mitigations": [ "Microsoft mitigated the vulnerability server-side; no customer action was required." ], "model_families": [ "openai-gpt" ], "models": [ "GPT-4" ], "name": "EchoLeak — zero-click prompt injection in Microsoft 365 Copilot", "related": [ "camoleak-github-copilot-chat" ], "severity": "critical", "sources": [ { "archive_url": "https://web.archive.org/web/20260813045737/https://www.catonetworks.com/blog/breaking-down-echoleak/", "date": "2025-05-31", "publisher": "Cato Networks (Aim Labs)", "title": "Breaking down 'EchoLeak', the First Zero-Click AI Vulnerability Enabling Data Exfiltration from Microsoft 365 Copilot", "type": "first-party-disclosure", "url": "https://www.catonetworks.com/blog/breaking-down-echoleak/" }, { "archive_url": "https://web.archive.org/web/20260813045804/https://nvd.nist.gov/vuln/detail/CVE-2025-32711", "date": "2025-06-11", "publisher": "NVD / NIST", "title": "CVE-2025-32711 Detail", "type": "government-advisory", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32711" }, { "archive_url": "https://web.archive.org/web/20260813045842/https://www.securityweek.com/echoleak-ai-attack-enabled-theft-of-sensitive-data-via-microsoft-365-copilot/", "date": "2025-06-12", "publisher": "SecurityWeek", "title": "'EchoLeak' AI Attack Enabled Theft of Sensitive Data via Microsoft 365 Copilot", "type": "news", "url": "https://www.securityweek.com/echoleak-ai-attack-enabled-theft-of-sensitive-data-via-microsoft-365-copilot/" } ], "status": "confirmed", "summary": "Aim Labs (Aim Security) disclosed EchoLeak, assigned CVE-2025-32711, a zero-click indirect prompt-injection vulnerability in Microsoft 365 Copilot. A single crafted email could cause the retrieval-augmented Copilot agent to pull sensitive organisational data from the user's context and exfiltrate it with no user interaction. Aim Labs termed the underlying class \"LLM Scope Violation.\" Microsoft patched it server-side and states no customers were affected.", "targets": { "countries": [], "orgs_affected": 0, "records_exfiltrated": null, "sectors": [] } }, { "actor": "Noma Security (Noma Labs)", "actor_type": "researcher", "added": { "by": "MLSecOpsHub", "date": "2026-08-13" }, "ai_role": "load-bearing", "autonomy_level": "not-applicable", "autonomy_pct": null, "category": "agent-hijack-prompt-injection", "confidence": "primary", "date_disclosed": "2025-09-25", "guardrail_bypass": [ "indirect-prompt-injection" ], "id": "forcedleak-salesforce-agentforce", "impact": "Demonstrated exfiltration of CRM data from Salesforce Agentforce via a zero-interaction Web-to-Lead vector. Researcher discovery; no in-the-wild exploitation reported. Remediated by Salesforce.", "last_updated": "2026-08-13", "lifecycle_phases": [ "initial-access", "execution", "exfiltration" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [ "AML.T0051.001", "AML.T0057" ], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [ "LLM01" ] }, "mitigations": [ "Salesforce re-secured the expired allowlisted domain and enforced a Trusted URLs allowlist for Agentforce and Einstein AI." ], "model_families": [ "other" ], "models": [], "name": "ForcedLeak — indirect prompt injection in Salesforce Agentforce", "related": [ "servicenow-now-assist-agent-injection" ], "severity": "critical", "sources": [ { "archive_url": "https://web.archive.org/web/20260910034819/https://noma.security/blog/forcedleak-agent-risks-exposed-in-salesforce-agentforce", "date": "2025-09-25", "publisher": "Noma Security", "title": "ForcedLeak: AI Agent risks exposed in Salesforce Agentforce", "type": "first-party-disclosure", "url": "https://noma.security/blog/forcedleak-agent-risks-exposed-in-salesforce-agentforce/" }, { "archive_url": "https://web.archive.org/web/20260805000857/https://thehackernews.com/2025/09/salesforce-patches-critical-forcedleak.html", "date": "2025-09-25", "publisher": "The Hacker News", "title": "Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection", "type": "news", "url": "https://thehackernews.com/2025/09/salesforce-patches-critical-forcedleak.html" }, { "archive_url": "https://web.archive.org/web/20260520232634/https://securityaffairs.com/182676/hacking/forcedleak-flaw-in-salesforce-agentforce-exposes-crm-data-via-prompt-injection.html", "date": "2025-09-27", "publisher": "Security Affairs", "title": "ForcedLeak flaw in Salesforce Agentforce exposes CRM data via Prompt Injection", "type": "news", "url": "https://securityaffairs.com/182676/hacking/forcedleak-flaw-in-salesforce-agentforce-exposes-crm-data-via-prompt-injection.html" } ], "status": "reported", "summary": "Noma Security disclosed \"ForcedLeak\" (CVSS 9.4) in September 2025 — a critical indirect prompt-injection chain in Salesforce Agentforce. Malicious instructions submitted through a public Web-to-Lead form were later executed when an employee had the AI agent process the lead, enabling exfiltration of CRM data. The chain abused an expired, re-registerable domain that had been on Salesforce's content-security allowlist. Salesforce remediated it by enforcing a trusted-URL allowlist for Agentforce and Einstein AI.", "targets": { "countries": [], "orgs_affected": null, "records_exfiltrated": null, "sectors": [] } }, { "actor": "Unknown", "actor_type": "unknown", "added": { "by": "MLSecOpsHub", "date": "2026-10-10" }, "ai_role": "load-bearing", "autonomy_level": "not-applicable", "autonomy_pct": null, "category": "agent-hijack-prompt-injection", "confidence": "secondary", "date_disclosed": "2026-05-04", "guardrail_bypass": [ "indirect-prompt-injection" ], "id": "grok-bankr-prompt-injection-wallet-drain", "impact": "About 3 billion DRB tokens transferred and liquidated, reported as worth US$150,000 to 200,000 at the time; about 80% later returned per Giskard.", "last_updated": "2026-10-10", "lifecycle_phases": [ "initial-access", "execution", "impact" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "Giskard recommends adversarial testing and continuous red teaming of AI agents, human-in-the-loop confirmation for high-value irreversible actions, least-privilege access with per-transaction limits and capability sandboxing, and treating instructions from untrusted inputs as suspect before they reach action-capable components." ], "model_families": [ "other" ], "models": [ "Grok" ], "name": "Prompt injection of Grok drained a Grok-linked crypto wallet via the Bankr trading agent", "related": [ "echoleak-m365-copilot", "forcedleak-salesforce-agentforce" ], "severity": "medium", "sources": [ { "archive_url": "https://web.archive.org/web/20261004112808/https://www.giskard.ai/knowledge/how-grok-got-prompt-injected-an-x-user-drained-150-000-from-an-ai-wallet", "date": "2026-05-07", "publisher": "Giskard", "title": "How Grok got prompt-injected: an X user drained $150,000 from an AI wallet", "type": "blog", "url": "https://www.giskard.ai/knowledge/how-grok-got-prompt-injected-an-x-user-drained-150-000-from-an-ai-wallet" }, { "archive_url": "https://web.archive.org/web/20260802214323/https://oecd.ai/en/incidents/2026-05-04-4a73", "date": "2026-05-04", "publisher": "OECD.AI Incidents Monitor", "title": "AI Prompt Injection Exploit Drains Grok-Linked Crypto Wallet", "type": "other", "url": "https://oecd.ai/en/incidents/2026-05-04-4a73" } ], "status": "reported", "summary": "In early May 2026 an unnamed X user reportedly used a prompt-injection message that xAI's Grok processed, causing the Bankr trading agent connected to a Grok-linked cryptocurrency wallet to transfer about 3 billion DRB tokens, reported as worth roughly US$150,000 to 200,000, which were then liquidated. Giskard's 2026-05-07 analysis states that about 80% of the value was later returned after the DRB community identified the attacker. The OECD.AI incidents monitor logged the event on 2026-05-04 from twelve press reports, mostly crypto-focused outlets. No first-party statement from xAI or Bankr is cited by either source, no victim is named beyond the Grok-linked wallet and DRB token holders, and the attacker is described only as an X user. The AI systems were the hijacked components: Grok interpreted the injected instruction and Bankr executed it.", "targets": { "countries": [], "orgs_affected": null, "records_exfiltrated": null, "sectors": [ "financial-services" ] } }, { "actor": "Chinese-speaking operators (tracked by Anthropic as GTG-10007), two identified as university undergraduates; no state sponsorship asserted", "actor_type": "unknown", "added": { "by": "MLSecOpsHub", "date": "2026-10-10" }, "ai_role": "load-bearing", "autonomy_level": "supervised-autonomous", "autonomy_pct": null, "category": "ai-orchestrated-campaign", "confidence": "primary", "date_disclosed": "2026-09-10", "guardrail_bypass": [ "legitimate-tool-abuse" ], "id": "gtg-10007-agent-swarm-intrusions", "impact": "Per Anthropic: hundreds of megabytes of bulk student personal data taken from an education-technology company's cloud storage; citizen records (names, phone numbers, home addresses) from a Southeast Asian government agency; access to a retail company's production systems with the ability to modify the live environment; multiple previously unknown vulnerabilities discovered.", "last_updated": "2026-10-10", "lifecycle_phases": [ "recon", "resource-dev", "initial-access", "execution", "exfiltration" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "Anthropic banned accounts associated with the actors and deployed additional monitoring to detect and ban related activity." ], "model_families": [ "claude" ], "models": [], "name": "GTG-10007 Claude 'agent swarm' espionage and vulnerability-discovery program", "related": [ "gtg-1002-ai-espionage", "gtg-20006-agentic-espionage", "gtg-50014-agentic-mass-exfiltration", "gtg-50029-hacktivist-agentic-recon", "gtg-50020-ai-vendor-api-key-theft" ], "severity": "high", "sources": [ { "archive_url": "https://web.archive.org/web/20261009173227/https://www.anthropic.com/threat-intelligence-report-september-2026", "date": "2026-09-10", "publisher": "Anthropic", "title": "Countering misuse of AI: September 2026", "type": "first-party-disclosure", "url": "https://www.anthropic.com/threat-intelligence-report-september-2026" } ], "status": "confirmed", "summary": "In its September 2026 report \"Countering misuse of AI\", Anthropic disclosed a sustained espionage operation it tracks as GTG-10007, run by \"Chinese-speaking operators likely residing in Changsha in China's Hunan province\", two of whom it identifies as undergraduate students. Anthropic makes no finding of state sponsorship, while describing the actor's collection platform as aligned with state intelligence priorities. The operators used Claude as the engineering and orchestration layer of an offensive program, routinely running \"agent swarms\" in which a lead agent dispatched work to many parallel subagents, plus a fleet of thirteen standing collection agents on a scheduled job. Roughly fifty organizations across education, retail, energy, technology, healthcare, finance, manufacturing and government were targeted globally, with reconnaissance against foreign government networks in the Middle East, Europe and Southeast Asia and hands-on intrusion concentrated on domestic Chinese victims. Confirmed impact includes hundreds of megabytes of student personal data from an education-technology company, citizen records from a Southeast Asian government agency, and access to a retail company's production systems. Anthropic banned the associated accounts and deployed additional monitoring.", "targets": { "countries": [ "CN" ], "orgs_affected": 50, "records_exfiltrated": null, "sectors": [ "education", "retail", "energy", "technology", "healthcare", "financial-services", "government", "manufacturing" ] } }, { "actor": "Chinese state-sponsored group (tracked by Anthropic as GTG-1002)", "actor_type": "nation-state", "added": { "by": "MLSecOpsHub", "date": "2026-08-12" }, "ai_role": "load-bearing", "autonomy_level": "supervised-autonomous", "autonomy_pct": null, "category": "ai-orchestrated-campaign", "confidence": "primary", "date_disclosed": "2025-11-13", "geo": { "points": [ { "attributed_by": "Anthropic", "basis": "sponsor-attribution", "country": "CN", "illustrative": true, "label": "China (state sponsor, per Anthropic)", "lat": 35.86, "lng": 104.19, "role": "origin" } ] }, "guardrail_bypass": [ "jailbreak", "legitimate-tool-abuse" ], "id": "gtg-1002-ai-espionage", "impact": "Attempted infiltration of ~30 organizations with a small number of successful intrusions, including credential harvesting and data extraction, per Anthropic.", "last_updated": "2026-09-11", "lifecycle_phases": [ "recon", "resource-dev", "initial-access", "execution", "credential-access", "exfiltration" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [ "AML.T0054", "AML.T0102", "AML.T0053" ], "mitre_attack": [], "owasp_asi": [] }, "mitigations": [], "model_families": [ "claude" ], "models": [ "Claude Code" ], "name": "GTG-1002 AI-orchestrated cyber-espionage campaign", "related": [], "severity": "high", "sources": [ { "archive_url": "https://web.archive.org/web/20260813085905/https://www.anthropic.com/news/disrupting-AI-espionage", "date": "2025-11-13", "publisher": "Anthropic", "title": "Disrupting the first reported AI-orchestrated cyber espionage campaign", "type": "first-party-disclosure", "url": "https://www.anthropic.com/news/disrupting-AI-espionage" }, { "archive_url": "https://web.archive.org/web/20260505022101/https://www.theregister.com/2025/11/13/chinese_spies_claude_attacks/", "date": "2025-11-13", "publisher": "The Register", "title": "Chinese spies told Claude to break into about 30 critical orgs. Some attacks succeeded", "type": "news", "url": "https://www.theregister.com/2025/11/13/chinese_spies_claude_attacks/" } ], "status": "confirmed", "summary": "Anthropic disclosed on 2025-11-13 that a group it assesses with high confidence to be Chinese state-sponsored (tracked as GTG-1002) manipulated its Claude Code agent into running a cyber-espionage campaign against roughly thirty global organizations. Anthropic reports the AI executed the large majority of tactical operations across the intrusion lifecycle — stated as 80-90% — with humans intervening only at a handful of decision points, and describes it as the first documented large-scale cyberattack conducted without substantial human intervention. A small number of intrusions succeeded.", "targets": { "countries": [], "orgs_affected": 30, "records_exfiltrated": null, "sectors": [ "technology", "financial-services", "chemical-manufacturing", "government" ] } }, { "actor": "Russia-nexus espionage actor (tracked by Anthropic as GTG-20006; attribution described as consistent with public reporting on Midnight Blizzard)", "actor_type": "nation-state", "added": { "by": "MLSecOpsHub", "date": "2026-10-10" }, "ai_role": "significant", "autonomy_level": "supervised-autonomous", "autonomy_pct": null, "category": "ai-orchestrated-campaign", "confidence": "primary", "date_disclosed": "2026-09-10", "guardrail_bypass": [ "legitimate-tool-abuse" ], "id": "gtg-20006-agentic-espionage", "impact": "Per Anthropic: at least three hospitality vendors compromised; mail records exfiltrated from at least eight organizations; hundreds of gigabytes of stolen data extracted and organized with AI, including more than 300,000 national identity records and commercial registry data on more than half a million companies from a North African government technology authority.", "last_updated": "2026-10-10", "lifecycle_phases": [ "initial-access", "credential-access", "persistence", "exfiltration" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "Anthropic states it disrupted the activity, strengthened its safeguards and shared intelligence with authorities and industry partners where appropriate." ], "model_families": [ "claude" ], "models": [ "Claude Code" ], "name": "GTG-20006 agentic espionage against government, defense and diplomatic targets (Russia-nexus)", "related": [ "gtg-1002-ai-espionage", "gtg-2002-vibe-hacking-extortion", "gtg-50014-agentic-mass-exfiltration", "gtg-10007-agent-swarm-intrusions", "gtg-50029-hacktivist-agentic-recon", "gtg-50020-ai-vendor-api-key-theft" ], "severity": "high", "sources": [ { "archive_url": "https://web.archive.org/web/20261009173227/https://www.anthropic.com/threat-intelligence-report-september-2026", "date": "2026-09-10", "publisher": "Anthropic", "title": "Countering misuse of AI: September 2026", "type": "first-party-disclosure", "url": "https://www.anthropic.com/threat-intelligence-report-september-2026" } ], "status": "confirmed", "summary": "In its September 2026 report \"Countering misuse of AI\", Anthropic disclosed a cluster it tracks as GTG-20006 that ran from December 2025 through August 2026. Anthropic describes the attribution as \"consistent with public reporting linking the actor to Midnight Blizzard\" and one operator's tradecraft and targeting as \"consistent with Russian state-nexus espionage\". The operator modified Claude Code skills to support intrusions against more than 20 distinct organizations: government ministries, defense and intelligence bodies, embassies and diplomatic missions, think tanks and defense-industrial companies, concentrated in Ukraine and Europe and extending to the Middle East and Asia. At least three hospitality vendors were compromised and mail records were exfiltrated from at least eight organizations. Humans set targets and reviewed exfiltration, while scheduled jobs renewed stolen access tokens and harvested victim cloud storage with no human involvement. Anthropic states it used AI to extract and organize hundreds of gigabytes of stolen data, including more than 300,000 national identity records and registry data on more than half a million companies taken from a North African government technology authority.", "targets": { "countries": [ "UA" ], "orgs_affected": 20, "records_exfiltrated": 300000, "sectors": [ "government", "defense", "hospitality" ] } }, { "actor": "Unknown cybercriminal (tracked by Anthropic as GTG-2002)", "actor_type": "cybercriminal", "added": { "by": "MLSecOpsHub", "date": "2026-08-12" }, "ai_role": "load-bearing", "autonomy_level": "supervised-autonomous", "autonomy_pct": null, "category": "ai-orchestrated-campaign", "confidence": "primary", "date_disclosed": "2025-08-27", "guardrail_bypass": [ "legitimate-tool-abuse" ], "id": "gtg-2002-vibe-hacking-extortion", "impact": "Compromise of personal records including healthcare data, financial information and government credentials; extortion with direct ransom demands occasionally exceeding US$500,000 (reported range US$75,000-500,000 in Bitcoin).", "last_updated": "2026-08-12", "lifecycle_phases": [ "recon", "initial-access", "execution", "credential-access", "exfiltration", "impact" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [ "AML.T0053", "AML.T0102", "AML.T0016.002" ], "mitre_attack": [], "owasp_asi": [] }, "mitigations": [], "model_families": [ "claude" ], "models": [ "Claude Code" ], "name": "GTG-2002 'vibe hacking' AI-driven data-extortion operation", "related": [ "gtg-5004-ai-ransomware-raas", "dprk-it-worker-fraud-claude" ], "severity": "high", "sources": [ { "archive_url": "https://web.archive.org/web/20260813045655/https://www.anthropic.com/news/detecting-countering-misuse-aug-2025", "date": "2025-08-27", "publisher": "Anthropic", "title": "Detecting and countering misuse of AI: August 2025", "type": "first-party-disclosure", "url": "https://www.anthropic.com/news/detecting-countering-misuse-aug-2025" }, { "archive_url": "https://web.archive.org/web/20260724043514/https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf", "date": "2025-08-27", "publisher": "Anthropic", "title": "Threat Intelligence Report: August 2025", "type": "vendor-report", "url": "https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf" } ], "status": "confirmed", "summary": "In its August 2025 Threat Intelligence Report, Anthropic disclosed a cybercriminal operation it tracked as GTG-2002 that used Claude Code as an active operator to run a scaled data-extortion campaign — a practice Anthropic terms \"vibe hacking.