{
  "count": 171,
  "disclaimer": "AariaSec mappings are analytical references, not claims about any specific deployment.",
  "displayed": 42,
  "generated_at": "2026-08-18T01:42:15Z",
  "incidents": [
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-10",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "SME Futures",
      "source_type": "Public reporting",
      "summary": "AI agent hacks gym booking system in Australia\u2019s first known autonomous cyberattack SME Futures",
      "title": "AI agent hacks gym booking system in Australia\u2019s first known autonomous cyberattack - SME Futures",
      "url": "https://news.google.com/rss/articles/CBMiqgFBVV95cUxOX09COHNfTElaZzFuNkp4Zzg3RDE5YkY1ZmRLYm82VHFleUJwQUtUMHhWN05OSkdraGUydHdsakt6YUw4UzJaV25vcXRLcmFhSDI2WmlTTGhHcXcxOWxudktzd19OS3pRV0IxbWpkRkxoc0JKUFp1ZU9lcmlPSWVUTTFmOXA2WW9LY1NoenVYZUFpNTRzd3laTmNyMTlqQ1QyWWZBc3ZCdzJmUQ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-07-06",
      "detection_surface": "MCP graph edges, privilege expansion, and scope explosion",
      "failure_pattern": "Connector or tool-surface expansion",
      "recommendation": "Pre-register tools, review requested scopes, and alert on unexpected graph expansion.",
      "relevant_awr": [
        "AWR-112",
        "AWR-113"
      ],
      "severity": "Medium",
      "source": "Tech Times",
      "source_type": "Public reporting",
      "summary": "AI Agent Red Teaming: Tencent Framework Audits MCP Supply Chain for First Time Tech Times",
      "title": "AI Agent Red Teaming: Tencent Framework Audits MCP Supply Chain for First Time - Tech Times",
      "url": "https://news.google.com/rss/articles/CBMixwFBVV95cUxPOGlWWElCeGZ0TnZrRXNCZGloMXVfWEZVZ21lVW9FQTI1RUY3WVB5RWJocTVPYUVJTGM3SVZvVFdwYUVSQ05qUl9pYnlHOXRaU2xMMktUUlZieG1GY3YyTk5mTlhETkF0N2Y0d3VJT1NORXlfTlBiUFBKQVdWQUxRcVZkd1lTejdqVm5xcFlpSEhUdUt3aVVMWURET1NDdzRCRGJHUjNfSWJwLTVKcUVURlY3ZEc2ZkNoNEhCbXpsT0pPazhiTHpV?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-14",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Security Boulevard",
      "source_type": "Public reporting",
      "summary": "The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure Security Boulevard",
      "title": "The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure - Security Boulevard",
      "url": "https://news.google.com/rss/articles/CBMizwFBVV95cUxOMUtBUHRqeGc1Q0RGbE5rak9mUGJLV2RDRk9qQThkU0tQb3lVNDJEcXdiU2p0QXYtMkRXZVhsOW1qTkE4ZE44bW9Sd09UNEJOMkhURnE1LUM1Zkc0RHc4b1l4Uk84TkM1X3hrVHJuVWNySlZCaVNlVDE3cVdaQmp6VmNPOHdqZDgtaWJ6RUZ4Y0FfV3RYWXR0VXh4WlVwUVZ3QWdLSjNxdFk2M3d2Zk9LbFJxa2dmcWlDWGpRUDFwUDBVM3hKN2dEWnMyY0dRUjA?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-08-10",
      "detection_surface": "Prompt-hash transition, tool call sequence, and session trace",
      "failure_pattern": "Prompt injection / instruction override",
      "recommendation": "Require approval before sensitive tool use and restrict untrusted input from tool instructions.",
      "relevant_awr": [
        "AWR-111",
        "AWR-001"
      ],
      "severity": "High",
      "source": "appinventiv.com",
      "source_type": "Public reporting",
      "summary": "Prompt Injection Defense: Here\u2019s How to Stop AI Data Exfiltration appinventiv.com",
      "title": "Prompt Injection Defense: Here\u2019s How to Stop AI Data Exfiltration - appinventiv.com",
      "url": "https://news.google.com/rss/articles/CBMiZEFVX3lxTE53VFdIYU5ZS1hxLWJUMGNDVHdiV2l2R24xSDlIeEtxU3dfNDFKWmFjZGd0Y2NoMGJMVTc2ZlNROENLR2NHVnZPSXVtSng1Q2NoZjJVcnhrbUVlaFp2a2dlbVB0MWs?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-13",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Built In",
      "source_type": "Public reporting",
      "summary": "The Hugging Face Breach Means Agentic Attacks Are a Matter of When, Not If Built In",
      "title": "The Hugging Face Breach Means Agentic Attacks Are a Matter of When, Not If - Built In",
