PERMISSION/PROTOCOL

Updated July 2026 · Sourced reports only

AI Agent Incident Tracker

AI agents are already deleting production data, leaking credentials, and executing tools nobody approved. Every incident below is sourced — and every one is missing the same control: authorization before execution.

98

documented incidents

40

critical severity

8

days since last incident

Incidents per month

Accelerating

Aug
1
Sep
2
Oct
1
Nov
3
Dec
5
Jan
9
Feb
7
Mar
9
Apr
24
May
22
Jun
8
Jul

July is month-to-date

Latest incidentHigh

Hugging Face breached: Autonomous AI agent swarm exfiltrates production DBs

Tools involved:Claude CodeClaudeGitHub CopilotCursorGeminiOpenAI CodexReplitLiteLLMMCP

Updated July 2026

All tracked incidents

RSS feed

Showing 98 of 98 sourced incidents.

HighPP: Partial

Hugging Face breached: Autonomous AI agent swarm exfiltrates production DBs

Hugging Face disclosed that its production infrastructure was breached by an autonomous AI agent swarm. The attack initiated through the dataset processing pipeline, where a…

Autonomous AI Agent Swarm · Credential Gate

HighPP: Yes

Symlink attack fools HITL approval — Claude Code knew the risk and hid it

Wiz Research disclosed GhostApproval, a CWE-61 (symlink following) + CWE-451 (UI misrepresentation) attack that bypasses Human-in-the-Loop approval in five major AI coding agents:…

Claude Code / Amazon Q / Cursor / Google Antigravity / Windsurf · Tool-Call Gate

HighPP: Partial

Security-review agent hijacked for RCE via prompt injections in library files

AI Now Institute published a proof-of-concept exploit on July 8, 2026, showing that prompt injections distributed across the source files of an ordinary open-source library cause…

Claude Code / OpenAI Codex CLI · Tool-Call Gate

HighPP: Partial

Crafted issue tricks GitHub's AI agent into leaking private repos publicly

Noma Labs disclosed GitLost, an indirect prompt injection vulnerability in GitHub Agentic Workflows — GitHub's new AI agent that reads Issues and executes Actions in natural…

GitHub Agentic Workflows · Tool-Call Gate

HighPP: Partial

CISA KEV milestone — Langflow let any authenticated user run another user's flow

CISA added CVE-2026-55255 in Langflow to its Known Exploited Vulnerabilities catalog on July 7, 2026 — the first time an AI agent orchestration platform has appeared in the KEV.…

Langflow · Tool-Call Gate

HighPP: Yes

Hidden page prompts tricked AI agents into making unauthorized crypto payments

Zscaler ThreatLabz published research on July 2, 2026 documenting two active campaigns exploiting indirect prompt injection to manipulate AI agents. Campaign 1 created a fake…

Multiple AI Agents (Llama 3.x, Gemini, Claude, GPT-5.4) · Tool-Call Gate

HighPP: Partial

Zero-click prompt injection in Cursor disables its sandbox, runs any command

Cato AI Labs disclosed DuneSlide, two critical vulnerabilities in the Cursor AI code editor tracked as CVE-2026-50548 and CVE-2026-50549 (both CVSS 9.8). Both flaws exploit prompt…

Cursor AI · Tool-Call Gate

CriticalPP: Partial

Autonomous AI ransomware wiped Nacos production configs — no key, no recovery

Sysdig Threat Research Team documented JADEPUFFER, the first confirmed agentic ransomware operation. An AI agent exploited CVE-2025-3248 (unauthenticated RCE in Langflow's code…

Langflow / Nacos · Data Mutation Gate

HighPP: Partial

GuardFall: shell injection defeats command guards in 10 of 11 AI coding agents

Adversa AI published GuardFall, research identifying five shell injection bypass classes that defeat the pattern-based command guards in 10 of 11 surveyed open-source AI coding…

10 Open-Source AI Coding Agents (GuardFall) · Tool-Call Gate

HighPP: Partial

Two critical Dify CVEs expose every tenant's private AI conversations

Four vulnerabilities in Dify — including critical CVE-2026-41947 and CVE-2026-41948 — allowed unauthenticated access and cross-tenant data exposure across an AI workflow platform…

Dify · Credential Gate

HighPP: Partial

Unauth RCE in Langflow exploited to mine Monero and spread via SSH

Threat actors exploited CVE-2026-33017, a critical unauthenticated RCE in Langflow (CVSS 9.3), in a sustained campaign observed between March 27 and April 15, 2026. By sending a…

Langflow · Runtime Gate

HighPP: Partial

Staged payload defeats every scanner, reaches 26K agents via ClawHub

Security firm AIR created a fake skill named brand-landingpage that claimed to build landing pages using Google’s Stitch tool. The skill passed every scanner tested — Cisco,…

AIR Security / brand-landingpage · Runtime Gate

The pattern

Every incident is missing the same control.

Scanners, system prompts, and audit logs did not stop any of these. What was missing is external authorization at the action boundary — before the agent executes, not after.

1. Agent attempts the action

Merge, deploy, migration, credential grant, or tool call — the gate holds it before anything runs.

2. The right human signs

Policy routes the request to a named signer who approves the exact action, not the general idea.

3. A signed receipt is issued

Receipt would bind: actor, tool, action, resource, environment, approver, expiry.

Incident alerts

Get notified when new incidents are added.

This tracker is a recurring research asset. Subscribe for new sourced AI agent incidents and authorization breakdowns.

Submit an incident

Send a sourced incident for review.

Include the primary link, what happened, and the permission gap. We review before adding anything to the tracker.