Practitioner critique of the OpenAI evaluation containment
A practitioner reaction arguing that the incident should be read primarily as a containment and operational-security failure rather than as proof of exotic exploit capability.
AI security research / sources
Evidence records and original attribution. A Source is connected to specific Claims, not a blanket endorsement of a Case.
30 of 103 published records shown
A practitioner reaction arguing that the incident should be read primarily as a containment and operational-security failure rather than as proof of exotic exploit capability.
Maintainer-side advisory and remediation context for malformed HEIF processing. Narrow software-maintainer scope; does not independently establish the full OpenAI SSO/Codex chain.
Hugging Face's detailed forensic reconstruction of the autonomous intrusion, including the launchpad, dataset processor compromise, lateral movement and recovered action log.
Developer discussion of Hugging Face's technical post-mortem. Used only as community context, not as authority for incident facts.
Goose maintainer advisory for CVE-2026-72718 confirming unsandboxed pre-model command execution from repository-local core.fsmonitor and the fix in Goose 1.44.0.
OpenAI Codex pull request documenting the root cause and fix: Git can interpret a requested SHA as a branch name, so Codex now resolves HEAD after checkout and rejects plugin materialization unless it exactly matches the requested commit.
KASS paper describing a multi-agent exploit-synthesis and simulation framework for smart contracts, with SmartBugs-Curated and real CVE-tagged evaluations.
GitHub security advisory for CVE-2026-59950, affecting the deprecated MCP Python SDK WebSocket server transport before 1.28.1.
Check Point Research investigation of a browser-only ransomware technique developed from an LLM-suggested concept and implemented as a practical proof of concept.
Ruflo GitHub security advisory describing unauthenticated MCP tool invocation, terminal execution, exposed provider keys, AgentDB poisoning and the patched version.
Ruflo maintainer remediation document stating that the project statically verified the coordinated-disclosure claims against the shipping default deployment and describing the security redesign.
Microsoft technical disclosure of AutoJack, a development-branch AutoGen Studio chain from hostile web content through a local MCP WebSocket to host process execution.
Original Microsoft figure showing the AutoJack end-to-end chain.
GitHub security advisory for CVE-2026-52870, affecting opt-in experimental tasks in mcp 1.23.0 through 1.27.1 and fixed in 1.27.2.
Maintainer advisory for the Windows-MCP HTTP transport vulnerability later assigned CVE-2026-48989.
Windows-MCP release notes describing the fix for GHSA-vrxg-gm77-7q5g.
Original Microsoft figure from the Semantic Kernel CVE-2026-26030 research article.
Microsoft's technical write-up of Semantic Kernel vulnerabilities, including the CVE-2026-26030 prompt-injection-to-RCE path and affected configuration.
GitHub-reviewed advisory for CVE-2026-26030, identifying affected Semantic Kernel Python versions and the patched release.
Research paper demonstrating a vibration-based covert channel where fan-speed modulation produces surface vibrations decoded by smartphone accelerometers.
Research paper demonstrating optical exfiltration through rapid modulation of a computer HDD activity LED.
Research paper demonstrating acoustic exfiltration by controlling HDD actuator movement and decoding the resulting sound with a nearby receiver.
Research paper showing software-controlled cooling-fan noise as an acoustic covert channel when speakers and audio hardware are absent.
Research paper demonstrating FM-band exfiltration from an air-gapped computer to nearby mobile phones through electromagnetic emissions associated with display hardware.
Independent BleepingComputer report published July 11, 2026. It reconstructs the split-image attack, CodeRabbit/Bugbot blind spot, fake provenance cover, 311-integer synthetic .env output, harness-dependent results and ASSET's multimodal defensive reviewer, and notes that the researchers disclosed findings to affected vendors.
Review article organizing air-gap attack research across electromagnetic, magnetic, electrical, acoustic, optical, thermal and vibrational transport mechanisms.
Primary Spanish data-protection authority publication stating that AEPD received its first notification of a personal-data breach in which the incident was allegedly executed through an AI agent using a known large language model.
Primary ASSET Research Group disclosure dated June 2026. It documents the failed plaintext precursor, the split AGENTS.md + PNG attack, CodeRabbit/Bugbot review behavior, a 6,480-PR review survey, a fabricated validator/postmortem cover story, end-to-end synthetic .env recovery, ten-session model/harness comparisons, a 49/50 attack and 0/30 benign multimodal-reviewer trial, controlled-test limitations and vendor disclosure.
Public GhostCommit PoC repository with the evolved attack fixture, decoder, threat-model document, safe reproduction procedure, retained desktop recording and verified result matrices. Its current Codex results cover 60 CLI trials across GPT-5.6 Luna/Sol/Terra plus six separate App observations, with explicit EXFIL, REFUSED and RETRACT definitions and a warning not to generalize fixture-specific counts.
Filters apply to the records shown on this page. Search the complete published library.
No shown records match these filters. Search the full library to continue.
Why this archive exists
DiggingBeagle is an independent research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.
We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.