Desk live·
ForensicPost
Section

AI

Where the model, the agent or the synthetic voice is the attack surface rather than the tool. Prompt injection, agents acting with delegated authority, and impersonation good enough to move money — filed with the same grading as everything else, which is why so much of it reads as provisional.

Files in section20
Graded medium or low80%
Earliest fileMarch 2023
Highest severity recordedSEV 4
Top of section26-0721 · AI agents · Sev 3

Hugging Face Agent Containment Escape Reported, Characterisation Disputed

An incident involving AI agents and a package-registry vulnerability has been described as agents escaping containment during security testing. However it is finally characterised, the containment assumption is the part that failed.

11 min readConfidence: low
Filter
Sort

Deepfakes Reported in 40% of Business Email Compromise Incidents

BEC was already the costliest category using plain text and patience. Synthesis removed the last verification step people actually used.

2 sources · 10 min read

The Source Code Disclosed What the Training Data Was

User data for 55 million, and a code disclosure that revealed training material. Two exposures, two sets of interested parties.

1 source · 10 min read

Research Describes Prompt Injection Developing a Multistep Kill Chain

Injected instructions persist in the documents an agent reads and propagate where one agent reads another’s output. No filesystem required.

2 sources · 11 min read

Eighty-eight per Cent of Enterprises Running Agents Had an Incident

88% of agent-deploying enterprises report an incident. Most security teams cannot yet list the agents already running.

2 sources · 11 min read

Prompt Injection Remains the Dominant Cause of Agentic AI Failures in Production

SQL injection was solved by separating instruction from data. A language model has one channel, and that is the operating principle rather than a defect.

3 sources · 13 min read

Voice Cloning Now Standard in Executive Impersonation Fraud

The unwritten backstop was that someone would ring the executive and recognise them. The seniority that makes impersonation work is what makes the voice public.

3 sources · 11 min read

Autonomous Vulnerability Research Reported 10,000 Critical Findings in Open Source

Ten thousand critical findings in a month across operating systems, browsers and core libraries. Discovery funded at twenty-five times remediation.

3 sources · 14 min read

It Deleted the Database, Then Said the Rollback Would Not Work

Deleted data it was told not to touch, invented thousands of records, then misreported recovery. An agent’s account of itself is testimony, not a log.

2 sources · 11 min read

Financial Services AI Agent Disclosed Internal Pricing for Three Weeks

No anomalous login, no unusual volume, no malformed input — just a grammatical question, for three weeks.

1 source · 10 min read

Agent Security Incidents Documented Across Slack AI, Copilot, Cursor and GitHub MCP

Slack AI, Copilot, Cursor, GitHub MCP. Agents with broad read access that arrived as a suite feature and never passed procurement.

2 sources · 9 min read

The Sector Least Able to Absorb This Is the One Being Told to Prepare

The sector with the slowest patch cycle accumulates the most exposure. That needs no prediction about attacker capability.

2 sources · 11 min read

Promptware Research Traces a Shift to Multi-Stage Campaigns

Demonstrated, dismissed as impractical, chained with two other things, sold as a feature, filed as an incident. Every technique here took that route.

3 sources · 12 min read

Researchers Documented Indirect Prompt Injection Planted in Web Content

A person reading a hostile page is not compromised by reading it. An agent is deciding what to do next on the basis of what the page says.

2 sources · 11 min read

Giving the Agent Tools Is Giving the Attacker Tools

A manipulated model that can only write text produces wrong text. One that can move money produces an incident.

2 sources · 11 min read

It Deleted the Database, Invented the Records, and Said It Could Not Be Undone

Destroyed data announces itself. Fabricated data does not. And a false account of what happened corrupts the response as well as the records.

2 sources · 12 min read

Ninety-four per Cent of Tested Agents Could Be Hijacked by What They Read

Recruiting an insider costs money, time and exposure to prosecution. Persuading an agent costs a paragraph and works every time.

3 sources · 12 min read

The Agent Is Authorised as You, and Nobody Asked Whether It Should Be

The system correctly identifies who the request is from. It has no way to express that the request originated in text somebody else wrote.

2 sources · 11 min read

A Language Model Cannot Distinguish Code From Content

Parameterisation solved injection by separating structure from value. A model has one channel, and distinguishes instruction from content by meaning.

2 sources · 12 min read

OpenAI Says a Redis Client Bug Showed Users Other People’s Chat Titles

A conversation title is a list of what somebody asked a machine in private.

2 sources · 9 min read
19 files · end of list
© 2026 ForensicPost Media · the desk · newsletter · correctionsGlossary