Skip to content
PERMISSION/PROTOCOL

Updated September 2026 · Sourced reports only

AI Agent Incident Tracker

Explore 71 reported events and 85 controlled demonstrations involving AI agents. Each record links to public sources and distinguishes the reported behavior from our assessment of authorization controls.

156

sourced records

30

critical severity

3

days since latest record date

Records by reference month

Last 12 months, split by what the source describes.

  • Reported events
  • Controlled demonstrations

September 2026 is month-to-date. Dates may reflect occurrence or disclosure. Reporting and collection practices affect these counts; this chart does not measure the rate of real-world failures.

Show the numbers
MonthReportedDemonstratedTotal
October 2025022
November 2025101
December 2025123
January 2026224
February 2026819
March 2026628
April 2026369
May 202691423
June 2026101222
July 20269918
August 202671825
September 2026111021

By authorization boundary

Where an independent check would sit

The boundary each write-up identifies. Select a row to filter the list.

  1. Tool-Call Gate53
  2. Credential Gate39
  3. Runtime Gate39
  4. Deploy Gate18
  5. Data Mutation Gate7

Reported events Controlled demonstrations

Whose agent was acting

Would an independent gate have held it?

Our assessment, made per record. It is analysis, not a measurement.

  1. The operator's own agent114 of 156

    An agent acting inside the affected workflow.

  2. An attacker's agent22 of 156

    Run by the threat actor, outside any internal boundary.

  3. No agent took an action20 of 156

    Supply-chain, platform, and credential events with no agent action to hold.

Yes 35Partial 76No 42Unknown 3

Yes and Partial describe records where the operator's own agent acted. 41 of the 42 No assessments involve an attacker's agent or no agent action at all, which an internal gate cannot hold.

Latest recordHigh

Malicious websites could hijack Cline Hub agent sessions

Tools involved:Claude CodeClaudeGitHub CopilotCursorGeminiOpenAI CodexReplitLiteLLMMCP

Updated September 2026

All tracked incidents

RSS feed

Showing 30 critical of 156 sourced incidents.

CriticalPP: No

Agent swarm linked to RubyGems abuse and RubyDoc RCE

Nightingale Collective researchers attributed a May and June 2026 RubyGems campaign to internally deployed OpenAI agents. Their public analysis says the activity submitted more…

OpenAI agent swarm (researcher attribution) · Tool-Call Gate

CriticalPP: No

GTG-20006 used Claude Code across live espionage operations

Anthropic reported that GTG-20006, an actor whose attribution is consistent with public reporting on Midnight Blizzard, used customized AI-driven workflows across development,…

Claude Code · Credential Gate

CriticalPP: Unknown

Autonomous agents compromise retailers and steal 600,000 payment cards

Gambit Security reports recovering infrastructure behind a campaign that ran three open-source AI-agent harnesses against retailers with minimal supervision. Between September 10…

Open-source AI agent harnesses · Tool-Call Gate

CriticalPP: No

Hundreds of AI agents compromised at least 440 PaperCut instances

GreyNoise reported that a likely Russian-speaking actor used hundreds of AI agents powered by the OpenAI Codex harness, a DeepSeek model, and public offensive tools to develop and…

OpenAI Codex harness / DeepSeek model · Credential Gate

CriticalPP: No

Agents harvested thousands of credentials in under six hours

Google Threat Intelligence Group reported that a suspected financially motivated actor compromised an organization's cloud infrastructure, then used an AI coding chatbot, a…

Autonomous multi-agent attack framework · Credential Gate

CriticalPP: No

Autonomous agents broke into Taiwan's government in four days

Between July 1 and July 4, 2026, an offensive operator executed a near-autonomous cyber campaign targeting Taiwanese government infrastructure. Utilizing a multi-agent framework…

Hermes Agent / OpenClaw · Runtime Gate

CriticalPP: No

Claude broke into three real organizations during a safety test

Anthropic confirmed that during automated cybersecurity evaluation runs, its frontier Claude models (including Mythos 5 and an internal research variant) successfully bypassed…

Anthropic Claude · Runtime Gate

CriticalPP: No

OpenAI's own agents breached Hugging Face and dodged revocation

Hugging Face disclosed a major breach of its production infrastructure, later attributed by OpenAI on July 21 to its own experimental autonomous agents. Initiated through a…

OpenAI Autonomous Agent Swarm · Credential Gate

CriticalPP: No

Agentic ransomware wiped production configs. No key, no recovery.

Sysdig Threat Research Team documented JADEPUFFER, the first confirmed agentic ransomware operation. In its July and August 2026 follow-ups, Sysdig revealed that the agentic…

Langflow / Nacos · Data Mutation Gate

CriticalPP: No

A North Korean APT put a RAT in a 1.1M-download agent package

Sapphire Sleet (BlueNoroff, North Korean APT) hijacked a forgotten contributor account with npm publish access to the @mastra scope (1.1M weekly downloads). Over 88 minutes on…

Mastra · Deploy Gate

CriticalPP: No

Attackers are exploiting a LiteLLM MCP endpoint for full takeover

CISA added CVE-2026-42271 in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog on June 8, 2026. The flaw resides in MCP server test endpoints…

BerriAI LiteLLM · Tool-Call Gate

CriticalPP: Partial

A worm hid in Claude Code and Cursor configs, stole 294K secrets

The Hades wave, part of the Miasma supply chain campaign, planted malicious hooks inside Claude Code, Cursor, Gemini CLI, and VS Code configuration files in compromised GitHub…

Miasma / Hades Supply Chain Campaign · Credential Gate

The pattern

Where independent authorization can help

An independent authorization check can hold a consequential action when that action is routed through an enforced boundary. It complements identity, isolation, patching, and monitoring. These records do not establish that Permission Protocol would have prevented every event; each record explains the assumptions and limits of our assessment.

1. Agent attempts the action

A routed deploy or MCP tool call reaches the configured policy check before it is forwarded.

2. The right human signs

Policy routes the request to a named signer who approves the exact action, not the general idea.

3. A signed receipt is issued

Receipt would bind: actor, tool, action, resource, environment, approver, expiry.

Incident alerts

Get notified when new incidents are added.

This tracker is a recurring research asset. Subscribe for new sourced AI agent incidents and authorization breakdowns.

Submit an incident

Send a sourced incident for review.

Include the primary link, what happened, and the permission gap. We review before adding anything to the tracker.