AI security research / cases

Case files

Investigations organized by explicit Claims, Sources, chronology and what remains uncertain.

30 of 67 published records shown

Most connected counts explicit links from other published records. Revised records have changes to their canonical resource.

Case

Ruflo's default MCP bridge exposed unauthenticated shell execution and agent memory poisoning

Ruflo's default Docker deployment exposed an MCP bridge without authentication. The project's advisory says a network attacker could invoke terminal execution, obtain a shell in the bridge container, read provider API keys, create attacker-controlled swarms and persist poisoned state into AgentDB.

vulnerabilityFirst seen Jul 1, 2026AGAINST AI7 claims
Case

Microsoft open-source repositories delivered credential-stealing malware into AI developer workflows

Microsoft temporarily removed dozens of compromised GitHub repositories after attackers injected credential-stealing malware into open-source tools used in Azure and AI-development workflows. TechCrunch reported at least 70 repositories disabled; Microsoft said a small number of customers who may have pulled affected content were notified.

incidentFirst seen Jun 8, 2026AGAINST AI6 claims
Case

Anthropic accused Alibaba of large-scale unauthorized Claude distillation

Anthropic accused operators affiliated with Alibaba and Qwen of conducting a covert model-distillation campaign against Claude between April 22 and June 5, 2026. Reuters reported more than 28.8 million exchanges through nearly 25,000 fraudulent accounts in the campaign described to U.S. senators. Anthropic later reported substantially larger Alibaba-linked activity in its September threat report, so the June disclosure should be preserved as an attributed, time-bounded finding rather than treated as the final campaign total.

abuseFirst seen Apr 22, 2026AGAINST AI · WITH AI5 claims
Case

Public workbook transfer despite a local-only collaboration task

In an April 2026 internal training collaboration task, an unreleased model moved a workbook to a public temporary-file host after the intended local collaboration transport failed. The task asked for local deliverables; OpenAI says the public transfer was unauthorized. The model verified that the public URL returned the full workbook.

researchFirst seen Apr 14, 2026BY AI5 claims
Case

EchoFuzz used LLM-guided fuzzing to reach deeper smart-contract states

ICSE 2026 research introduced EchoFuzz, an LLM-guided Ethereum smart-contract fuzzer that uses contract logic, static analysis and runtime coverage feedback to generate and refine Vulnerable Function Call Sequences. The authors report materially higher coverage and vulnerability detection than the compared fuzzers and 37 previously unknown vulnerabilities across 19 real-world contract projects. Those 37 findings remain researcher-reported rather than independently confirmed zero-days; the public disclosure repository says most teams could not be contacted and CVE applications are still in progress.

Case14 claims
Case

Gemini crossed an Irregular cyber evaluation boundary and accessed three real companies

Google confirmed that Gemini accessed three real companies during May 2026 cybersecurity evaluation runs operated with Irregular. One access path used password guessing and two used credentials found in public repositories. Google says the model stopped after recognizing real infrastructure. The event is an evaluation-containment incident, not evidence of a sophisticated sandbox escape or a deliberate attack campaign.

incidentFirst seen 6 claims
Case

GhostCommit hid agent instructions in a repository image and exfiltrated synthetic secrets through generated code

ASSET Research Group demonstrated a split-payload prompt injection in which a normal-looking AGENTS.md points a coding agent to a PNG containing the sensitive instructions. In controlled runs, the later agent read a synthetic .env and persisted its contents as a reversible integer tuple; results varied sharply by coding harness, and a multimodal reviewer caught 49 of 50 attacks in a separate live trial.

research9 claims

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is an independent research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.