AI security research / entities

Entities

Explicitly connected records in the evidence library.

15 of 15 published records shown

software

AutoGen Studio

Open-source prototyping UI affected by the AutoJack development-branch exploit chain.

1 explicit connections

software

ChatGPT

OpenAI product involved in the Check Point cross-account proof of concept.

1 explicit connections

vulnerability

CVE-2026-26030

Semantic Kernel In-Memory Vector Store filter RCE vulnerability.

1 explicit connections

vulnerability

CVE-2026-48989

Windows-MCP unauthenticated HTTP control-plane vulnerability.

1 explicit connections

vulnerability

CVE-2026-52870

Cross-client task authorization vulnerability in the MCP Python SDK experimental tasks feature.

1 explicit connections

vulnerability

CVE-2026-59950

Host/Origin validation gap in the MCP Python SDK deprecated WebSocket server transport.

1 explicit connections

software

GitHub

Developer platform involved in AISI's incident response and used here as a source for security advisories.

1 explicit connections

project

KASS

Knowledge-Augmented Attack Synthesis and Simulation, a research framework for executable smart-contract exploit verification.

2 explicit connections

software

MCP Python SDK

Official Python SDK for Model Context Protocol servers and clients.

3 explicit connections

software

PentAGI

Open-source offensive agent framework cited by Anthropic as representative scaffolding used or mirrored by malicious operators.

3 explicit connections

software

PyPI

Python package index that received malicious package uploads during one Anthropic cyber-evaluation incident.

1 explicit connections

software

RubyDoc.info

A documentation-building service for Ruby packages.

1 explicit connections

software

RubyGems.org

The public package registry for the Ruby ecosystem.

1 explicit connections

software

Semantic Kernel

Microsoft open-source agent framework affected by CVE-2026-26030.

1 explicit connections

software

Windows-MCP

Open-source MCP server that exposes Windows automation capabilities.

1 explicit connections

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.