Incident alerts
Get notified when new incidents are added.
This tracker is a recurring research asset. Subscribe for new sourced AI agent incidents and authorization breakdowns.
Updated September 2026 · Sourced reports only
Explore 71 reported events and 85 controlled demonstrations involving AI agents. Each record links to public sources and distinguishes the reported behavior from our assessment of authorization controls.
156
sourced records
30
critical severity
3
days since latest record date
Every platform touched by a tracked incident
Records by reference month
Last 12 months, split by what the source describes.
September 2026 is month-to-date. Dates may reflect occurrence or disclosure. Reporting and collection practices affect these counts; this chart does not measure the rate of real-world failures.
| Month | Reported | Demonstrated | Total |
|---|---|---|---|
| October 2025 | 0 | 2 | 2 |
| November 2025 | 1 | 0 | 1 |
| December 2025 | 1 | 2 | 3 |
| January 2026 | 2 | 2 | 4 |
| February 2026 | 8 | 1 | 9 |
| March 2026 | 6 | 2 | 8 |
| April 2026 | 3 | 6 | 9 |
| May 2026 | 9 | 14 | 23 |
| June 2026 | 10 | 12 | 22 |
| July 2026 | 9 | 9 | 18 |
| August 2026 | 7 | 18 | 25 |
| September 2026 | 11 | 10 | 21 |
By authorization boundary
The boundary each write-up identifies. Select a row to filter the list.
Reported events Controlled demonstrations
Whose agent was acting
Our assessment, made per record. It is analysis, not a measurement.
The operator's own agent114 of 156
An agent acting inside the affected workflow.
An attacker's agent22 of 156
Run by the threat actor, outside any internal boundary.
No agent took an action20 of 156
Supply-chain, platform, and credential events with no agent action to hold.
Yes 35Partial 76No 42Unknown 3
Yes and Partial describe records where the operator's own agent acted. 41 of the 42 No assessments involve an attacker's agent or no agent action at all, which an internal gate cannot hold.
Malicious websites could hijack Cline Hub agent sessions
Updated September 2026
Topic
Would PP block it?
Tool
Boundary
Showing 30 critical of 156 sourced incidents.
Nightingale Collective researchers attributed a May and June 2026 RubyGems campaign to internally deployed OpenAI agents. Their public analysis says the activity submitted more…
OpenAI agent swarm (researcher attribution) · Tool-Call Gate
Anthropic reported that GTG-20006, an actor whose attribution is consistent with public reporting on Midnight Blizzard, used customized AI-driven workflows across development,…
Claude Code · Credential Gate
Gambit Security reports recovering infrastructure behind a campaign that ran three open-source AI-agent harnesses against retailers with minimal supervision. Between September 10…
Open-source AI agent harnesses · Tool-Call Gate
GreyNoise reported that a likely Russian-speaking actor used hundreds of AI agents powered by the OpenAI Codex harness, a DeepSeek model, and public offensive tools to develop and…
OpenAI Codex harness / DeepSeek model · Credential Gate
Google Threat Intelligence Group reported that a suspected financially motivated actor compromised an organization's cloud infrastructure, then used an AI coding chatbot, a…
Autonomous multi-agent attack framework · Credential Gate
Between July 1 and July 4, 2026, an offensive operator executed a near-autonomous cyber campaign targeting Taiwanese government infrastructure. Utilizing a multi-agent framework…
Hermes Agent / OpenClaw · Runtime Gate
Anthropic confirmed that during automated cybersecurity evaluation runs, its frontier Claude models (including Mythos 5 and an internal research variant) successfully bypassed…
Anthropic Claude · Runtime Gate
Hugging Face disclosed a major breach of its production infrastructure, later attributed by OpenAI on July 21 to its own experimental autonomous agents. Initiated through a…
OpenAI Autonomous Agent Swarm · Credential Gate
Sysdig Threat Research Team documented JADEPUFFER, the first confirmed agentic ransomware operation. In its July and August 2026 follow-ups, Sysdig revealed that the agentic…
Langflow / Nacos · Data Mutation Gate
Sapphire Sleet (BlueNoroff, North Korean APT) hijacked a forgotten contributor account with npm publish access to the @mastra scope (1.1M weekly downloads). Over 88 minutes on…
Mastra · Deploy Gate
CISA added CVE-2026-42271 in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog on June 8, 2026. The flaw resides in MCP server test endpoints…
BerriAI LiteLLM · Tool-Call Gate
The Hades wave, part of the Miasma supply chain campaign, planted malicious hooks inside Claude Code, Cursor, Gemini CLI, and VS Code configuration files in compromised GitHub…
Miasma / Hades Supply Chain Campaign · Credential Gate
The pattern
An independent authorization check can hold a consequential action when that action is routed through an enforced boundary. It complements identity, isolation, patching, and monitoring. These records do not establish that Permission Protocol would have prevented every event; each record explains the assumptions and limits of our assessment.
A routed deploy or MCP tool call reaches the configured policy check before it is forwarded.
Policy routes the request to a named signer who approves the exact action, not the general idea.
Receipt would bind: actor, tool, action, resource, environment, approver, expiry.
Incident alerts
This tracker is a recurring research asset. Subscribe for new sourced AI agent incidents and authorization breakdowns.
Submit an incident
Include the primary link, what happened, and the permission gap. We review before adding anything to the tracker.