      "url": "https://news.google.com/rss/articles/CBMickFVX3lxTFBZVXhzYXdscHNoUTVZUlhYUXc1cEFtX0tLSmxDbmVHTzdxQS16SWlrS2UxVTNfLXg4VUJfbnc5NG0tSVJ6ZWF4cWNuRExaSTZ5TE5xTWZ3d1BiNnNKWG1kNHQzeThYS0NXSnRPcmVHbGN5QQ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-03-11",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Cisco Talos Blog",
      "source_type": "Public reporting",
      "summary": "Agentic AI security: Why you need to know about autonomous agents now Cisco Talos Blog",
      "title": "Agentic AI security: Why you need to know about autonomous agents now - Cisco Talos Blog",
      "url": "https://news.google.com/rss/articles/CBMipwFBVV95cUxQVEFIMGhBUnRKMUpGdUZ4ZmdiaW85ajBKekdubnpFaE1FbjlSX0ktM0JZdl9vUWtwbDFKNmpvdGxLcjh2LWVDZjV3QWYxVnl4TEtNWDFCaG8ybWV1c0VzZ05XR25tV3dNMUktRWw0Y2x3czJ2RWtNY0VUbUNRRkg1VFZFbzREWnU2NFdPZnZpSEt6RjZPcEdNV2ExWHJvR2FrNVZtNk42TQ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-03-19",
      "detection_surface": "Prompt-hash transition, tool call sequence, and session trace",
      "failure_pattern": "Prompt injection / instruction override",
      "recommendation": "Require approval before sensitive tool use and restrict untrusted input from tool instructions.",
      "relevant_awr": [
        "AWR-111",
        "AWR-001"
      ],
      "severity": "High",
      "source": "itbrief.co.uk",
      "source_type": "Public reporting",
      "summary": "HackerOne unveils live agentic AI prompt injection tests itbrief.co.uk",
      "title": "HackerOne unveils live agentic AI prompt injection tests - itbrief.co.uk",
      "url": "https://news.google.com/rss/articles/CBMijAFBVV95cUxONnY0UVYtbXcxRFRqSUVQR05pOWswWHo5YWZZc3dFT2R5T2UtcFI3Z1c5TnQwbUIzVkxPOGhya0JYQVp5N2duWDdaVko5RmhzOE1CLWVKcjlOLXAxTjd2SUFyWDZYbW1fX0NfUXZTRGZIMXZhS1NFZlhsVkJaOU9UZnNVYi13U3BYUnl4LQ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-03-03",
      "detection_surface": "Prompt-hash transition, tool call sequence, and session trace",
      "failure_pattern": "Prompt injection / instruction override",
      "recommendation": "Require approval before sensitive tool use and restrict untrusted input from tool instructions.",
      "relevant_awr": [
        "AWR-111",
        "AWR-001"
      ],
      "severity": "High",
      "source": "Unit 42",
      "source_type": "Public reporting",
      "summary": "Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild Unit 42",
      "title": "Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild - Unit 42",
      "url": "https://news.google.com/rss/articles/CBMib0FVX3lxTE81b0QxYzZmNUZ1Z0pmVjMyeFgtVkZxZUZoUFBwUjJtX3F2MklKQ21MbDlOSGN2eG5Hb3VPSlduTk1qczVKVHRsNzlGRUFxZkVycXVramF2ZFp2QkIzVjJ2ZElkMjhldllzeGJsdkZjZw?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.13608v1 Announce Type: cross Abstract: Agentic \"Continual Learning Harnesses\", systems that pair an LLM with retrieval or memory to improve from feedback without retraining, have shown growing value in cybersecurity. But their value is conventionally measured by.",
      "title": "Evaluating Agentic Learning Harness Capabilities Without Labels via the Scaling Hypothesis",
      "url": "https://arxiv.org/abs/2608.13608"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-05-05",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "TechRadar",
      "source_type": "Public reporting",
      "summary": "Reporting on enterprise agent adoption highlights operational risk from unpredictable behavior, model drift, and unexpected actions, with a focus on continuous monitoring.",
      "title": "AI agents create new risks requiring continuous monitoring and oversight",
      "url": "https://www.techradar.com/pro/ai-agents-create-new-risks-requiring-continuous-monitoring-and-oversight"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-01-19",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "PR Newswire",
