PERMISSION/PROTOCOL

Updated June 2026 · Sourced reports only

AI Agent Incident Tracker

AI agents are already deleting production data, leaking credentials, and executing tools nobody approved. Every incident below is sourced — and every one is missing the same control: authorization before execution.

84

documented incidents

39

critical severity

1

day since last incident

Incidents per month

Accelerating

3
Jul
Aug
1
Sep
2
Oct
1
Nov
3
Dec
5
Jan
9
Feb
6
Mar
9
Apr
24
May
17
Jun

June is month-to-date

Latest incidentHigh

Staged payload defeats every scanner, reaches 26K agents via ClawHub

Tools involved:Claude CodeClaudeGitHub CopilotCursorGeminiOpenAI CodexReplitLiteLLMMCP

Updated June 2026

All tracked incidents

RSS feed

Showing 84 of 84 sourced incidents.

HighPP: Partial

Staged payload defeats every scanner, reaches 26K agents via ClawHub

Security firm AIR created a fake skill named brand-landingpage that claimed to build landing pages using Google’s Stitch tool. The skill passed every scanner tested — Cisco,…

AIR Security / brand-landingpage · Runtime Gate

HighPP: Partial

23 plugins squat @openclaw/ and @clawhub/ scopes on the ClawHub registry

Manifold Security found 23 plugins on ClawHub — the primary plugin registry for Claude Code, Cursor, and Codex — published under @openclaw/ and @clawhub/ organizational scopes by…

ClawHub · Runtime Gate

HighPP: Partial

144 Mastra npm AI agent packages backdoored via typosquat RAT, LLM keys targeted

On June 17, 2026, an attacker used a dormant former Mastra contributor account (ehindero) whose scope permissions were never revoked to publish 144 malicious @mastra package…

Mastra / npm · Credential Gate

CriticalPP: Partial

Sapphire Sleet hijacked Mastra npm, injected RAT into 1.1M weekly downloads

Sapphire Sleet (BlueNoroff, North Korean APT) hijacked a forgotten contributor account with npm publish access to the @mastra scope (1.1M weekly downloads). Over 88 minutes on…

Mastra · Deploy Gate

HighPP: Partial

One malicious link made Copilot exfiltrate your email and MFA codes

Varonis Threat Labs discovered SearchLeak (CVE-2026-42824), a chained vulnerability in Microsoft 365 Copilot Enterprise that lets an attacker exfiltrate emails, MFA codes, meeting…

Microsoft 365 Copilot · Tool-Call Gate

HighPP: Partial

A booby-trapped document gives M365 Copilot a persistent backdoor

Presented at DEF CON Singapore (June 2026), CVE-2026-24299 'Copirate 365' chains four weaknesses: an indirect prompt injection via a booby-trapped document triggers CSS font-face…

Microsoft 365 Copilot · Tool-Call Gate

HighPP: Partial

US govt shuts down Fable 5 globally — jailbreak, no advance notice

On June 12, 2026 at 5:21 PM ET, the US government issued an export control directive ordering Anthropic to suspend all access to Fable 5 and Mythos 5 by any foreign national.…

Anthropic Claude Fable 5 / Mythos 5 · Runtime Gate

HighPP: Partial

No-auth path traversal in Langflow left 7,000 AI pipelines open to RCE

CVE-2026-5027 is a path traversal vulnerability in Langflow, a popular open-source low-code platform for building AI agent workflows. The POST /api/v2/files endpoint did not…

Langflow · Runtime Gate

HighPP: Partial

LangGraph checkpoint SQL injection chains to full RCE on self-hosted agents

Check Point Research disclosed three chained CVEs in LangGraph's persistence layer. CVE-2025-67644 (CVSS 7.3) is a SQL injection in the SQLite checkpointer's metadata filter that…

LangGraph · Runtime Gate

CriticalPP: Partial

Actively exploited: LiteLLM flaw chains to full RCE (CVSS 10.0)

CISA added CVE-2026-42271 in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog on June 8, 2026. The flaw resides in MCP server test endpoints…

BerriAI LiteLLM · Tool-Call Gate

CriticalPP: Partial

Fake Sentry errors hijack AI coding agents — 85% success, 2,388 orgs exposed

Researchers at Tenet Security demonstrated "agentjacking" — an attack class that injects malicious Markdown instructions into Sentry error events via the platform's public ingest…

Sentry MCP · Tool-Call Gate

CriticalPP: Partial

Hades worm poisoned AI tool config files to steal 294K developer secrets

The Hades wave, part of the Miasma supply chain campaign, planted malicious hooks inside Claude Code, Cursor, Gemini CLI, and VS Code configuration files in compromised GitHub…

Miasma / Hades Supply Chain Campaign · Credential Gate

The pattern

Every incident is missing the same control.

Scanners, system prompts, and audit logs did not stop any of these. What was missing is external authorization at the action boundary — before the agent executes, not after.

1. Agent attempts the action

Merge, deploy, migration, credential grant, or tool call — the gate holds it before anything runs.

2. The right human signs

Policy routes the request to a named signer who approves the exact action, not the general idea.

3. A signed receipt is issued

Receipt would bind: actor, tool, action, resource, environment, approver, expiry.

Incident alerts

Get notified when new incidents are added.

This tracker is a recurring research asset. Subscribe for new sourced AI agent incidents and authorization breakdowns.

Submit an incident

Send a sourced incident for review.

Include the primary link, what happened, and the permission gap. We review before adding anything to the tracker.