Curated timelines of AI agent security incidents through 2024–2026 record issues affecting Slack AI, Microsoft 365 Copilot, Cursor, GitHub MCP and multiple coding assistants.
Two years ago the equivalent list would have been research demonstrations against chat interfaces. It is now a list of software that reads corporate mail, chat history and source repositories.
Integration Depth Sets The Consequence
These products are useful in proportion to how much they can see. An assistant that cannot read your messages cannot summarise them; one that cannot read the repository cannot suggest a change.
That produces a direct relationship between usefulness and blast radius which no configuration resolves. The value proposition is the access.
Deployed By Default, Inventoried By Nobody
The governance problem is compounded because much of this arrived as a feature rather than a purchase. An assistant appears in a suite the organisation already licenses, enabled by default or by an administrator clicking accept, without the review a new vendor would attract.
The result is agents with broad read access across the corporate estate that never passed through procurement, never appeared in a risk register, and are not in scope for any access review — the enumeration problem filed in 26-0523, arriving through the front door.
Graded medium. These are documented issues of varying severity aggregated by third parties, not a single verified incident.
Compiled from published incident timelines and research, listed below. Individual issues vary widely in severity and disclosure status; we describe the pattern rather than characterising any specific product’s security posture. Corrections: corrections@forensicpost.com.