Incident alerts
Get notified when new incidents are added.
This tracker is a recurring research asset. Subscribe for new sourced AI agent incidents and authorization breakdowns.
Updated June 2026 · Sourced reports only
AI agents are already deleting production data, leaking credentials, and executing tools nobody approved. Every incident below is sourced — and every one is missing the same control: authorization before execution.
84
documented incidents
39
critical severity
1
day since last incident
Every platform touched by a tracked incident
Incidents per month
Accelerating
June is month-to-date
Staged payload defeats every scanner, reaches 26K agents via ClawHub
Updated June 2026
Severity
Topic
Would PP block it?
Tool
Showing 84 of 84 sourced incidents.
Security firm AIR created a fake skill named brand-landingpage that claimed to build landing pages using Google’s Stitch tool. The skill passed every scanner tested — Cisco,…
AIR Security / brand-landingpage · Runtime Gate
Manifold Security found 23 plugins on ClawHub — the primary plugin registry for Claude Code, Cursor, and Codex — published under @openclaw/ and @clawhub/ organizational scopes by…
ClawHub · Runtime Gate
On June 17, 2026, an attacker used a dormant former Mastra contributor account (ehindero) whose scope permissions were never revoked to publish 144 malicious @mastra package…
Mastra / npm · Credential Gate
Sapphire Sleet (BlueNoroff, North Korean APT) hijacked a forgotten contributor account with npm publish access to the @mastra scope (1.1M weekly downloads). Over 88 minutes on…
Mastra · Deploy Gate
Varonis Threat Labs discovered SearchLeak (CVE-2026-42824), a chained vulnerability in Microsoft 365 Copilot Enterprise that lets an attacker exfiltrate emails, MFA codes, meeting…
Microsoft 365 Copilot · Tool-Call Gate
Presented at DEF CON Singapore (June 2026), CVE-2026-24299 'Copirate 365' chains four weaknesses: an indirect prompt injection via a booby-trapped document triggers CSS font-face…
Microsoft 365 Copilot · Tool-Call Gate
On June 12, 2026 at 5:21 PM ET, the US government issued an export control directive ordering Anthropic to suspend all access to Fable 5 and Mythos 5 by any foreign national.…
Anthropic Claude Fable 5 / Mythos 5 · Runtime Gate
CVE-2026-5027 is a path traversal vulnerability in Langflow, a popular open-source low-code platform for building AI agent workflows. The POST /api/v2/files endpoint did not…
Langflow · Runtime Gate
Check Point Research disclosed three chained CVEs in LangGraph's persistence layer. CVE-2025-67644 (CVSS 7.3) is a SQL injection in the SQLite checkpointer's metadata filter that…
LangGraph · Runtime Gate
CISA added CVE-2026-42271 in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog on June 8, 2026. The flaw resides in MCP server test endpoints…
BerriAI LiteLLM · Tool-Call Gate
Researchers at Tenet Security demonstrated "agentjacking" — an attack class that injects malicious Markdown instructions into Sentry error events via the platform's public ingest…
Sentry MCP · Tool-Call Gate
The Hades wave, part of the Miasma supply chain campaign, planted malicious hooks inside Claude Code, Cursor, Gemini CLI, and VS Code configuration files in compromised GitHub…
Miasma / Hades Supply Chain Campaign · Credential Gate
The pattern
Scanners, system prompts, and audit logs did not stop any of these. What was missing is external authorization at the action boundary — before the agent executes, not after.
Merge, deploy, migration, credential grant, or tool call — the gate holds it before anything runs.
Policy routes the request to a named signer who approves the exact action, not the general idea.
Receipt would bind: actor, tool, action, resource, environment, approver, expiry.
Incident alerts
This tracker is a recurring research asset. Subscribe for new sourced AI agent incidents and authorization breakdowns.
Submit an incident
Include the primary link, what happened, and the permission gap. We review before adding anything to the tracker.