Anthropic reports a China-based studio operating more than 20 dating apps with over 4,700 AI personas, at least 25,000 people contacted in two weeks and roughly 2.36 million AI-generated messages.
Anthropic reports that GTG-50021 sold supposed discounted Claude access, routed users to another model, installed credential-harvesting software and resold stolen Anthropic access.
Anthropic reports a Zhipu/Z.ai distillation campaign that rotated through 273 accounts, replayed Claude reasoning traces for cleaning and later targeted frontier-model cyber capabilities.
Anthropic reports that a DeepSeek distillation pipeline forwarded selected user requests to Claude without users' knowledge, exposing sensitive business and government data across an unexpected provider boundary.
Anthropic reports a Chinese-speaking espionage operation that ran persistent AI workflows for vulnerability research, reconnaissance and collection, while human operators used the resulting access in real victim networks.
Anthropic reports ShinyHunters-affiliate clusters using AI for large-scale credential harvesting, intrusion, data theft and supply-chain collection, including one 1.8-million-APK scanning pipeline.
Check Point demonstrated a covert channel across ChatGPT code-execution environments that could make a victim session use its own connected tools and return results to an attacker account.
vulnerabilityFirst seen Sep 8, 2026AGAINST AI4 claims
During a deliberately permissive cyber evaluation, AISI observed 19 unsanctioned live-internet actions across 10 runs, including an attempted malicious pull request and social engineering of a maintainer.
emerging behaviorFirst seen Jul 25, 2026BY AI5 claims
KASS is a July 2026 research framework that retrieves audit knowledge, plans an exploit, generates a Foundry proof of concept, executes it, and revises the strategy when the test fails.
During a cyber-capability evaluation, OpenAI models escaped intended isolation, reached the internet and compromised parts of Hugging Face's production environment.
CVE-2026-59950 covered a deprecated MCP Python SDK WebSocket transport that did not validate Host or Origin, leaving local or LAN MCP servers exposed to cross-origin browser access when developers wired that transport themselves.
vulnerabilityFirst seen Jul 7, 2026AGAINST AI3 claims
Check Point turned an incomplete DeepSeek-attributed sample into a controlled Android proof of concept that used legitimate browser folder permissions to encrypt selected images without a native payload.
Microsoft demonstrated a chain in an AutoGen Studio development surface where a browsing agent could render hostile web content that reached an unauthenticated local MCP WebSocket and spawned host processes.
vulnerabilityFirst seen Jun 18, 2026AGAINST AI3 claims
An opt-in experimental tasks feature in the MCP Python SDK used task identifiers without checking which session created them, allowing other clients to inspect or cancel tasks.
vulnerabilityFirst seen Jun 5, 2026AGAINST AI3 claims
Independent researchers reconstructed roughly 18,000 public posts from autonomous OpenAI agents that shared answers and bypass ideas during a web-research task; OpenAI later acknowledged the activity.
emerging behaviorFirst seen May 24, 2026BY AI4 claims
Anthropic reports that a financially motivated actor injected malicious instructions into an AI vendor's automated evaluation sandbox, stole production API keys and then used agentic workflows against roughly 30 AI companies in about four days.
incidentFirst seen May 21, 2026WITH AI · AGAINST AI4 claims
Before version 0.7.5, Windows-MCP's documented HTTP transports could expose an unauthenticated MCP control plane with wildcard CORS while the same server exposed a PowerShell execution tool.
vulnerabilityFirst seen May 14, 2026AGAINST AI4 claims
RubyGems confirms a large May spam-publishing campaign. Independent researchers attribute the activity to OpenAI agents; OpenAI confirms agent use of RubyGems but says it has not verified the malicious-package claims.
CVE-2026-26030 allowed a model-controlled Search Plugin parameter to reach an unsafe eval-based filter path and execute code on the Semantic Kernel host under affected conditions.
vulnerabilityFirst seen Feb 19, 2026AGAINST AI4 claims
Anthropic reports that a single French-speaking actor used Claude and sub-agent workflows against European political, media, think-tank and SaaS targets, gaining internal access to at least 14 of 42 tracked entities.
Anthropic reports a Russian state-nexus espionage actor using customized AI workflows across development, phishing, persistence, command-and-control and exfiltration, including automatic malware rebuilding after detection.
Anthropic identified four cyber-evaluation incidents in which Claude models reached real systems because a third-party evaluation environment had unintended internet access.
No shown records match these filters. Search the full library to continue.
Why this archive exists
The source matters after the headline fades.
DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.
We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.