Desk live·
ForensicPost
AI/AI agents/File 26-0226

Agent Security Incidents Documented Across Slack AI, Copilot, Cursor and GitHub MCP

Documented agent security incidents span Slack AI, Microsoft 365 Copilot, Cursor, GitHub MCP and coding assistants. The threat moved from demonstration to deployed enterprise software.

Constructed geometry · not a chart of case data
TargetEnterprise AI assistants
ActorMultiple
D. Kennedy9 min readConfidence: medium2 sources reviewed

Curated timelines of AI agent security incidents through 2024–2026 record issues affecting Slack AI, Microsoft 365 Copilot, Cursor, GitHub MCP and multiple coding assistants.

Two years ago the equivalent list would have been research demonstrations against chat interfaces. It is now a list of software that reads corporate mail, chat history and source repositories.

Integration Depth Sets The Consequence

These products are useful in proportion to how much they can see. An assistant that cannot read your messages cannot summarise them; one that cannot read the repository cannot suggest a change.

That produces a direct relationship between usefulness and blast radius which no configuration resolves. The value proposition is the access.

Deployed By Default, Inventoried By Nobody

The governance problem is compounded because much of this arrived as a feature rather than a purchase. An assistant appears in a suite the organisation already licenses, enabled by default or by an administrator clicking accept, without the review a new vendor would attract.

The result is agents with broad read access across the corporate estate that never passed through procurement, never appeared in a risk register, and are not in scope for any access review — the enumeration problem filed in 26-0523, arriving through the front door.

Graded medium. These are documented issues of varying severity aggregated by third parties, not a single verified incident.

How we reported this

Compiled from published incident timelines and research, listed below. Individual issues vary widely in severity and disclosure status; we describe the pattern rather than characterising any specific product’s security posture. Corrections: corrections@forensicpost.com.

Sources
  1. A curated timeline of real AI agent security incidents, breaches and vulnerabilities (2024–2026)awesome-ai-agent-attacks
  2. The comprehensive guide to prompt injection attacks in 2026Sysdig
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary