Incident alerts
Get notified when new incidents are added.
This tracker is a recurring research asset. Subscribe for new sourced AI agent incidents and authorization breakdowns.
Updated July 2026 · Sourced reports only
AI agents are already deleting production data, leaking credentials, and executing tools nobody approved. Every incident below is sourced — and every one is missing the same control: authorization before execution.
98
documented incidents
40
critical severity
8
days since last incident
Every platform touched by a tracked incident
Incidents per month
Accelerating
July is month-to-date
Hugging Face breached: Autonomous AI agent swarm exfiltrates production DBs
Updated July 2026
Severity
Topic
Would PP block it?
Tool
Showing 98 of 98 sourced incidents.
Hugging Face disclosed that its production infrastructure was breached by an autonomous AI agent swarm. The attack initiated through the dataset processing pipeline, where a…
Autonomous AI Agent Swarm · Credential Gate
Wiz Research disclosed GhostApproval, a CWE-61 (symlink following) + CWE-451 (UI misrepresentation) attack that bypasses Human-in-the-Loop approval in five major AI coding agents:…
Claude Code / Amazon Q / Cursor / Google Antigravity / Windsurf · Tool-Call Gate
AI Now Institute published a proof-of-concept exploit on July 8, 2026, showing that prompt injections distributed across the source files of an ordinary open-source library cause…
Claude Code / OpenAI Codex CLI · Tool-Call Gate
Noma Labs disclosed GitLost, an indirect prompt injection vulnerability in GitHub Agentic Workflows — GitHub's new AI agent that reads Issues and executes Actions in natural…
GitHub Agentic Workflows · Tool-Call Gate
CISA added CVE-2026-55255 in Langflow to its Known Exploited Vulnerabilities catalog on July 7, 2026 — the first time an AI agent orchestration platform has appeared in the KEV.…
Langflow · Tool-Call Gate
Zscaler ThreatLabz published research on July 2, 2026 documenting two active campaigns exploiting indirect prompt injection to manipulate AI agents. Campaign 1 created a fake…
Multiple AI Agents (Llama 3.x, Gemini, Claude, GPT-5.4) · Tool-Call Gate
Cato AI Labs disclosed DuneSlide, two critical vulnerabilities in the Cursor AI code editor tracked as CVE-2026-50548 and CVE-2026-50549 (both CVSS 9.8). Both flaws exploit prompt…
Cursor AI · Tool-Call Gate
Sysdig Threat Research Team documented JADEPUFFER, the first confirmed agentic ransomware operation. An AI agent exploited CVE-2025-3248 (unauthenticated RCE in Langflow's code…
Langflow / Nacos · Data Mutation Gate
Adversa AI published GuardFall, research identifying five shell injection bypass classes that defeat the pattern-based command guards in 10 of 11 surveyed open-source AI coding…
10 Open-Source AI Coding Agents (GuardFall) · Tool-Call Gate
Four vulnerabilities in Dify — including critical CVE-2026-41947 and CVE-2026-41948 — allowed unauthenticated access and cross-tenant data exposure across an AI workflow platform…
Dify · Credential Gate
Threat actors exploited CVE-2026-33017, a critical unauthenticated RCE in Langflow (CVSS 9.3), in a sustained campaign observed between March 27 and April 15, 2026. By sending a…
Langflow · Runtime Gate
Security firm AIR created a fake skill named brand-landingpage that claimed to build landing pages using Google’s Stitch tool. The skill passed every scanner tested — Cisco,…
AIR Security / brand-landingpage · Runtime Gate
The pattern
Scanners, system prompts, and audit logs did not stop any of these. What was missing is external authorization at the action boundary — before the agent executes, not after.
Merge, deploy, migration, credential grant, or tool call — the gate holds it before anything runs.
Policy routes the request to a named signer who approves the exact action, not the general idea.
Receipt would bind: actor, tool, action, resource, environment, approver, expiry.
Incident alerts
This tracker is a recurring research asset. Subscribe for new sourced AI agent incidents and authorization breakdowns.
Submit an incident
Include the primary link, what happened, and the permission gap. We review before adding anything to the tracker.