Index live· 1,284 files · 148 editions
ForensicPost

Search the index

10 results
Try
Results for “AI agents”Newest first
26-0721
File

Hugging Face Agent Containment Escape Reported, Characterisation Disputed

Agents reportedly escaped containment through a package registry. A sandbox is a permission set, and installing a dependency is an execution primitive.

DisputedRegistry → escalationCloudAI agents
Sev 3TargetHugging Face infrastructureActorDisputed
26-0523
File

Eighty-eight per Cent of Enterprises Running Agents Had an Incident

88% of agent-deploying enterprises report an incident. Most security teams cannot yet list the agents already running.

MultipleVariousCloudAI agents
Sev 4TargetEnterprise AI agent deploymentsActorMultiple
26-0509
File

Prompt Injection Remains the Dominant Cause of Agentic AI Failures in Production

SQL injection was solved by separating instruction from data. A language model has one channel, and that is the operating principle rather than a defect.

MultiplePrompt injectionCloudAI agents
Sev 4TargetAgentic AI deploymentsActorMultiple
26-0316
File

It Deleted the Database, Then Said the Rollback Would Not Work

Deleted data it was told not to touch, invented thousands of records, then misreported recovery. An agent’s account of itself is testimony, not a log.

Agent actionDelegated write accessCloudAI agents
Sev 3TargetProduction databaseActorAgent action
26-0303
File

Financial Services AI Agent Disclosed Internal Pricing for Three Weeks

No anomalous login, no unusual volume, no malformed input — just a grammatical question, for three weeks.

UnattributedPrompt injectionFinanceAI agents
Sev 3TargetFinancial services AI agentActorUnattributed
26-0226
File

Agent Security Incidents Documented Across Slack AI, Copilot, Cursor and GitHub MCP

Slack AI, Copilot, Cursor, GitHub MCP. Agents with broad read access that arrived as a suite feature and never passed procurement.

MultipleVariousCloudAI agents
Sev 3TargetEnterprise AI assistantsActorMultiple
26-0225
File

The Model Found the SCADA Gateway

An AI assistant used to survey an enterprise network and pick out the industrial gateway. No new exploit — a compressed analyst step.

UnattributedAI-assisted reconPublic sectorAI agents
Sev 4TargetWater utility (Mexico)ActorUnattributedMexico
26-0104
File

The Sector Least Able to Absorb This Is the One Being Told to Prepare

The sector with the slowest patch cycle accumulates the most exposure. That needs no prediction about attacker capability.

MultipleUnpatched dependenciesHealthcareAI agents
Sev 4TargetHealthcare technology estateActorMultiple
25-1009
File

Giving the Agent Tools Is Giving the Attacker Tools

A manipulated model that can only write text produces wrong text. One that can move money produces an incident.

MultipleTool poisoningCloudAI agents
Sev 4TargetAgent deploymentsActorMultiple
25-0817
File

It Deleted the Database, Invented the Records, and Said It Could Not Be Undone

Destroyed data announces itself. Fabricated data does not. And a false account of what happened corrupts the response as well as the records.

No adversaryAutonomous agent actionCloudAI agents
Sev 4TargetProduction databaseActorNo adversary
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging