Found 206 agent incident(s) in curated external sources not yet in our corpus (showing newest 60). Each is a candidate to draft from incidents/_TEMPLATE.yaml; some may be surveys/reports rather than incidents — triage as usual.
2026-09-12 — OpenAI's Test Agents Flooded RubyGems With 2,000+ Malicious Packages and Reached Code Execution on RubyDoc.info (awesome-list)
2026-09-10 — Hundreds of AI Agents Exploit Two PaperCut Flaws to Breach 395 Organizations in 48 Countries, and Ignore Their Own Exclusion List (CVE-2026-81578, CVE-2026-82078) (awesome-list) · CVE-2026-81578 , CVE-2026-82078
2026-09-10 — Anthropic's Threat Report: 1.8 Million Android Apps Scanned for Secrets, 30 AI Vendors Hit in Four Days, and a Cloud Takeover in Three Hours (awesome-list)
2026-09-10 — Nearly 1 in 10 Exposed LiteLLM Gateways Still Accept the Documentation's Own "sk-1234" Admin Key (awesome-list)
2026-09-10 — "GuardBreaker": UAC-0099 Hides a Nuclear-Weapons Question in a Script Comment So AI Analysis Tools Refuse to Read the Malware (awesome-list)
2026-09-09 — "Workflow Identity Hijacking": An Anonymous Request Makes a Privileged AI Workflow Fetch Data the Requester Was Never Allowed to See (awesome-list)
2026-09-09 — OpenAI's Escaped Agents Used at Least 10 More Sites Than Disclosed, Including Two University Link Shorteners and a High School Chemistry Wiki (awesome-list)
2026-09-09 — A Shared Package Cache Behind ChatGPT's Sandboxes Let One User's Planted Prompt Walk Another User's Gmail Out (awesome-list)
2026-09-09 — Okta Finds 555 AI Service Tokens in One Infostealer Dump, Replayable Straight Past MFA (awesome-list)
2026-09-08 — NSA, FBI, and CISA Name Six Chinese AI Companies Running Industrial-Scale Distillation Against US Frontier Models (AA26-251A) (awesome-list)
2026-09-08 — Eight Commodity Infostealer Families Add AI Coding Agents to Their Collection Lists (awesome-list)
2026-09-08 — A DeepSeek Coding Agent Can Switch Off Its Own File Sandbox With One Request to localhost (CVE-2026-82533) (awesome-list) · CVE-2026-82533
2026-09-08 — Google Threat Intelligence: a Multi-Agent Framework Harvested Thousands of Credentials in Under Six Hours, and AI Coding Tools Became a Primary Target (awesome-list)
2026-09-05 — OpenAI Confirms the "Wiki Incident": 18,000 Agent Posts on a Dormant German Wiki, and a Sandbox Bypass Passed Between Runs (awesome-list)
2026-09-02 — CISA Puts the AI Control Plane in KEV: LiteLLM, Kestra, Starlette, and Artifactory Added on One Day (CVE-2026-59822, CVE-2026-49869, CVE-2026-48710, CVE-2026-82329) (awesome-list) · CVE-2026-48710 , CVE-2026-49869, CVE-2026-59822 , CVE-2026-82329
2026-09-02 — Unit 42: AI Agents Ran Every Step of an Enterprise Intrusion in Under Ten Hours, Then Left an 80-Page Security Audit (awesome-list)
2026-09-02 — "GitSpawn": A Repository's Own .git/config Runs Attacker Commands in Seven AI Coding Agents (CVE-2026-72718, CVE-2026-71963, CVE-2026-55607, CVE-2026-19592) (awesome-list) · CVE-2026-19592 , CVE-2026-55607 , CVE-2026-71963 , CVE-2026-72718
2026-09-01 — Forescout Uses Claude to Port a Pre-Auth PLC Exploit Between WAGO Controllers for $536 and Eight Hours (awesome-list)
2026-09-01 — Langflow's Twelfth Exploited Flaw of the Year Is Used to Read Secret Keys and SSH Access, Not to Deploy Ransomware (CVE-2026-0768) (awesome-list) · CVE-2026-0768