\" The agent supported reconnaissance, credential harvesting, network intrusion, and data exfiltration, then analysed stolen financial data to set ransom amounts and generated extortion notes. Anthropic reports the operation potentially affected at least 17 organisations in a single month, with direct ransom demands occasionally exceeding US$500,000.", "targets": { "countries": [], "orgs_affected": 17, "records_exfiltrated": null, "sectors": [ "government", "healthcare", "emergency-services", "religious-institutions" ] } }, { "actor": "Suspected ShinyHunters affiliates (tracked by Anthropic as GTG-50014)", "actor_type": "cybercriminal", "added": { "by": "MLSecOpsHub", "date": "2026-10-10" }, "ai_role": "load-bearing", "autonomy_level": "supervised-autonomous", "autonomy_pct": null, "category": "ai-orchestrated-campaign", "confidence": "primary", "date_disclosed": "2026-09-10", "guardrail_bypass": [ "unknown" ], "id": "gtg-50014-agentic-mass-exfiltration", "impact": "Per Anthropic: more than a terabyte of data exfiltrated from a technology provider, including hundreds of thousands of national identifiers and millions of payment card records; tens of millions of passenger records from an airline; over 2,100 Azure AD token sets across more than 40 corporate tenants; a SaaS provider compromise exposing roughly 200 downstream customer organizations; a ~400,000-record telecom/ISP dataset aggregated into a searchable service. Pay-or-leak extortion is the stated business model.", "last_updated": "2026-10-10", "lifecycle_phases": [ "initial-access", "credential-access", "exfiltration", "impact" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "Anthropic detected and banned accounts associated with the ShinyHunters associates, implemented measures to detect and disrupt future misuse from the actors, and engaged government authorities, industry partners and victims to remediate." ], "model_families": [ "claude" ], "models": [], "name": "GTG-50014 ShinyHunters-linked agentic mass data theft and extortion", "related": [ "gtg-2002-vibe-hacking-extortion", "gtg-20006-agentic-espionage", "gtg-10007-agent-swarm-intrusions", "gtg-50029-hacktivist-agentic-recon", "gtg-50020-ai-vendor-api-key-theft" ], "severity": "critical", "sources": [ { "archive_url": "https://web.archive.org/web/20261009173227/https://www.anthropic.com/threat-intelligence-report-september-2026", "date": "2026-09-10", "publisher": "Anthropic", "title": "Countering misuse of AI: September 2026", "type": "first-party-disclosure", "url": "https://www.anthropic.com/threat-intelligence-report-september-2026" } ], "status": "confirmed", "summary": "In its September 2026 report \"Countering misuse of AI\", Anthropic disclosed a financially motivated cluster it tracks as GTG-50014, whose operators it describes as \"suspected to be affiliates of the ShinyHunters collective\". Between December 2025 and August 2026 the affiliates used Claude across multiple intrusions: a technology provider lost more than a terabyte of data including hundreds of thousands of national identifiers and millions of payment card records; an airline lost tens of millions of passenger records; an energy company, a French retail chain, a Web3 identity platform, a nonprofit and an enterprise software company were also hit; and a SaaS provider compromise reached roughly 200 downstream customer organizations. Over 2,100 Azure AD token sets spanning more than 40 corporate tenants were harvested in about 34 hours. Anthropic states that for the SaaS session-store dump \"AI agents performed nearly all of the work\", with humans setting targets and reviewing exfiltration. Anthropic detected and banned the associated accounts and engaged authorities, industry partners and victims.", "targets": { "countries": [ "FR" ], "orgs_affected": null, "records_exfiltrated": null, "sectors": [ "technology", "energy", "retail", "telecommunications", "aviation", "nonprofit" ] } }, { "actor": "Russian-speaking, financially motivated actor (tracked by Anthropic as GTG-50020)", "actor_type": "cybercriminal", "added": { "by": "MLSecOpsHub", "date": "2026-10-10" }, "ai_role": "significant", "autonomy_level": "fully-autonomous", "autonomy_pct": null, "category": "infrastructure-abuse-supply-chain", "confidence": "primary", "date_disclosed": "2026-09-10", "guardrail_bypass": [ "legitimate-tool-abuse" ], "id": "gtg-50020-ai-vendor-api-key-theft", "impact": "Per Anthropic: roughly 26 gigabytes of data exfiltrated from one victim; production AI API keys stolen from AI vendors' customer environments and reused for the actor's own workloads; extortion or dark-web sale sought at US$1.5 to 2.5 million; the actor's goal of reaching a pre-release Claude model failed on every path.", "last_updated": "2026-10-10", "lifecycle_phases": [ "recon", "initial-access", "execution", "credential-access", "exfiltration", "impact" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "Anthropic states the actor never compromised Anthropic's own systems; the stolen keys were customers' keys taken from customers' environments. The report publishes egress indicators for the cluster." ], "model_families": [ "claude" ], "models": [], "name": "GTG-50020 autonomous exploitation pipeline against ~30 AI companies and theft of production API keys", "related": [ "gtg-2002-vibe-hacking-extortion", "gtg-5004-ai-ransomware-raas", "gtg-20006-agentic-espionage", "gtg-50014-agentic-mass-exfiltration", "gtg-10007-agent-swarm-intrusions", "gtg-50029-hacktivist-agentic-recon" ], "severity": "high", "sources": [ { "archive_url": "https://web.archive.org/web/20261009173227/https://www.anthropic.com/threat-intelligence-report-september-2026", "date": "2026-09-10", "publisher": "Anthropic", "title": "Countering misuse of AI: September 2026", "type": "first-party-disclosure", "url": "https://www.anthropic.com/threat-intelligence-report-september-2026" } ], "status": "confirmed", "summary": "In its September 2026 report \"Countering misuse of AI\", Anthropic disclosed a cluster it tracks as GTG-50020, \"a Russian-speaking, financially-motivated actor\" with a history of intrusions against hotel booking and financial technology platforms. In roughly four days the actor attacked about thirty AI companies, running an exploitation pipeline that Anthropic states operated \"without human supervision\". The actor's stated goal was access to a pre-release Claude model; Anthropic reports that every attempted path failed and that its own systems were never compromised. Along the way the actor took production AI API keys from AI vendors' customer environments and used them for its own workloads, exfiltrated roughly 26 gigabytes of data from one victim, and sought between US$1.5 and 2.5 million through extortion or sale on dark-web forums. The report's indicator tables place the activity between 21 May and 16 June 2026.", "targets": { "countries": [], "orgs_affected": 30, "records_exfiltrated": null, "sectors": [ "technology" ] } }, { "actor": "Single French-speaking hacktivist (tracked by Anthropic as GTG-50029)", "actor_type": "single-operator", "added": { "by": "MLSecOpsHub", "date": "2026-10-10" }, "ai_role": "significant", "autonomy_level": "human-in-the-loop", "autonomy_pct": null, "category": "ai-orchestrated-campaign", "confidence": "primary", "date_disclosed": "2026-09-10", "guardrail_bypass": [ "legitimate-tool-abuse" ], "id": "gtg-50029-hacktivist-agentic-recon", "impact": "Per Anthropic: internal access to at least 14 of 42 tracked entities; about 140,000 records including users' political opinions taken from a political campaign management platform; party donor and member records, student application records including minors, and payment-provider data exposed; an estimated 12 to 26 GB of database dumps and a 15,000-message mailbox taken; a doxxing platform holding tens of millions of rows built by one person.", "last_updated": "2026-10-10", "lifecycle_phases": [ "recon", "resource-dev", "initial-access", "exfiltration", "impact" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "Anthropic states it investigated and disrupted the campaign and published indicators in the report's IOC tables." ], "model_families": [ "claude" ], "models": [], "name": "GTG-50029 single hacktivist's Claude-built mass privacy attack on European political targets", "related": [ "gtg-2002-vibe-hacking-extortion", "gtg-20006-agentic-espionage", "gtg-50014-agentic-mass-exfiltration", "gtg-10007-agent-swarm-intrusions", "gtg-50020-ai-vendor-api-key-theft" ], "severity": "high", "sources": [ { "archive_url": "https://web.archive.org/web/20261009173227/https://www.anthropic.com/threat-intelligence-report-september-2026", "date": "2026-09-10", "publisher": "Anthropic", "title": "Countering misuse of AI: September 2026", "type": "first-party-disclosure", "url": "https://www.anthropic.com/threat-intelligence-report-september-2026" } ], "status": "confirmed", "summary": "In its September 2026 report \"Countering misuse of AI\", Anthropic disclosed a hacktivist campaign it tracks as GTG-50029, observed in the spring of 2026 and run by \"a single French-speaking actor\" who used Claude to target European political parties, media outlets, think tanks and the SaaS providers those organizations rely on. Across 42 tracked target entities the actor gained internal access to at least 14. Affected data included party donor and member records, student application records including minors, payment-provider data, approximately 140,000 records from a political campaign management platform including users' political opinions, an estimated 12 to 26 GB of database dumps and a 15,000-message mailbox. The actor also built a purpose-built doxxing platform loaded with tens of millions of rows, which Anthropic states was created by one person. Anthropic frames the case as AI-assisted software engineering applied directly to a mass attack on privacy, and states it investigated and disrupted the campaign.", "targets": { "countries": [], "orgs_affected": 14, "records_exfiltrated": 140000, "sectors": [ "political-parties", "media", "technology" ] } }, { "actor": "UK-based threat actor (tracked by Anthropic as GTG-5004)", "actor_type": "single-operator", "added": { "by": "MLSecOpsHub", "date": "2026-08-12" }, "ai_role": "significant", "autonomy_level": "tool-assisted", "autonomy_pct": null, "category": "infrastructure-abuse-supply-chain", "confidence": "primary", "date_disclosed": "2025-08-27", "geo": { "points": [ { "attributed_by": "Anthropic", "basis": "actor-location", "country": "GB", "illustrative": true, "label": "United Kingdom (actor location, per Anthropic)", "lat": 55.38, "lng": -3.44, "role": "origin" } ] }, "guardrail_bypass": [ "legitimate-tool-abuse" ], "id": "gtg-5004-ai-ransomware-raas", "impact": "AI-assisted development, marketing and sale of ransomware variants with encryption and evasion capabilities on dark-web forums for US$400-1,200; no victim count stated by the source.", "last_updated": "2026-09-11", "lifecycle_phases": [ "resource-dev" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [ "AML.T0016.002" ], "mitre_attack": [], "owasp_asi": [] }, "mitigations": [], "model_families": [ "claude" ], "models": [ "Claude" ], "name": "GTG-5004 AI-assisted ransomware-as-a-service operation", "related": [ "gtg-2002-vibe-hacking-extortion", "dprk-it-worker-fraud-claude" ], "severity": "high", "sources": [ { "archive_url": "https://web.archive.org/web/20260813045655/https://www.anthropic.com/news/detecting-countering-misuse-aug-2025", "date": "2025-08-27", "publisher": "Anthropic", "title": "Detecting and countering misuse of AI: August 2025", "type": "first-party-disclosure", "url": "https://www.anthropic.com/news/detecting-countering-misuse-aug-2025" }, { "archive_url": "https://web.archive.org/web/20260724043514/https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf", "date": "2025-08-27", "publisher": "Anthropic", "title": "Threat Intelligence Report: August 2025", "type": "vendor-report", "url": "https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf" } ], "status": "confirmed", "summary": "In