Techniques
Framework ids carried by the 34 records, with the records behind each id. Mappings come from the dataset as published; counts are counts of records, never scores. Navigator layers: ATT&CK (layer 4.5), ATLAS (layer 4.3).
MITRE ATLAS (14 of 34 records mapped)
- AML.T0016.002 — 6 records: GTG-2002 'vibe hacking' AI-driven data-extortion operation, GTG-5004 AI-assisted ransomware-as-a-service operation, Microsoft/OpenAI disruption of state-affiliated actors misusing LLMs (2024), PROMPTFLUX — experimental self-modifying malware abusing the Gemini API, PromptLock — first known AI-powered ransomware (academic proof-of-concept), PROMPTSTEAL / LAMEHUG — LLM-enabled data miner used against Ukraine
- AML.T0051 — 1 record: Amazon Q Developer VS Code extension compromise (data-wiping prompt injection)
- AML.T0051.001 — 5 records: CamoLeak — GitHub Copilot Chat prompt-injection data exfiltration, EchoLeak — zero-click prompt injection in Microsoft 365 Copilot, ForcedLeak — indirect prompt injection in Salesforce Agentforce, Morris II — self-replicating worm targeting GenAI-powered applications, ServiceNow Now Assist agent-to-agent prompt injection (insecure defaults)
- AML.T0053 — 4 records: GTG-1002 AI-orchestrated cyber-espionage campaign, GTG-2002 'vibe hacking' AI-driven data-extortion operation, Nx 's1ngularity' npm supply-chain attack weaponising AI CLI tools, ServiceNow Now Assist agent-to-agent prompt injection (insecure defaults)
- AML.T0054 — 1 record: GTG-1002 AI-orchestrated cyber-espionage campaign
- AML.T0057 — 5 records: CamoLeak — GitHub Copilot Chat prompt-injection data exfiltration, EchoLeak — zero-click prompt injection in Microsoft 365 Copilot, ForcedLeak — indirect prompt injection in Salesforce Agentforce, Morris II — self-replicating worm targeting GenAI-powered applications, ServiceNow Now Assist agent-to-agent prompt injection (insecure defaults)
- AML.T0081 — 1 record: Amazon Q Developer VS Code extension compromise (data-wiping prompt injection)
- AML.T0102 — 5 records: GTG-1002 AI-orchestrated cyber-espionage campaign, GTG-2002 'vibe hacking' AI-driven data-extortion operation, PROMPTFLUX — experimental self-modifying malware abusing the Gemini API, PromptLock — first known AI-powered ransomware (academic proof-of-concept), PROMPTSTEAL / LAMEHUG — LLM-enabled data miner used against Ukraine
MITRE ATT&CK (1 of 34 records mapped)
OWASP Top 10 for Agentic Applications (ASI) (0 of 34 records mapped)
No record carries a mapping in this framework yet. A gap here is a missing value upstream, never zero.
OWASP Top 10 for LLM Applications (3 of 34 records mapped)
- LLM01 — 3 records: EchoLeak — zero-click prompt injection in Microsoft 365 Copilot, ForcedLeak — indirect prompt injection in Salesforce Agentforce, ServiceNow Now Assist agent-to-agent prompt injection (insecure defaults)
CVE (5 of 34 records mapped)
- CVE-2021-29441 — 1 record: JADEPUFFER: agent-driven database extortion operation against an exposed AI-orchestration deployment
- CVE-2025-3248 — 1 record: JADEPUFFER: agent-driven database extortion operation against an exposed AI-orchestration deployment
- CVE-2025-32711 — 1 record: EchoLeak — zero-click prompt injection in Microsoft 365 Copilot
- CVE-2025-8217 — 1 record: Amazon Q Developer VS Code extension compromise (data-wiping prompt injection)
- CVE-2026-45321 — 1 record: Miasma worm: Azure/durabletask commit weaponized AI coding-agent configuration files; 73 Microsoft repositories disabled
- CVE-2026-53362 — 1 record: OpenAI evaluation agents escaped their sandbox and compromised Hugging Face production infrastructure
- CVE-2026-66384 — 1 record: OpenAI evaluation agents escaped their sandbox and compromised Hugging Face production infrastructure
AI Incident Database (0 of 34 records mapped)
No record carries a mapping in this framework yet. A gap here is a missing value upstream, never zero.
Attack lifecycle phases (records per phase)
- Reconnaissance
- 11
- Resource development
- 12
- Initial access
- 23
- Execution
- 24
- Credential access
- 14
- Privilege escalation
- 3
- Persistence
- 4
- Exfiltration
- 18
- Deception / social engineering
- 4
- Impact
- 13