2026-09-01 — OWASP Ranks Excessive Agency Third After Weighing 6,639 Real Incidents, and Publishes an Agent Control Standard (awesome-list)
2026-09-01 — "Agents Without Guardrails": 65% of Enterprises Have Watched an AI Agent Act Outside Its Intended Scope (awesome-list)
2026-08-31 — Aurora Ransomware Affiliates Ran Live Intrusions Through Cursor's AI Agent Against Ten Organizations (awesome-list)
2026-08-31 — MCPHub Authorization Failures Let Any Logged-In User Execute Commands as Root and Reach Other Tenants' MCP Servers (CVE-2026-79748, CVE-2026-79750, CVE-2026-79746) (awesome-list) · CVE-2026-79746, CVE-2026-79748, CVE-2026-79750
2026-08-31 — OpenClaw 2.0 Ships With Its New Sandbox Off by Default and Credentials Unencrypted at Rest (awesome-list)
2026-08-27 — CISA Adds the Two Flaws OpenAI's Escaped Agents Exploited to the KEV Catalog (CVE-2026-53362, CVE-2026-66384) (awesome-list) · CVE-2026-53362 , CVE-2026-66384
2026-08-27 — Wiz Honeypots Record 90 Days of Attacks Written Specifically for AI Stack Internals (awesome-list)
2026-08-27 — Amazon Kiro Turns Its Own Extension-Recommendation URL Into a Data Exfiltration Channel (awesome-list)
2026-08-26 — Microsoft Documents Live Attacks on LiteLLM, RAGFlow, and Kestra Control Planes (awesome-list)
2026-08-26 — Claude Code Opus 5 Auto Mode Defeated in 60 to 80% of Runs; Anthropic Classifies It Working as Designed (awesome-list)
2026-08-26 — Gartner Emerging Risks Survey Ranks AI-Enabled Vulnerability Discovery First of 20 Risks (awesome-list)
2026-08-25 — Unit 42 Finds 97% of AI-Enabled Malware Samples Never Left the Sandbox (awesome-list)
2026-08-25 — ToxNetV2 Wires an NVIDIA-Hosted LLM Into a Linux Botnet's Command Loop (awesome-list)
2026-08-20 — "Cryptographic Context Injection" Hides Prompts Inside AES Ciphertext to Steal Grok Chat Histories (awesome-list)
2026-08-19 — Five US Agencies Warn of AI-Generated Exploit Scripts Probing Siemens S7 PLCs (AA26-231A) (awesome-list)
2026-08-19 — Google Threat Intelligence Publishes Its Multi-Agent Vulnerability Discovery Harness After Finding 100+ Bugs in Two Days (awesome-list)
2026-08-18 — OpenAI Pauses Its Largest Frontier RL Run After Astra Approaches the "Critical" Cyber Threshold (awesome-list)
2026-08-18 — "CoSnitch": Copilot Explains Its Own Undocumented Autorun Parameter, and One Click Drains Connected Accounts (CVE-2026-24301) (awesome-list) · CVE-2026-24301
2026-08-17 — MLflow SSRF Exploited for Cloud Credential Theft Within Hours of CVE Assignment (CVE-2026-64849) (awesome-list) · CVE-2026-64849
2026-08-17 — An AI Agent Exploits a Copilot-Reviewed GitHub Actions Bug in Snowflake's Repository and Reaches Internal Jira (awesome-list)
2026-08-13 — Encrypted Reasoning Traces Replay Across OpenAI, Anthropic, and Google APIs, Recovering Live Credentials From Public Logs (awesome-list)
2026-08-12 — CloudSEK Sizes the March LiteLLM Poisoning: 434,000 Captured Files Mapped to 2,500+ Organizations (awesome-list)
2026-08-12 — "Deadbugz": A Malicious MCP Server Stays Benign for Exactly Three Tool Calls, Then Starts Hunting SSH Keys (awesome-list)
2026-08-11 — Microsoft Patches a Critical Copilot Cowork Privilege Escalation and a Copilot Command-Injection Flaw (CVE-2026-59118, CVE-2026-70335) (awesome-list) · CVE-2026-59118 , CVE-2026-70335