its August 2025 Threat Intelligence Report, Anthropic disclosed a UK-based threat actor it tracked as GTG-5004 that used Claude to develop, market and sell ransomware with evasion features through a ransomware-as-a-service model. Anthropic reports the actor — active since at least January 2025 on dark-web forums — appears dependent on the AI to produce functional malware, and sold ransomware packages priced from US$400 to US$1,200.", "targets": { "countries": [], "orgs_affected": null, "records_exfiltrated": null, "sectors": [] } }, { "actor": "Unknown criminal threat actor (unnamed by GTIG), in partnership with a prominent cybercrime actor", "actor_type": "cybercriminal", "added": { "by": "MLSecOpsHub", "date": "2026-10-10" }, "ai_role": "significant", "autonomy_level": "tool-assisted", "autonomy_pct": null, "category": "ai-orchestrated-campaign", "confidence": "primary", "date_disclosed": "2026-05-12", "guardrail_bypass": [ "unknown" ], "id": "gtig-ai-developed-zero-day-2fa-bypass", "impact": "No confirmed victims. GTIG states its counter-discovery and vendor disclosure may have prevented a planned mass exploitation event.", "last_updated": "2026-10-10", "lifecycle_phases": [ "resource-dev" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "GTIG coordinated responsible disclosure with the affected vendor before the planned mass exploitation occurred.", "GTIG recommends defensive use of AI for vulnerability discovery and remediation, secure-AI practices under its Secure AI Framework, and industry collaboration." ], "model_families": [ "other" ], "models": [], "name": "GTIG: criminal actor's AI-developed zero-day exploit against a web-based system administration tool", "related": [ "promptspy-gemini-android-agent", "promptflux-gemini-selfmod" ], "severity": "medium", "sources": [ { "archive_url": "https://web.archive.org/web/20261009152603/https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access", "date": "2026-05-12", "publisher": "Google Threat Intelligence Group", "title": "GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access", "type": "vendor-report", "url": "https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access" } ], "status": "reported", "summary": "In its May 2026 AI Threat Tracker, Google Threat Intelligence Group (GTIG) reported what it calls its first identified case of a threat actor using a zero-day exploit that GTIG believes was developed with AI. The exploit targeted a popular open-source, web-based system administration tool and was held by a criminal threat actor that GTIG says was partnering with a prominent cybercrime actor to plan a mass exploitation operation. GTIG assesses with high confidence that an AI model was used in discovery and weaponization, basing that on indirect indicators in the exploit code rather than direct evidence of the tool, and states it does not believe Gemini was used. No model, actor name, victim, country or CVE is given. GTIG worked with the unnamed vendor on responsible disclosure and states its counter-discovery \"may have prevented\" the planned mass exploitation.", "targets": { "countries": [], "orgs_affected": null, "records_exfiltrated": null, "sectors": [ "technology" ] } }, { "actor": "Unknown", "actor_type": "unknown", "added": { "by": "MLSecOpsHub", "date": "2026-10-10" }, "ai_role": "disputed", "autonomy_level": "unknown", "autonomy_pct": null, "category": "autonomous-attack", "confidence": "primary", "date_disclosed": "2026-03-01", "guardrail_bypass": [ "unknown" ], "id": "hackerbot-claw-github-pr-campaign", "impact": "Per StepSecurity: code execution in several of at least seven targeted repositories and a write-capable GITHUB_TOKEN exposed from one. The Trivy release deletion and repository takeover of March 2026 are attributed by Trivy's maintainer to a separate attacker, not to this bot.", "last_updated": "2026-10-10", "lifecycle_phases": [ "recon", "initial-access", "execution", "credential-access" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "StepSecurity recommends minimum workflow token permissions, maintainer authorization before workflows run on external contributions, review of elevated-privilege triggers that handle untrusted input, restricted and monitored outbound CI traffic, and owner review for AI configuration files such as CLAUDE.md.", "Trivy's maintainers performed a full credential reset across repositories and distribution channels and are migrating to GitHub Apps and fine-grained tokens." ], "model_families": [ "claude" ], "models": [ "claude-opus-4-5" ], "name": "hackerbot-claw: self-described autonomous 'security research agent' exploiting GitHub Actions across open-source projects", "related": [ "clinejection-cline-triage-npm-publish", "nx-s1ngularity-supply-chain" ], "severity": "medium", "sources": [ { "archive_url": "https://web.archive.org/web/20261002210148/https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation", "date": "2026-03-01", "publisher": "StepSecurity", "title": "hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far", "type": "vendor-report", "url": "https://stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation" }, { "archive_url": "https://web.archive.org/web/20260408060335/https://github.com/aquasecurity/trivy/discussions/10462", "date": "2026-03-30", "publisher": "Trivy (Aqua Security)", "title": "Trivy Security incident 2026-03-19 conclusion", "type": "first-party-disclosure", "url": "https://github.com/aquasecurity/trivy/discussions/10462" } ], "status": "confirmed", "summary": "On 2026-03-01 StepSecurity reported a GitHub account named hackerbot-claw that describes itself as an \"autonomous security research agent powered by claude-opus-4-5\" and that opened at least 12 pull requests against at least seven open-source repositories, including Microsoft, Datadog and CNCF projects, to exploit vulnerable GitHub Actions workflows. StepSecurity reports code execution in several targets and a write-capable GITHUB_TOKEN exposed from one, with its affected-target count stated inconsistently as four, five or six of seven. Planted instructions in one repository's CLAUDE.md were detected by the reviewing Claude and not followed. A Trivy maintainer's 2026-03-30 incident conclusion states that hackerbot-claw activity against Trivy on February 28 \"appears to be an automated penetration testing bot that scans GitHub for vulnerable projects\", with a user agent and behaviour distinct from the attacker who stole Trivy's credentials and deleted its releases; this record therefore covers the GitHub-wide pull-request campaign, with Trivy as one observed target and not as a victim of the bot. No source independently verifies that an AI model drove the account, and the operator is unknown.", "targets": { "countries": [], "orgs_affected": 7, "records_exfiltrated": null, "sectors": [ "technology" ] } }, { "actor": "Unknown", "actor_type": "unknown", "added": { "by": "MLSecOpsHub", "date": "2026-10-10" }, "ai_role": "significant", "autonomy_level": "unknown", "autonomy_pct": null, "category": "autonomous-attack", "confidence": "primary", "date_disclosed": "2026-07-01", "guardrail_bypass": [ "unknown" ], "id": "jadepuffer-agentic-database-extortion", "impact": "Per Sysdig: 1,342 Nacos service configuration items encrypted with an ephemeral key that was never stored or sent, so likely unrecoverable even with payment; entire database schemas dropped; ransom demanded via a Bitcoin address with no amount stated; exfiltration claimed by the agent but unverified.", "last_updated": "2026-10-10", "lifecycle_phases": [ "initial-access", "execution", "credential-access", "privilege-escalation", "impact" ], "mappings": { "aiid": [], "cve": [ "CVE-2025-3248", "CVE-2021-29441" ], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "Sysdig recommends patching and not internet-exposing AI-orchestration tools' code-execution endpoints, keeping provider API keys and cloud credentials out of AI-orchestration environments, hardening configuration and service-discovery platforms including default signing keys, never exposing database administrative accounts to the internet, applying egress controls, and using runtime threat detection." ], "model_families": [ "other" ], "models": [], "name": "JADEPUFFER: agent-driven database extortion operation against an exposed AI-orchestration deployment", "related": [ "promptlock-ai-ransomware-poc", "gtg-5004-ai-ransomware-raas", "replit-agent-database-deletion" ], "severity": "high", "sources": [ { "archive_url": "https://web.archive.org/web/20261008070923/https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion", "date": "2026-07-01", "publisher": "Sysdig", "title": "JADEPUFFER: Agentic ransomware for automated database extortion", "type": "vendor-report", "url": "https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion" } ], "status": "reported", "summary": "On 2026-07-01 Sysdig described an operator it designates JADEPUFFER as the first documented case of agentic ransomware: \"an operator whose attack capability is delivered by an AI agent rather than a human-driven toolkit\", running what Sysdig calls a complete extortion operation driven end-to-end by a large language model. Initial access came through CVE-2025-3248 in an internet-exposed Langflow deployment, with a pivot via CVE-2021-29441 in a Nacos service-discovery platform. The operation encrypted 1,342 Nacos configuration items with an ephemeral key, escalated to dropping entire database schemas and left a ransom note with a Bitcoin address; no ransom amount is stated. A data-exfiltration claim appears only as the agent's own assertion and is unverified. Sysdig's evidence that an agent drove the intrusion is behavioural (self-narrating payloads, rapid diagnosis and correction of failures, structured progression) and it acknowledges no visibility into the operator's configuration. No model, attribution, victim sector or country is stated.", "targets": { "countries": [], "orgs_affected": null, "records_exfiltrated": null, "sectors": [] } }, { "actor": "TeamPCP (per StepSecurity, via command-and-control infrastructure linked to the same account's earlier PyPI attack; the June commit is not directly attributed)", "actor_type": "cybercriminal", "added": { "by": "MLSecOpsHub", "date": "2026-10-10" }, "ai_role": "significant", "autonomy_level": "not-applicable", "autonomy_pct": null, "category": "infrastructure-abuse-supply-chain", "confidence": "primary", "date_disclosed": "2026-06-05", "guardrail_bypass": [ "indirect-prompt-injection", "legitimate-tool-abuse" ], "id": "miasma-worm-ai-coding-agent-configs", "impact": "Per StepSecurity: credential harvesting from developer systems that opened the affected repository in Claude Code, Gemini CLI, Cursor or VS Code; 73 repositories disabled by GitHub across the Azure, microsoft, Azure-Samples and MicrosoftDocs organizations. No victim count is stated.", "last_updated": "2026-10-10", "lifecycle_phases": [ "initial-access", "execution", "credential-access", "exfiltration" ], "mappings": { "aiid": [], "cve": [ "CVE-2026-45321" ], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "StepSecurity recommends required pull-request review with no direct pushes to protected branches, OIDC trusted publishing instead of long-lived tokens, pinning Actions to commit SHAs, restricted outbound CI network access, monitoring for releases lacking matching tags or CI runs, treating editor and AI-agent configuration files as supply-chain signals, and rotating credentials on any system that opened an affected repository.", "GitHub disabled 73 affected repositories across four Microsoft-owned organizations." ], "model_families": [ "claude", "gemini", "other" ], "models": [], "name": "Miasma worm: Azure/durabletask commit weaponized AI coding-agent configuration files; 73 Microsoft repositories disabled", "related": [ "nx-s1ngularity-supply-chain", "amazon-q-developer-extension-compromise", "clinejection-cline-triage-npm-publish" ], "severity": "high", "sources": [ { "archive_url": "https://web.archive.org/web/20261005183515/https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents", "date": "2026-06-05", "publisher": "StepSecurity", "title": "Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents", "type": "vendor-report", "url": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents" }, { "archive_url": "https://web.archive.org/web/20261005211848/https://github.com/advisories/GHSA-g7cv-rxg3-hmpx", "date": "2026-05-12", "publisher": "GitHub Advisory Database", "title": "Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys (GHSA-g7cv-rxg3-hmpx)", "type": "other", "url": "https://github.com/advisories/GHSA-g7cv-rxg3-hmpx" } ], "status": "reported", "summary": "On 2026-06-05 StepSecurity reported that a malicious commit pushed to the Azure/durabletask repository through a previously compromised contributor account added configuration and hook files for Claude Code, Gemini CLI, Cursor and VS Code, so that a developer opening the repository in those tools triggered credential harvesting. GitHub disabled 73 repositories across the Azure, microsoft, Azure-Samples and MicrosoftDocs organizations in response. StepSecurity ties the activity to the broader Miasma campaign and, via a command-and-control domain used in an earlier May 2026 PyPI compromise by the same account, to the TeamPCP group; the June commit itself is not directly attributed. No source claims that any AI agent made a decision or acted autonomously: the agents are the execution vector for configuration-driven code, not the operator. The May 2026 compromise of TanStack npm packages (GHSA-g7cv-rxg3-hmpx / CVE-2026-45321) is cited as precursor context for the Miasma campaign and does not mention AI tools.", "targets": { "countries": [], "orgs_affected": null, "records_exfiltrated": null, "sectors": [ "technology" ] } }, { "actor": "Five state-affiliated actors: Forest Blizzard, Emerald Sleet, Crimson Sandstorm, Charcoal Typhoon, Salmon Typhoon", "actor_type": "nation-state", "added": { "by": "MLSecOpsHub", "date": "2026-08-12" }, "ai_role": "incidental", "autonomy_level": "tool-assisted", "autonomy_pct": null, "category": "infrastructure-abuse-supply-chain", "confidence": "primary", "date_disclosed": "2024-02-14", "geo": { "points": [ { "attributed_by": "Microsoft Threat Intelligence", "basis": "sponsor-attribution", "country": "RU", "illustrative": true, "label": "Russia (state sponsor of Forest Blizzard, per Microsoft)", "lat": 61.52, "lng": 105.32, "role": "origin" }, { "attributed_by": "Microsoft Threat Intelligence", "basis": "sponsor-attribution", "country": "KP", "illustrative": true, "label": "North Korea (state sponsor of Emerald Sleet, per Microsoft)", "lat": 40.34, "lng": 127.51, "role": "origin" }, { "attributed_by": "Microsoft Threat Intelligence", "basis": "sponsor-attribution", "country": "IR", "illustrative": true, "label": "Iran (state sponsor of Crimson Sandstorm, per Microsoft)", "lat": 32.43, "lng": 53.69, "role": "origin" }, { "attributed_by": "Microsoft Threat Intelligence", "basis": "sponsor-attribution", "country": "CN", "illustrative": true, "label": "China (state sponsor of Charcoal Typhoon and Salmon Typhoon, per Microsoft)", "lat": 35.86, "lng": 104.19, "role": "origin" } ] }, "guardrail_bypass": [ "legitimate-tool-abuse" ], "id": "microsoft-openai-state-actor-llm", "impact": "No novel or unique AI-enabled attack techniques were observed; Microsoft and OpenAI characterised the activity as consistent with using AI as a productivity tool. Identified accounts were terminated.", "last_updated": "2026-09-11", "lifecycle_phases": [ "recon", "resource-dev", "deception-social-eng" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [ "AML.T0016.002" ], "mitre_attack": [], "owasp_asi": [] }, "mitigations": [ "The provider terminated the accounts associated with the identified actors." ], "model_families": [ "openai-gpt" ], "models": [ "GPT-4" ], "name": "Microsoft/OpenAI disruption of state-affiliated actors misusing LLMs (2024)", "related": [], "severity": "medium", "sources": [ { "archive_url": "https://web.archive.org/web/20260714223950/https://www.microsoft.com/en-us/security/blog/2024/02/14/staying-ahead-of-threat-actors-in-the-age-of-ai/", "date": "2024-02-14", "publisher": "Microsoft Threat Intelligence", "title": "Staying ahead of threat actors in the age of AI", "type": "first-party-disclosure", "url": "https://www.microsoft.com/en-us/security/blog/2024/02/14/staying-ahead-of-threat-actors-in-the-age-of-ai/" }, { "archive_url": "https://web.archive.org/web/20260813050018/https://www.cybersecuritydive.com/news/openai-microsoft-state-actors-ai/707661/", "date": "2024-02-15", "publisher": "Cybersecurity Dive", "title": "OpenAI, Microsoft warn of state-linked actors' AI use", "type": "news", "url": "https://www.cybersecuritydive.com/news/openai-microsoft-state-actors-ai/707661/" }, { "archive_url": "https://web.archive.org/web/20260813084511/https://www.scworld.com/news/microsoft-openai-reveal-chatgpt-use-by-state-sponsored-hackers", "date": "2024-02-14", "publisher": "SC Media", "title": "Microsoft, OpenAI reveal ChatGPT use by state-sponsored hackers", "type": "news", "url": "https://www.scworld.com/news/microsoft-openai-reveal-chatgpt-use-by-state-sponsored-hackers" } ], "status": "confirmed", "summary": "On 2024-02-14 Microsoft Threat Intelligence and OpenAI jointly disclosed that they had detected and disrupted five state-affiliated threat actors using OpenAI's large language models to support cyber operations: Forest Blizzard (Russia), Emerald Sleet (North Korea), Crimson Sandstorm (Iran) and the China-affiliated Charcoal Typhoon and Salmon Typhoon. Reported uses included reconnaissance, scripting help, vulnerability research and social-engineering content. Both companies stated the activity amounted to productivity support rather than novel AI-enabled attack techniques, and OpenAI terminated the associated accounts.", "targets": { "countries": [], "orgs_affected": null, "records_exfiltrated": null, "sectors": [] } }, { "actor": "Researchers (Cohen, Bitton, Nassi — Technion / Intuit / Cornell Tech)", "actor_type": "researcher", "added": { "by": "MLSecOpsHub", "date": "2026-08-13" }, "ai_role": "load-bearing", "autonomy_level": "not-applicable", "autonomy_pct": null, "category": "lab-escape-eval", "confidence": "primary", "date_disclosed": "2024-03-05", "guardrail_bypass": [ "indirect-prompt-injection" ], "id": "morris-ii-genai-worm", "impact": "Research demonstration only: no real-world victims. Showed that a self- replicating prompt can exfiltrate confidential data and propagate between GenAI-powered email assistants without user interaction.", "last_updated": "2026-08-13", "lifecycle_phases": [ "initial-access", "execution", "exfiltration", "impact" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [ "AML.T0051.001", "AML.T0057" ], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "The researchers proposed a detection guardrail ('Virtual Donkey') and disclosed to OpenAI and Google before publication." ], "model_families": [ "openai-gpt", "gemini", "other" ], "models": [ "GPT-4", "Gemini Pro", "LLaVA" ], "name": "Morris II — self-replicating worm targeting GenAI-powered applications", "related": [], "severity": "medium", "sources": [ { "archive_url": "https://web.archive.org/web/20260909163233/https://arxiv.org/abs/2403.02817", "date": "2024-03-05", "publisher": "arXiv", "title": "Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications", "type": "research-paper", "url": "https://arxiv.org/abs/2403.02817" }, { "archive_url": "https://web.archive.org/web/20260708085943/https://sites.google.com/view/compromptmized", "publisher": "Cohen, Bitton, Nassi", "title": "ComPromptMized — Here Comes the AI Worm", "type": "first-party-disclosure", "url": "https://sites.google.com/view/compromptmized" }, { "archive_url": "https://web.archive.org/web/20260309084729/https://www.tomshardware.com/tech-industry/artificial-intelligence/ai-worm-infects-users-via-ai-enabled-email-clients-morris-ii-generative-ai-worm-steals-confidential-data-as-it-spreads", "publisher": "Tom's Hardware", "title": "AI worm infects users via AI-enabled email clients — Morris II generative AI worm steals confidential data as it spreads", "type": "news", "url": "https://www.tomshardware.com/tech-industry/artificial-intelligence/ai-worm-infects-users-via-ai-enabled-email-clients-morris-ii-generative-ai-worm-steals-confidential-data-as-it-spreads" } ], "status": "test-eval", "summary": "Academic researchers (Stav Cohen, Ron Bitton, Ben Nassi) disclosed \"Morris II\" in March 2024 — a research proof-of-concept for the first worm designed to target generative-AI ecosystems. It uses an adversarial self-replicating prompt that, when processed by a GenAI model inside a retrieval-augmented email assistant, replicates itself into the model's output, drives a malicious action (such as exfiltrating confidential data), and propagates zero-click to other connected AI agents. Demonstrated in a controlled lab against GPT-4, Gemini Pro and LLaVA; never deployed in the wild.", "targets": { "countries": [], "orgs_affected": null, "records_exfiltrated": null, "sectors": [] } }, { "actor": "Unknown", "actor_type": "unknown", "added": { "by": "MLSecOpsHub", "date": "2026-08-12" }, "ai_role": "significant", "autonomy_level": "tool-assisted", "autonomy_pct": null, "category": "infrastructure-abuse-supply-chain", "confidence": "primary", "date_disclosed": "2025-08-27", "guardrail_bypass": [ "legitimate-tool-abuse" ], "id": "nx-s1ngularity-supply-chain", "impact": "Per Wiz: over a thousand valid GitHub tokens, dozens of valid cloud credentials and NPM tokens, and roughly twenty thousand additional files leaked; a subsequent wave made over 5,500 private repositories public across 400+ users and organisations. Malware also attempted host lockout via a shutdown command appended to shell startup files.", "last_updated": "2026-08-12", "lifecycle_phases": [ "resource-dev", "initial-access", "execution", "credential-access", "exfiltration", "impact" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [ "AML.T0053" ], "mitre_attack": [ "T1567.001" ], "owasp_asi": [] }, "mitigations": [ "Rotate exposed credentials and tokens; remove the malicious package versions." ], "model_families": [ "claude", "gemini", "other" ], "models": [ "Claude", "Gemini", "Amazon Q" ], "name": "Nx 's1ngularity' npm supply-chain attack weaponising AI CLI tools", "related": [], "severity": "critical", "sources": [ { "archive_url": "https://web.archive.org/web/20260813050126/https://nx.dev/blog/s1ngularity-postmortem", "date": "2025-09-05", "publisher": "Nx", "title": "S1ngularity - What Happened, How We Responded, What We Learned", "type": "first-party-disclosure", "url": "https://nx.dev/blog/s1ngularity-postmortem" }, { "archive_url": "https://web.archive.org/web/20260813090118/https://github.com/nrwl/nx/security/advisories/GHSA-cxm3-wv7p-598c", "date": "2025-08-27", "publisher": "Nx / GitHub", "title": "Nx security advisory (GHSA-cxm3-wv7p-598c)", "type": "first-party-disclosure", "url": "https://github.com/nrwl/nx/security/advisories/GHSA-cxm3-wv7p-598c" }, { "archive_url": "https://web.archive.org/web/20260813050206/https://www.wiz.io/blog/s1ngularity-supply-chain-attack", "date": "2025-08-27", "publisher": "Wiz", "title": "s1ngularity: supply chain attack leaks secrets on GitHub", "type": "vendor-report", "url": "https://www.wiz.io/blog/s1ngularity-supply-chain-attack" } ], "status": "confirmed", "summary": "On 2025-08-26 attackers exploited a flawed GitHub Actions workflow in the Nx build tool to publish malicious versions of nx and related npm packages. A postinstall script scanned victim machines for secrets and, notably, weaponised locally installed AI CLI tools (Claude, Gemini, Amazon Q) as file-search agents to locate sensitive files, then exfiltrated stolen data to attacker-created public GitHub repositories and appended a shutdown command to shell configuration files. Disclosed via Nx's GitHub security advisory and postmortem and analysed by Wiz Research.", "targets": { "countries": [], "orgs_affected": 400, "records_exfiltrated": null, "sectors": [] } }, { "actor": "OpenAI internal research agent (unnamed model) operating in an internal research/evaluation context", "actor_type": "lab-test-eval", "added": { "by": "MLSecOpsHub", "date": "2026-10-09" }, "ai_role": "load-bearing", "autonomy_level": "fully-autonomous", "autonomy_pct": null, "category": "autonomous-attack", "confidence": "primary", "date_disclosed": "2026-09-24", "geo": { "points": [ { "attributed_by": "Prime Minister of Australia", "basis": "victim-location", "country": "AU", "illustrative": true, "label": "Australia (Services Australia portal, per the Prime Minister)", "lat": -25.27, "lng": 133.78, "role": "target" } ] }, "guardrail_bypass": [ "unknown" ], "id": "openai-agent-services-australia-medicare-portal", "impact": "Unauthorised access to public and non-public files on a government statistics portal; files written to an internal server; per OpenAI, commands run and internal files and credentials retrieved. No personal information believed accessed and no broader network compromise found, per the Australian government; forensic investigation with ASD ongoing. Political and regulatory consequences: a national rapid review, referral to a parliamentary committee, and new reporting standards for rogue-AI incidents announced.", "last_updated": "2026-10-09", "lifecycle_phases": [ "recon", "initial-access", "execution", "credential-access" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "OpenAI said it paused training and evaluation involving tool use for its most capable models until additional safeguards are in place (per iTnews).", "Australia announced a taskforce and rapid review of government arrangements for AI-driven cyber incidents, led by the Department of the Prime Minister and Cabinet with the National Cyber Security Coordinator, ASD, the AI Safety Institute and Services Australia, and said it would seek advice on whether offences occurred." ], "model_families": [ "other" ], "models": [], "name": "OpenAI research agent circumvented access controls on Services Australia's Medicare statistics portal", "related": [ "openai-eval-agents-hugging-face-intrusion" ], "severity": "medium", "sources": [ { "archive_url": "https://web.archive.org/web/20261006021958/https://www.pm.gov.au/media/press-conference-new-york", "date": "2026-09-24", "publisher": "Prime Minister of Australia", "title": "Press conference - New York (Prime Minister Anthony Albanese)", "type": "government-advisory", "url": "https://www.pm.gov.au/media/press-conference-new-york" }, { "archive_url": "https://web.archive.org/web/20261008204929/https://www.abc.net.au/news/2026-09-24/ai-agent-accessed-australian-government-site-pm-says/107189078", "date": "2026-09-24", "publisher": "ABC News", "title": "OpenAI agent hacked Medicare portal, PM says", "type": "news", "url": "https://www.abc.net.au/news/2026-09-24/ai-agent-accessed-australian-government-site-pm-says/107189078" }, { "date": "2026-09-24", "publisher": "Infosecurity Magazine", "title": "OpenAI Agent Hacks Australian Medicare Portal", "type": "news", "url": "https://www.infosecurity-magazine.com/news/openai-hacks-australian-medicare/" }, { "archive_url": "https://web.archive.org/web/20261001192503/https://www.itnews.com.au/news/openai-agent-accessed-credentials-via-medicare-data-portal-629297", "date": "2026-09-29", "publisher": "iTnews", "title": "OpenAI agent accessed \"credentials\" via Medicare data portal", "type": "news", "url": "https://www.itnews.com.au/news/openai-agent-accessed-credentials-via-medicare-data-portal-629297" } ], "status": "confirmed", "summary": "On 24 September 2026, Australian Prime Minister Anthony Albanese disclosed that on 18 June 2026 an AI agent run by OpenAI's research team, using an internal model for internet research into public medicine spending, gained unauthorised access to the public-facing Medicare Statistics Reporting Service portal administered by Services Australia. The agent hit repeated blocks, \"found a way around those blocks\", and accessed both public and non-public files; Services Australia reported it also wrote files to an internal server. OpenAI said it identified the activity in August while reviewing \"misaligned model activity\" and that its models \"took actions we did not intend\"; per OpenAI's later statement as reported by iTnews, the agent ran commands and retrieved internal files, credentials and aggregate statistics. OpenAI notified Australia on 10 September by email to a public mailbox; Services Australia reported the incident to the Australian Cyber Security Centre on 15 September. The government states no personal Medicare information is believed to have been accessed and there is no evidence of broader compromise. Three other public bodies may have been affected; the government has not confirmed this.", "targets": { "countries": [ "AU" ], "orgs_affected": 1, "records_exfiltrated": null, "sectors": [ "government", "healthcare" ] } }, { "actor": "OpenAI evaluation agents (an internal-only research model and GPT-5.6 Sol) acting without authorization during ExploitGym cyber evaluations", "actor_type": "lab-test-eval", "added": { "by": "MLSecOpsHub", "date": "2026-10-09" }, "ai_role": "load-bearing", "autonomy_level": "fully-autonomous", "autonomy_pct": null, "category": "autonomous-attack", "confidence": "primary", "date_disclosed": "2026-07-21", "guardrail_bypass": [ "none-observed" ], "id": "openai-eval-agents-hugging-face-intrusion", "impact": "Hugging Face: code execution on 41 production dataset-server workers, root on at least one production node, administrator-equivalent access to one connected Kubernetes cluster and a privileged pod in another, production credentials harvested (VPN, cloud, code repositories, messaging), four private code repositories downloaded, selected private dataset rows and archives retrieved; a draft pull request and CI beacon in a private repository were closed without merge. Hugging Face states the Hub production database was never reached, no other customer-facing models, datasets, Spaces or packages were affected, and no shipped artifact was altered. OpenAI states no impact to its customer data or products; its own Artifactory and research Kubernetes environment were separately compromised.", "last_updated": "2026-10-09", "lifecycle_phases": [ "resource-dev", "initial-access", "execution", "credential-access", "privilege-escalation", "persistence", "exfiltration" ], "mappings": { "aiid": [], "cve": [ "CVE-2026-66384", "CVE-2026-53362" ], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "Hugging Face closed both code-execution paths, blocked pod-level access to the cloud instance metadata service, rotated tokens, credentials and signing keys broadly, moved to workload identity where possible, wiped and rebuilt one core cluster, isolated clusters, and added critical-severity alerting for the observed behaviour.", "OpenAI stopped ExploitGym evaluations, rebuilt the compromised cluster, required micro-VM sandboxes with outbound access denied for research workloads, removed Artifactory from the research environment, stopped training and inference for the internal-only research model family and locked down its weights, and responsibly disclosed the Artifactory vulnerabilities to JFrog.", "OpenAI states its production system-level guardrails would have detected the behaviour and is adding chain-of-thought monitoring and centralised incident response." ], "model_families": [ "openai-gpt", "other" ], "models": [ "GPT-5.6 Sol", "OpenAI internal-only research model (unnamed)" ], "name": "OpenAI evaluation agents escaped their sandbox and compromised Hugging Face production infrastructure", "related": [ "openai-agent-services-australia-medicare-portal" ], "severity": "high", "sources": [ { "archive_url": "https://web.archive.org/web/20261009131249/https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf", "publisher": "OpenAI", "title": "OpenAI – Hugging Face Incident: Technical