Timeline

34 records by disclosure date, newest first. Status, sourcing confidence, AI role and severity are shown for each.

2026 (18)

  1. OpenAI research agent circumvented access controls on Services Australia's Medicare statistics portal — disclosed · Confirmed · Primary sourcing · AI load-bearing · Medium severity
    Autonomous attack · actor as stated: OpenAI internal research agent (unnamed model) operating in an internal research/evaluation context
  2. GTG-10007 Claude 'agent swarm' espionage and vulnerability-discovery program — disclosed · Confirmed · Primary sourcing · AI load-bearing · High severity
    AI-orchestrated campaign · actor as stated: Chinese-speaking operators (tracked by Anthropic as GTG-10007), two identified as university undergraduates; no state sponsorship asserted
  3. GTG-20006 agentic espionage against government, defense and diplomatic targets (Russia-nexus) — disclosed · Confirmed · Primary sourcing · AI significant · High severity
    AI-orchestrated campaign · actor as stated: Russia-nexus espionage actor (tracked by Anthropic as GTG-20006; attribution described as consistent with public reporting on Midnight Blizzard)
  4. GTG-50014 ShinyHunters-linked agentic mass data theft and extortion — disclosed · Confirmed · Primary sourcing · AI load-bearing · Critical severity
    AI-orchestrated campaign · actor as stated: Suspected ShinyHunters affiliates (tracked by Anthropic as GTG-50014)
  5. GTG-50020 autonomous exploitation pipeline against ~30 AI companies and theft of production API keys — disclosed · Confirmed · Primary sourcing · AI significant · High severity
    Infrastructure abuse / supply chain · actor as stated: Russian-speaking, financially motivated actor (tracked by Anthropic as GTG-50020)
  6. GTG-50029 single hacktivist's Claude-built mass privacy attack on European political targets — disclosed · Confirmed · Primary sourcing · AI significant · High severity
    AI-orchestrated campaign · actor as stated: Single French-speaking hacktivist (tracked by Anthropic as GTG-50029)
  7. Anthropic cybersecurity-evaluation agents reached real third-party systems (four incidents, 2026) — disclosed · Confirmed · Primary sourcing · AI load-bearing · High severity
    Autonomous attack · actor as stated: Anthropic evaluation agents (Claude Opus 4.7, Claude Mythos 5, an early Claude Opus 4.6 checkpoint and an internal research model) acting outside their intended scope during cybersecurity evaluations
  8. OpenAI evaluation agents escaped their sandbox and compromised Hugging Face production infrastructure — disclosed · Confirmed · Primary sourcing · AI load-bearing · High severity
    Autonomous attack · actor as stated: OpenAI evaluation agents (an internal-only research model and GPT-5.6 Sol) acting without authorization during ExploitGym cyber evaluations
  9. JADEPUFFER: agent-driven database extortion operation against an exposed AI-orchestration deployment — disclosed · Reported · Primary sourcing · AI significant · High severity
    Autonomous attack · actor as stated: Unknown
  10. Miasma worm: Azure/durabletask commit weaponized AI coding-agent configuration files; 73 Microsoft repositories disabled — disclosed · Reported · Primary sourcing · AI significant · High severity
    Infrastructure abuse / supply chain · actor as stated: TeamPCP (per StepSecurity, via command-and-control infrastructure linked to the same account's earlier PyPI attack; the June commit is not directly attributed)
  11. GTIG: criminal actor's AI-developed zero-day exploit against a web-based system administration tool — disclosed · Reported · Primary sourcing · AI significant · Medium severity
    AI-orchestrated campaign · actor as stated: Unknown criminal threat actor (unnamed by GTIG), in partnership with a prominent cybercrime actor
  12. PROMPTSPY — Android backdoor that delegates on-device UI actions to the Gemini API — disclosed · Confirmed · Primary sourcing · AI load-bearing · Medium severity
    Autonomous attack · actor as stated: Unknown
  13. Prompt injection of Grok drained a Grok-linked crypto wallet via the Bankr trading agent — disclosed · Reported · Secondary sourcing · AI load-bearing · Medium severity
    Agent hijack / prompt injection · actor as stated: Unknown
  14. Coral Sleet (North Korea) operationalizes agentic AI tools across its attack workflow — disclosed · Reported · Primary sourcing · AI significant · Medium severity
    AI-orchestrated campaign · actor as stated: Coral Sleet (North Korean state actor, formerly Storm-1877, per Microsoft Threat Intelligence)
  15. hackerbot-claw: self-described autonomous 'security research agent' exploiting GitHub Actions across open-source projects — disclosed · Confirmed · Primary sourcing · AI disputed · Medium severity
    Autonomous attack · actor as stated: Unknown
  16. OpenClaw agent deleted a researcher's emails and ignored stop commands — disclosed · Reported · Secondary sourcing · AI load-bearing · Low severity
    Autonomous attack · actor as stated: OpenClaw agent (autonomous)
  17. Clinejection: prompt injection of Cline's Claude issue-triage workflow led to an unauthorized npm release — disclosed · Confirmed · Primary sourcing · AI significant · High severity
    Agent hijack / prompt injection · actor as stated: Unknown (an "unauthorized party" per Cline; the researcher states a different actor reused his proof-of-concept)
  18. ClawHavoc: large-scale poisoning of the OpenClaw ClawHub skill marketplace with credential-stealing skills — disclosed · Confirmed · Primary sourcing · AI incidental · High severity
    Infrastructure abuse / supply chain · actor as stated: Unknown (operators identified only by ClawHub handles; financially motivated per Antiy CERT)

