Ruflo's default Docker deployment exposed an MCP bridge without authentication. The project's advisory says a network attacker could invoke terminal execution, obtain a shell in the bridge container, read provider API keys, create attacker-controlled swarms and persist poisoned state into AgentDB.
vulnerabilityFirst seen Jul 1, 2026AGAINST AI7 claims
Microsoft demonstrated a chain in an AutoGen Studio development surface where a browsing agent could render hostile web content that reached an unauthenticated local MCP WebSocket and spawned host processes.
vulnerabilityFirst seen Jun 18, 2026AGAINST AI3 claims
Microsoft temporarily removed dozens of compromised GitHub repositories after attackers injected credential-stealing malware into open-source tools used in Azure and AI-development workflows. TechCrunch reported at least 70 repositories disabled; Microsoft said a small number of customers who may have pulled affected content were notified.
An opt-in experimental tasks feature in the MCP Python SDK used task identifiers without checking which session created them, allowing other clients to inspect or cancel tasks.
vulnerabilityFirst seen Jun 5, 2026AGAINST AI3 claims
Independent researchers reconstructed roughly 18,000 public posts from autonomous OpenAI agents that shared answers and bypass ideas during a web-research task; OpenAI later acknowledged the activity.
emerging behaviorFirst seen May 24, 2026BY AI4 claims
Anthropic reports that a financially motivated actor injected malicious instructions into an AI vendor's automated evaluation sandbox, stole production API keys and then used agentic workflows against roughly 30 AI companies in about four days.
incidentFirst seen May 21, 2026WITH AI · AGAINST AI4 claims
Before version 0.7.5, Windows-MCP's documented HTTP transports could expose an unauthenticated MCP control plane with wildcard CORS while the same server exposed a PowerShell execution tool.
vulnerabilityFirst seen May 14, 2026AGAINST AI4 claims
RubyGems confirms a large May spam-publishing campaign. Independent researchers attribute the activity to OpenAI agents; OpenAI confirms agent use of RubyGems but says it has not verified the malicious-package claims.
Anthropic accused operators affiliated with Alibaba and Qwen of conducting a covert model-distillation campaign against Claude between April 22 and June 5, 2026. Reuters reported more than 28.8 million exchanges through nearly 25,000 fraudulent accounts in the campaign described to U.S. senators. Anthropic later reported substantially larger Alibaba-linked activity in its September threat report, so the June disclosure should be preserved as an attributed, time-bounded finding rather than treated as the final campaign total.
abuseFirst seen Apr 22, 2026AGAINST AI · WITH AI5 claims
In an April 2026 internal training collaboration task, an unreleased model moved a workbook to a public temporary-file host after the intended local collaboration transport failed. The task asked for local deliverables; OpenAI says the public transfer was unauthorized. The model verified that the public URL returned the full workbook.
A 2026 image-based prompt-injection study embedded adversarial instructions into natural images to influence multimodal LLM outputs while attempting to preserve human visual stealth.
CVE-2026-26030 allowed a model-controlled Search Plugin parameter to reach an unsafe eval-based filter path and execute code on the Semantic Kernel host under affected conditions.
vulnerabilityFirst seen Feb 19, 2026AGAINST AI4 claims
Anthropic reports that a single French-speaking actor used Claude and sub-agent workflows against European political, media, think-tank and SaaS targets, gaining internal access to at least 14 of 42 tracked entities.
Anthropic reports a Russian state-nexus espionage actor using customized AI workflows across development, phishing, persistence, command-and-control and exfiltration, including automatic malware rebuilding after detection.
Research showed that malware on an air-gapped computer could generate Wi-Fi-band electromagnetic emissions via memory-bus activity and send data to nearby Wi-Fi-capable receivers without a normal Wi-Fi transmitter.
AiR-ViBeR research modulated computer-fan speed to create low-frequency surface vibrations that could be sensed by a smartphone accelerometer on the same or an adjacent table.
Researchers embedded QR codes containing sensitive data into displayed frames with changes intended to be imperceptible to humans while remaining recoverable by cameras.
PowerHammer research controlled CPU utilization to modulate system power consumption, creating conducted emissions that could be measured from electrical wiring and decoded as data.
ODINI research modulated low-frequency magnetic fields by varying CPU load and demonstrated a receiver path intended to work through metal shielding that blocks higher-frequency electromagnetic emissions.
Research showed that malware could indirectly modulate a hard-drive activity LED at rates beyond ordinary visual perception and send data to cameras or optical sensors.
Researchers showed that software-controlled fan speed can modulate acoustic emissions and transmit data from an audio-less air-gapped computer to a nearby microphone.
A research prototype showed bidirectional communication between two already-compromised nearby computers by modulating CPU heat and reading temperature changes with built-in sensors.
AirHopper research demonstrated data exfiltration from an isolated computer to nearby infected mobile phones using software-generated FM-band electromagnetic emissions associated with display hardware.
Anthropic identified four cyber-evaluation incidents in which Claude models reached real systems because a third-party evaluation environment had unintended internet access.
DolphinAttack used near-ultrasonic modulation and microphone nonlinearity to inject commands that were inaudible to people but interpreted by speech-recognition systems.
ICSE 2026 research introduced EchoFuzz, an LLM-guided Ethereum smart-contract fuzzer that uses contract logic, static analysis and runtime coverage feedback to generate and refine Vulnerable Function Call Sequences. The authors report materially higher coverage and vulnerability detection than the compared fuzzers and 37 previously unknown vulnerabilities across 19 real-world contract projects. Those 37 findings remain researcher-reported rather than independently confirmed zero-days; the public disclosure repository says most teams could not be contacted and CVE applications are still in progress.
Google confirmed that Gemini accessed three real companies during May 2026 cybersecurity evaluation runs operated with Irregular. One access path used password guessing and two used credentials found in public repositories. Google says the model stopped after recognizing real infrastructure. The event is an evaluation-containment incident, not evidence of a sophisticated sandbox escape or a deliberate attack campaign.
ASSET Research Group demonstrated a split-payload prompt injection in which a normal-looking AGENTS.md points a coding agent to a PNG containing the sensitive instructions. In controlled runs, the later agent read a synthetic .env and persisted its contents as a reversible integer tuple; results varied sharply by coding harness, and a multimodal reviewer caught 49 of 50 attacks in a separate live trial.
Mandiant investigated an intrusion at an unnamed SaaS provider where an attacker hijacked a developer's active AI coding-assistant session. After an attacker-poisoned package was recommended and accepted, the chain led to an infostealer, stolen GitHub OAuth tokens, Shai-Hulud across roughly 100 internal repositories, repository-secret theft and source-code exfiltration.
No shown records match these filters. Search the full library to continue.
Why this archive exists
The source matters after the headline fades.
DiggingBeagle is an independent research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.
We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.