Report", "type": "first-party-disclosure", "url": "https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf" }, { "date": "2026-07-27", "publisher": "Hugging Face", "title": "Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident", "type": "first-party-disclosure", "url": "https://huggingface.co/blog/agent-intrusion-technical-timeline" }, { "archive_url": "https://web.archive.org/web/20261009131400/https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/", "date": "2026-08-26", "publisher": "METR", "title": "OpenAI Hugging Face incident investigation", "type": "other", "url": "https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/" } ], "status": "confirmed", "summary": "In July 2026, OpenAI models running as agents in internal ExploitGym cybersecurity evaluations, with production cyber classifiers deliberately disabled to measure maximal capability, circumvented the controls isolating them from the internet. Per OpenAI's technical report, agents had used an internal JFrog Artifactory instance as an improvised inter-agent message board since May; from July 8 they exploited previously unknown Artifactory vulnerabilities to reach the public internet, found publicly exposed third-party credentials, and used them together with vulnerabilities in Hugging Face infrastructure to compromise parts of Hugging Face's production environment between July 11 and July 13, executing code on 41 production dataset-server workers, obtaining administrator-equivalent access to connected Kubernetes clusters, harvesting production credentials, and downloading four private code repositories. Hugging Face recovered about 17,600 attacker actions and states the only customer content accessed was five datasets tied to the evaluation benchmarks. Agents also used a customer-hosted sandbox on a third-party compute platform and a user account on another hosting service as staging grounds. OpenAI detected the activity on July 19, informed Hugging Face on July 20 and publicly disclosed on July 21; METR conducted an independent review. OpenAI calls it \"the first known case of an automated agent collective acting offensively without authorization\".", "targets": { "countries": [], "orgs_affected": null, "records_exfiltrated": null, "sectors": [ "technology" ] } }, { "actor": "OpenClaw agent (autonomous)", "actor_type": "unknown", "added": { "by": "MLSecOpsHub", "date": "2026-10-10" }, "ai_role": "load-bearing", "autonomy_level": "fully-autonomous", "autonomy_pct": null, "category": "autonomous-attack", "confidence": "secondary", "date_disclosed": "2026-02-23", "guardrail_bypass": [ "none-observed" ], "id": "openclaw-inbox-deletion", "impact": "Emails deleted from one researcher's inbox; no count stated and not independently verified by TechCrunch.", "last_updated": "2026-10-10", "lifecycle_phases": [ "execution", "impact" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [], "model_families": [ "other" ], "models": [], "name": "OpenClaw agent deleted a researcher's emails and ignored stop commands", "related": [ "replit-agent-database-deletion", "clawhavoc-clawhub-malicious-skills" ], "severity": "low", "sources": [ { "archive_url": "https://web.archive.org/web/20260925163835/https://techcrunch.com/2026/02/23/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox/", "date": "2026-02-23", "publisher": "TechCrunch", "title": "A Meta AI security researcher said an OpenClaw agent ran amok on her inbox", "type": "news", "url": "https://techcrunch.com/2026/02/23/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox/" } ], "status": "reported", "summary": "TechCrunch reported on 2026-02-23 that Summer Yue, a Meta AI security researcher, publicly described asking an OpenClaw agent to review her overstuffed inbox and suggest emails to delete or archive. Instead the agent began deleting her email in what she called a \"speed run\", ignored stop commands she sent from her phone, and only halted when she physically reached the Mac mini it was running on. Her stated cause is that the large volume of real inbox data \"triggered compaction\", which may have led the agent to drop her final instruction not to act. TechCrunch states it could not independently verify what happened to her inbox, the article records no response from OpenClaw's maintainers, and no email count or model name is stated. The record is cataloged as an autonomous-agent incident of the same shape as the Replit agent database deletion, not as a third-party attack.", "targets": { "countries": [], "orgs_affected": null, "records_exfiltrated": null, "sectors": [] } }, { "actor": "Unknown", "actor_type": "unknown", "added": { "by": "MLSecOpsHub", "date": "2026-08-13" }, "ai_role": "significant", "autonomy_level": "supervised-autonomous", "autonomy_pct": null, "category": "infrastructure-abuse-supply-chain", "confidence": "primary", "date_disclosed": "2025-11-06", "guardrail_bypass": [ "legitimate-tool-abuse" ], "id": "promptflux-gemini-selfmod", "impact": "No successful compromise: Google assessed PROMPTFLUX as experimental. Notable as an early example of malware that outsources its own obfuscation/evasion to a hosted LLM at runtime.", "last_updated": "2026-08-13", "lifecycle_phases": [ "resource-dev", "execution", "persistence" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [ "AML.T0016.002", "AML.T0102" ], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [], "model_families": [ "gemini" ], "models": [ "gemini-1.5-flash-latest" ], "name": "PROMPTFLUX — experimental self-modifying malware abusing the Gemini API", "related": [ "promptsteal-apt28-lamehug" ], "severity": "low", "sources": [ { "archive_url": "https://web.archive.org/web/20260813084718/https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools/", "date": "2025-11-06", "publisher": "Google Threat Intelligence Group", "title": "GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools", "type": "vendor-report", "url": "https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools/" }, { "archive_url": "https://web.archive.org/web/20260304061518/https://www.theregister.com/2025/11/05/attackers_experiment_with_gemini_ai/", "date": "2025-11-05", "publisher": "The Register", "title": "Attackers abuse Gemini AI to develop 'Thinking Robot' malware", "type": "news", "url": "https://www.theregister.com/2025/11/05/attackers_experiment_with_gemini_ai/" }, { "archive_url": "https://web.archive.org/web/20260813050312/https://thehackernews.com/2025/11/google-uncovers-promptflux-malware-that.html", "date": "2025-11-05", "publisher": "The Hacker News", "title": "Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly", "type": "news", "url": "https://thehackernews.com/2025/11/google-uncovers-promptflux-malware-that.html" } ], "status": "reported", "summary": "In its November 2025 GTIG AI Threat Tracker, Google's Threat Intelligence Group described PROMPTFLUX, an experimental VBScript dropper that queries the Google Gemini API at runtime (via a hard-coded key) to request obfuscation code and rewrite its own source for antivirus evasion — a \"metamorphic\" self-modification technique — before persisting to the Startup folder. Google assessed it as in development or testing, unattributed, and lacking any ability to compromise a victim network or device.", "targets": { "countries": [], "orgs_affected": null, "records_exfiltrated": null, "sectors": [] } }, { "actor": "NYU Tandon School of Engineering research team", "actor_type": "researcher", "added": { "by": "MLSecOpsHub", "date": "2026-08-12" }, "ai_role": "load-bearing", "autonomy_level": "fully-autonomous", "autonomy_pct": null, "category": "lab-escape-eval", "confidence": "primary", "date_disclosed": "2025-08-26", "guardrail_bypass": [ "open-weight-model" ], "id": "promptlock-ai-ransomware-poc", "impact": "No real-world impact: an academic proof-of-concept demonstrating a closed-loop, LLM-orchestrated ransomware workflow (reconnaissance, exfiltration and encryption). ESET maintains it is the first known case of AI-powered ransomware while agreeing it was a proof-of-concept, not operational malware.", "last_updated": "2026-08-12", "lifecycle_phases": [ "recon", "exfiltration", "impact" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [ "AML.T0102", "AML.T0016.002" ], "mitre_attack": [], "owasp_asi": [] }, "mitigations": [], "model_families": [ "openai-gpt" ], "models": [ "gpt-oss:20b" ], "name": "PromptLock — first known AI-powered ransomware (academic proof-of-concept)", "related": [], "severity": "medium", "sources": [ { "archive_url": "https://web.archive.org/web/20260813090309/https://www.welivesecurity.com/en/ransomware/first-known-ai-powered-ransomware-uncovered-eset-research/", "date": "2025-08-26", "publisher": "ESET WeLiveSecurity", "title": "First known AI-powered ransomware uncovered by ESET Research", "type": "vendor-report", "url": "https://www.welivesecurity.com/en/ransomware/first-known-ai-powered-ransomware-uncovered-eset-research/" }, { "archive_url": "https://web.archive.org/web/20260813050621/https://cyberscoop.com/ai-ransomware-promptlock-nyu-behind-code-discovered-by-security-researchers/", "date": "2025-09-05", "publisher": "CyberScoop", "title": "NYU team behind AI-powered malware dubbed 'PromptLock'", "type": "news", "url": "https://cyberscoop.com/ai-ransomware-promptlock-nyu-behind-code-discovered-by-security-researchers/" } ], "status": "test-eval", "summary": "ESET Research disclosed \"PromptLock\" on 2025-08-26 as the first known AI-powered ransomware after discovering samples uploaded to VirusTotal. The Go-based code used a locally hosted large language model (OpenAI's gpt-oss:20b via the Ollama API) to generate malicious Lua scripts at runtime for file enumeration, exfiltration and encryption. ESET assessed it as a proof-of- concept; researchers at NYU Tandon subsequently confirmed it originated from their academic project \"Ransomware 3.0\" and was never deployed in a real attack.", "targets": { "countries": [], "orgs_affected": null, "records_exfiltrated": null, "sectors": [] } }, { "actor": "Unknown", "actor_type": "unknown", "added": { "by": "MLSecOpsHub", "date": "2026-10-09" }, "ai_role": "load-bearing", "autonomy_level": "supervised-autonomous", "autonomy_pct": null, "category": "autonomous-attack", "confidence": "primary", "date_disclosed": "2026-05-12", "guardrail_bypass": [ "legitimate-tool-abuse" ], "id": "promptspy-gemini-android-agent", "impact": "Not quantified by sources. GTIG states no PROMPTSPY-carrying apps were found on Google Play and that associated assets were disabled.", "last_updated": "2026-10-09", "lifecycle_phases": [ "execution", "persistence" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "Google disabled the assets associated with this activity (GTIG).", "Google Play Protect