2025 (14)

  1. ServiceNow Now Assist agent-to-agent prompt injection (insecure defaults) — disclosed · Reported · Primary sourcing · AI load-bearing · High severity
    Agent hijack / prompt injection · actor as stated: AppOmni (AO Labs)
  2. GTG-1002 AI-orchestrated cyber-espionage campaign — disclosed · Confirmed · Primary sourcing · AI load-bearing · High severity
    AI-orchestrated campaign · actor as stated: Chinese state-sponsored group (tracked by Anthropic as GTG-1002)
  3. PROMPTFLUX — experimental self-modifying malware abusing the Gemini API — disclosed · Reported · Primary sourcing · AI significant · Low severity
    Infrastructure abuse / supply chain · actor as stated: Unknown
  4. PROMPTSTEAL / LAMEHUG — LLM-enabled data miner used against Ukraine — disclosed · Confirmed · Primary sourcing · AI load-bearing · High severity
    AI-orchestrated campaign · actor as stated: APT28 (FROZENLAKE), Russian government-backed
  5. CamoLeak — GitHub Copilot Chat prompt-injection data exfiltration — disclosed · Reported · Primary sourcing · AI load-bearing · Critical severity
    Agent hijack / prompt injection · actor as stated: Omer Mayraz (Legit Security)
  6. ForcedLeak — indirect prompt injection in Salesforce Agentforce — disclosed · Reported · Primary sourcing · AI load-bearing · Critical severity
    Agent hijack / prompt injection · actor as stated: Noma Security (Noma Labs)
  7. North Korean IT-worker remote-employment fraud using Claude — disclosed · Confirmed · Primary sourcing · AI significant · High severity
    Infrastructure abuse / supply chain · actor as stated: North Korean operatives (DPRK IT workers)
  8. GTG-2002 'vibe hacking' AI-driven data-extortion operation — disclosed · Confirmed · Primary sourcing · AI load-bearing · High severity
    AI-orchestrated campaign · actor as stated: Unknown cybercriminal (tracked by Anthropic as GTG-2002)
  9. GTG-5004 AI-assisted ransomware-as-a-service operation — disclosed · Confirmed · Primary sourcing · AI significant · High severity
    Infrastructure abuse / supply chain · actor as stated: UK-based threat actor (tracked by Anthropic as GTG-5004)
  10. Nx 's1ngularity' npm supply-chain attack weaponising AI CLI tools — disclosed · Confirmed · Primary sourcing · AI significant · Critical severity
    Infrastructure abuse / supply chain · actor as stated: Unknown
  11. PromptLock — first known AI-powered ransomware (academic proof-of-concept) — disclosed · Test / evaluation · Primary sourcing · AI load-bearing · Medium severity
    Lab escape / evaluation · actor as stated: NYU Tandon School of Engineering research team
  12. Amazon Q Developer VS Code extension compromise (data-wiping prompt injection) — disclosed · Confirmed · Primary sourcing · AI significant · High severity
    Infrastructure abuse / supply chain · actor as stated: lkmanka58
  13. Replit AI coding agent deleted a production database during a code freeze — disclosed · Confirmed · Secondary sourcing · AI load-bearing · High severity
    Autonomous attack · actor as stated: Replit AI agent (autonomous)
  14. EchoLeak — zero-click prompt injection in Microsoft 365 Copilot — disclosed · Confirmed · Primary sourcing · AI load-bearing · Critical severity
    Agent hijack / prompt injection · actor as stated: Aim Labs (Aim Security)

2024 (2)

  1. Morris II — self-replicating worm targeting GenAI-powered applications — disclosed · Test / evaluation · Primary sourcing · AI load-bearing · Medium severity
    Lab escape / evaluation · actor as stated: Researchers (Cohen, Bitton, Nassi — Technion / Intuit / Cornell Tech)
  2. Microsoft/OpenAI disruption of state-affiliated actors misusing LLMs (2024) — disclosed · Confirmed · Primary sourcing · AI incidental · Medium severity
    Infrastructure abuse / supply chain · actor as stated: Five state-affiliated actors: Forest Blizzard, Emerald Sleet, Crimson Sandstorm, Charcoal Typhoon, Salmon Typhoon