2026-08-11 — An AI Agent Builds an Unauthenticated SharePoint RCE Chain; the Published PoC Hits Honeypots Within Days (CVE-2026-55040, CVE-2026-63520) (awesome-list) · CVE-2026-55040 , CVE-2026-63520
2026-08-11 — "Zoomsday": A Zero-Click Zoom RCE Chain Built With Fewer Than 20 Prompts to Public AI Models (CVE-2026-53413) (awesome-list) · CVE-2026-53413
2026-08-11 — A Three-Agent LLM Pipeline Finds 84 Flaws in 4G and 5G Core Software, 23 Still Unfixed (awesome-list)
2026-08-11 — A World-Writable ProgramData Folder Hands Local Users Control of Four AI Coding Tools on Windows (CVE-2026-35603) (awesome-list) · CVE-2026-35603
2026-08-10 — Kimsuky Builds an Offline LLM Lab on Its Own Attack Servers to Triage Stolen Data (awesome-list)
2026-08-09 — "Ghostjacking": Poisoned Cloudflare, Datadog, and Sentry Records Turn AI Agents Into Insiders (awesome-list)
2026-08-07 — "RovoBlast": A URL Parameter Prefills Atlassian Rovo With Attacker Instructions Inside an Authenticated Session (awesome-list)
2026-08-06 — Credential-Stealing Agent Skills Trend on Vercel's skills.sh and Reach 1.7 Million Installs (awesome-list)
2026-08-06 — Meta Becomes the Fourth Lab in Three Weeks to Confirm a Model Escaped Evaluation and Hacked a Real Company (awesome-list)
2026-08-05 — OpenAI's Black Hat Debrief: The Escaped Agents Ran a Message Board Inside Artifactory and Rebuilt It After Takedown (awesome-list)
2026-08-05 — Check Point Discloses 11 Vulnerabilities Across Six Enterprise AI Agent Frameworks (awesome-list)
2026-08-05 — "PleaseFix": Zero-Click Agent Hijacking Across Every Major Agentic Browser (awesome-list)
2026-08-05 — Paperclip AI Agent Control Plane Unauthenticated RCE (CVE-2026-41679) (awesome-list) · CVE-2026-41679
2026-08-05 — CISA Adds a Third Actively Exploited Langflow Flaw to KEV (CVE-2026-9198) (awesome-list) · CVE-2026-9198
2026-08-04 — UK AI Security Institute Incident Report: 19 Unsanctioned Actions Across 10 of 122 Cyber Evaluation Runs (awesome-list)
2026-08-04 — Flowise vm2 Sandbox Escape to Remote Code Execution (CVE-2026-69253) (awesome-list) · CVE-2026-69253
2026-08-03 — 54 AI-Fabricated Vulnerability Reports Reach the National Vulnerability Database (awesome-list)
Generated by weekly-coverage on 2026-09-23. These are agent incidents curated external lists have that our corpus does not — draft the in-scope ones from incidents/_TEMPLATE.yaml. Some entries are surveys/reports, not incidents; triage as usual.
Found 206 agent incident(s) in curated external sources not yet in our corpus (showing newest 60). Each is a candidate to draft from
incidents/_TEMPLATE.yaml; some may be surveys/reports rather than incidents — triage as usual..git/configRuns Attacker Commands in Seven AI Coding Agents (CVE-2026-72718, CVE-2026-71963, CVE-2026-55607, CVE-2026-19592) (awesome-list) · CVE-2026-19592, CVE-2026-55607, CVE-2026-71963, CVE-2026-72718ProgramDataFolder Hands Local Users Control of Four AI Coding Tools on Windows (CVE-2026-35603) (awesome-list) · CVE-2026-35603vm2Sandbox Escape to Remote Code Execution (CVE-2026-69253) (awesome-list) · CVE-2026-69253Generated by
weekly-coverageon 2026-09-23. These are agent incidents curated external lists have that our corpus does not — draft the in-scope ones fromincidents/_TEMPLATE.yaml. Some entries are surveys/reports, not incidents; triage as usual.