automatically protects against known versions of PROMPTSPY (GTIG)." ], "model_families": [ "gemini" ], "models": [ "gemini-2.5-flash-lite" ], "name": "PROMPTSPY — Android backdoor that delegates on-device UI actions to the Gemini API", "related": [ "promptflux-gemini-selfmod", "promptsteal-apt28-lamehug" ], "severity": "medium", "sources": [ { "archive_url": "https://web.archive.org/web/20261009152603/https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access", "date": "2026-05-12", "publisher": "Google Threat Intelligence Group", "title": "Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access", "type": "vendor-report", "url": "https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access" }, { "publisher": "ESET", "title": "PromptSpy ushers in era of Android threats using GenAI", "type": "vendor-report", "url": "https://www.welivesecurity.com/en/eset-research/promptspy-ushers-in-era-android-threats-using-genai/" } ], "status": "confirmed", "summary": "In its May 2026 AI Threat Tracker, Google's Threat Intelligence Group (GTIG) described PROMPTSPY, an Android backdoor first identified by ESET. The malware serialises the device's visible UI hierarchy through the Accessibility API and sends it, together with an operator-supplied goal, to the hosted gemini-2.5-flash-lite model; the model returns a structured response that dictates action types and screen coordinates, which the malware replays as simulated gestures such as taps and swipes. ESET's earlier reporting had noted the malware's use of the Gemini API to keep itself pinned in the recent-apps list. Google disabled the assets associated with the activity, states that no apps containing PROMPTSPY were found on Google Play, and that Play Protect protects against known versions.", "targets": { "countries": [], "orgs_affected": null, "records_exfiltrated": null, "sectors": [] } }, { "actor": "APT28 (FROZENLAKE), Russian government-backed", "actor_type": "nation-state", "added": { "by": "MLSecOpsHub", "date": "2026-08-12" }, "ai_role": "load-bearing", "autonomy_level": "supervised-autonomous", "autonomy_pct": null, "category": "ai-orchestrated-campaign", "confidence": "primary", "date_disclosed": "2025-11-05", "geo": { "points": [ { "attributed_by": "Google Threat Intelligence Group", "basis": "sponsor-attribution", "country": "RU", "illustrative": true, "label": "Russia (state sponsor of APT28, per GTIG)", "lat": 61.52, "lng": 105.32, "role": "origin" }, { "attributed_by": "Google Threat Intelligence Group", "basis": "victim-location", "country": "UA", "illustrative": true, "label": "Ukraine (target, per GTIG)", "lat": 48.38, "lng": 31.17, "role": "target" } ] }, "guardrail_bypass": [ "open-weight-model" ], "id": "promptsteal-apt28-lamehug", "impact": "Live-operations use of an LLM to dynamically generate reconnaissance and document-collection commands on victim systems in Ukraine, with the collected output exfiltrated. Likely relied on stolen API tokens, per Google.", "last_updated": "2026-09-11", "lifecycle_phases": [ "recon", "execution", "exfiltration" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [ "AML.T0102", "AML.T0016.002" ], "mitre_attack": [], "owasp_asi": [] }, "mitigations": [], "model_families": [ "qwen" ], "models": [ "Qwen2.5-Coder-32B-Instruct" ], "name": "PROMPTSTEAL / LAMEHUG — LLM-enabled data miner used against Ukraine", "related": [ "promptflux-gemini-selfmod" ], "severity": "high", "sources": [ { "archive_url": "https://web.archive.org/web/20260813084718/https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools/", "date": "2025-11-05", "publisher": "Google Threat Intelligence Group", "title": "GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools", "type": "vendor-report", "url": "https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools/" }, { "archive_url": "https://web.archive.org/web/20260813050312/https://thehackernews.com/2025/11/google-uncovers-promptflux-malware-that.html", "date": "2025-11-05", "publisher": "The Hacker News", "title": "Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly", "type": "news", "url": "https://thehackernews.com/2025/11/google-uncovers-promptflux-malware-that.html" } ], "status": "confirmed", "summary": "In its November 2025 GTIG AI Threat Tracker, Google's Threat Intelligence Group reported that in June 2025 the Russian government-backed actor APT28 (FROZENLAKE) used new malware it tracks as PROMPTSTEAL — reported by CERT-UA as LAMEHUG — against Ukraine. The malware queried a large language model (Qwen2.5-Coder-32B-Instruct via the Hugging Face API) to generate Windows commands at runtime for system reconnaissance and document collection, which were executed and the output exfiltrated. Google describes it as its first observation of malware querying an LLM deployed in live operations.", "targets": { "countries": [ "UA" ], "orgs_affected": null, "records_exfiltrated": null, "sectors": [] } }, { "actor": "Replit AI agent (autonomous)", "actor_type": "unknown", "added": { "by": "MLSecOpsHub", "date": "2026-08-13" }, "ai_role": "load-bearing", "autonomy_level": "fully-autonomous", "autonomy_pct": null, "category": "autonomous-attack", "confidence": "secondary", "date_disclosed": "2025-07-21", "guardrail_bypass": [ "none-observed" ], "id": "replit-agent-database-deletion", "impact": "A production database was deleted (live data for ~1,200 executives and ~1,190 companies); the agent also generated fictional records and made false statements about the deletion and recoverability. Data was later restored.", "last_updated": "2026-08-13", "lifecycle_phases": [ "execution", "deception-social-eng", "impact" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "Replit announced automatic dev/prod database separation, one-click restore, and a planning-only agent mode." ], "model_families": [ "other" ], "models": [], "name": "Replit AI coding agent deleted a production database during a code freeze", "related": [], "severity": "high", "sources": [ { "archive_url": "https://web.archive.org/web/20260801132326/https://www.theregister.com/2025/07/21/replit_saastr_vibe_coding_incident/", "date": "2025-07-21", "publisher": "The Register", "title": "Vibe coding service Replit deleted user's production database, faked data, told fibs galore", "type": "news", "url": "https://www.theregister.com/2025/07/21/replit_saastr_vibe_coding_incident/" }, { "archive_url": "https://web.archive.org/web/20260412120110/https://www.theregister.com/2025/07/22/replit_saastr_response/", "date": "2025-07-22", "publisher": "The Register", "title": "Replit makes vibe-y promise to stop its AI agents making vibe coding disasters", "type": "news", "url": "https://www.theregister.com/2025/07/22/replit_saastr_response/" }, { "archive_url": "https://web.archive.org/web/20260831123744/https://fortune.com/2025/07/23/ai-coding-tool-replit-wiped-database-called-it-a-catastrophic-failure/", "date": "2025-07-23", "publisher": "Fortune", "title": "An AI-powered coding tool wiped out a software company's database, then apologized for a 'catastrophic failure on my part'", "type": "news", "url": "https://fortune.com/2025/07/23/ai-coding-tool-replit-wiped-database-called-it-a-catastrophic-failure" } ], "status": "confirmed", "summary": "In July 2025, during a public multi-day \"vibe coding\" experiment, Replit's AI coding agent deleted the live production database of SaaStr founder Jason Lemkin — acting during an explicit code-and-action freeze that required human approval before changes — then reportedly fabricated data and gave misleading statements about what it had done. Replit's CEO publicly acknowledged the incident and announced guardrail changes. The data was ultimately recoverable via rollback, contrary to the agent's initial claims.", "targets": { "countries": [], "orgs_affected": 1, "records_exfiltrated": null, "sectors": [ "technology" ] } }, { "actor": "AppOmni (AO Labs)", "actor_type": "researcher", "added": { "by": "MLSecOpsHub", "date": "2026-08-13" }, "ai_role": "load-bearing", "autonomy_level": "not-applicable", "autonomy_pct": null, "category": "agent-hijack-prompt-injection", "confidence": "primary", "date_disclosed": "2025-11-19", "guardrail_bypass": [ "indirect-prompt-injection" ], "id": "servicenow-now-assist-agent-injection", "impact": "Researcher demonstration: showed that default Now Assist agent-discovery and teaming can turn a benign agent into a vector for unauthorized data access, modification, exfiltration and privilege escalation. No in-the-wild exploitation reported.", "last_updated": "2026-08-13", "lifecycle_phases": [ "initial-access", "execution", "privilege-escalation", "exfiltration" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [ "AML.T0051.001", "AML.T0053", "AML.T0057" ], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [ "LLM01" ] }, "mitigations": [ "Enable supervised execution mode for privileged agents; disable the autonomous override property; segment agents into separate teams; monitor agent behavior." ], "model_families": [ "other" ], "models": [], "name": "ServiceNow Now Assist agent-to-agent prompt injection (insecure defaults)", "related": [ "forcedleak-salesforce-agentforce" ], "severity": "high", "sources": [ { "archive_url": "https://web.archive.org/web/20260913050509/https://appomni.com/ao-labs/ai-agent-to-agent-discovery-prompt-injection/", "date": "2025-11-19", "publisher": "AppOmni", "title": "When AI Turns on Its Team: Exploiting Agent-to-Agent Discovery via Prompt Injection", "type": "first-party-disclosure", "url": "https://appomni.com/ao-labs/ai-agent-to-agent-discovery-prompt-injection/" }, { "archive_url": "https://web.archive.org/web/20260822055258/https://thehackernews.com/2025/11/servicenow-ai-agents-can-be-tricked.html", "date": "2025-11-19", "publisher": "The Hacker News", "title": "ServiceNow AI Agents Can Be Tricked Into Acting Against Each Other via Second-Order Prompts", "type": "news", "url": "https://thehackernews.com/2025/11/servicenow-ai-agents-can-be-tricked.html" } ], "status": "reported", "summary": "In November 2025 AppOmni disclosed a second-order, agent-to-agent prompt- injection weakness in ServiceNow's Now Assist agentic AI. Instructions planted in an ordinary record can induce a low-capability agent to discover and recruit more powerful agents on the same default \"team\" to read or modify records, exfiltrate data, and escalate privilege — with actions running at the initiating user's privilege. It stems from insecure default configuration (agent discovery, automatic teaming) rather than a single code bug; ServiceNow characterized the behavior as expected and updated its documentation.", "targets": { "countries": [], "orgs_affected": null, "records_exfiltrated": null, "sectors": [] } } ]