AI security research / sources

Source library

Evidence records and original attribution. A Source is connected to specific Claims, not a blanket endorsement of a Case.

30 of 103 published records shown

Source

Practitioner critique of the OpenAI evaluation containment

A practitioner reaction arguing that the incident should be read primarily as a containment and operational-security failure rather than as proof of exotic exploit capability.

Source

RCE via malformed HEIF file

Maintainer-side advisory and remediation context for malformed HEIF processing. Narrow software-maintainer scope; does not independently establish the full OpenAI SSO/Codex chain.

Source

Verify Git plugin SHA checkouts

OpenAI Codex pull request documenting the root cause and fix: Git can interpret a requested SHA as a branch name, so Codex now resolves HEAD after checkout and rejects plugin materialization unless it exactly matches the requested commit.

Source

ADR-166: MCP bridge unauthenticated RCE remediation

Ruflo maintainer remediation document stating that the project statically verified the coordinated-disclosure claims against the shipping default deployment and describing the security redesign.

Source

'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets

Independent BleepingComputer report published July 11, 2026. It reconstructs the split-image attack, CodeRabbit/Bugbot blind spot, fake provenance cover, 311-integer synthetic .env output, harness-dependent results and ASSET's multimodal defensive reviewer, and notes that the researchers disclosed findings to affected vendors.

Source

ASSET Research Group: We put the exploit in a picture. The AI code reviewer never opened it.

Primary ASSET Research Group disclosure dated June 2026. It documents the failed plaintext precursor, the split AGENTS.md + PNG attack, CodeRabbit/Bugbot review behavior, a 6,480-PR review survey, a fabricated validator/postmortem cover story, end-to-end synthetic .env recovery, ten-session model/harness comparisons, a 49/50 attack and 0/30 benign multimodal-reviewer trial, controlled-test limitations and vendor disclosure.

Source

asset-group/ghostcommit public proof of concept

Public GhostCommit PoC repository with the evolved attack fixture, decoder, threat-model document, safe reproduction procedure, retained desktop recording and verified result matrices. Its current Codex results cover 60 CLI trials across GPT-5.6 Luna/Sol/Terra plus six separate App observations, with explicit EXFIL, REFUSED and RETRACT definitions and a warning not to generalize fixture-specific counts.

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is an independent research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.