      "source_type": "Public reporting",
      "summary": "Adversa AI Wins 2026 BIG Innovation Award for Agentic AI Security Platform, Advancing Continuous AI Red Teaming for Autonomous AI Agents PR Newswire",
      "title": "Adversa AI Wins 2026 BIG Innovation Award for Agentic AI Security Platform, Advancing Continuous AI Red Teaming for Autonomous AI Agents - PR Newswire",
      "url": "https://news.google.com/rss/articles/CBMimwJBVV95cUxON2VvOXM1S291MnNFUEFjSlV4YWhNSDFTQ3hNdVVnOVlJQnB2SVVGSE1uOGhtREVXVDNpbGpZdVY1R01zRjRDSjM1VFhrVVV6cUlvb0NhOFpYTU1FWGY3UHJPdVMzWm9CSXVQRl90alIyckwxRnFuWk9FX21HLVZycTJ1MUhMQjBCeF9KQ3hDQTJIRFpHNy1qODJ1VlhYZkMyMks5Yk1hR1J4OVlCWlNrRkhSSHZhZzNpOEY1RFNaVEdtb1pqbUNNV0ItY2Fpclh5ZWN4b05BdGFSc3F0TkQ3Q0pIQUxxbXRmZENFWXdRU2NXQnZhUWRaS3V3em5pem80ckN3OHhMV09PM3NYcHU1V1RLQ2RZOHBfOElJ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-12-10",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Aikido Security",
      "source_type": "Public reporting",
      "summary": "OWASP Top 10 for Agentic Applications (2026): Full Guide to AI Agent Security Risks Aikido Security",
      "title": "OWASP Top 10 for Agentic Applications (2026): Full Guide to AI Agent Security Risks - Aikido Security",
      "url": "https://news.google.com/rss/articles/CBMibkFVX3lxTE9qTlkyZVZUcWl6X2RVS0FPVktiejBDMWQ3YW9nSkI5NXVTWlIyWFF1MGtjc1lGdDItdlNVOW5JNUxkaU81SlBxajZ6ZW5VRkNCenF4aEhJVGkxSkRRc3hOa05MVXNRdHZ6R2kybmlB?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-05-06",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "ITPro",
      "source_type": "Public reporting",
      "summary": "Public reporting on Five Eyes guidance describes risk from unguarded agentic AI deployments, including excessive privileges, unpredictable behavior, and the need for oversight and access controls.",
      "title": "Five Eyes agencies warn about risks in agentic AI deployments",
      "url": "https://www.itpro.com/security/five-eyes-agencies-sound-alarm-over-risky-agentic-ai-deployments"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-01-07",
      "detection_surface": "Prompt-hash transition, tool call sequence, and session trace",
      "failure_pattern": "Prompt injection / instruction override",
      "recommendation": "Require approval before sensitive tool use and restrict untrusted input from tool instructions.",
      "relevant_awr": [
        "AWR-111",
        "AWR-001"
      ],
      "severity": "High",
      "source": "Information",
      "source_type": "Public reporting",
      "summary": "A 2026 review article surveys prompt injection vulnerabilities, attack vectors, and defense mechanisms for LLM and AI agent systems.",
      "title": "Prompt injection attacks in large language models and AI agent systems",
      "url": "https://www.mdpi.com/2078-2489/17/1/54"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-07-28",
      "detection_surface": "OS-layer scope-lock enforcement (Patent C202): filesystem, exec and TCP allow-lists with a signed enforcement receipt, plus egress-destination drift",
      "failure_pattern": "Containment escape / unauthorized network egress",
      "recommendation": "Enforce network boundaries at the OS layer rather than in the prompt \u2014 an instruction saying the model has no internet is a guideline, not a guardrail. Scope agents to an explicit TCP allow-list and alert on any denied connection.",
      "relevant_awr": [
        "AWR-286"
      ],
      "severity": "Critical",
      "source": "Tech Times",
      "source_type": "Public reporting",
      "summary": "Over 1,100 AI Employees Petition for US-Backed Pacing Mechanism After OpenAI's Sandbox Escape Tech Times",
      "title": "Over 1,100 AI Employees Petition for US-Backed Pacing Mechanism After OpenAI's Sandbox Escape - Tech Times",
      "url": "https://news.google.com/rss/articles/CBMi2gFBVV95cUxQbWxSRmQ5aDk4Mm5oMFlBZnhvSWhoLUNkQXdRQmVSbWdFYVNLaE1aSGpqN3J0OU5PNVRXSDhRbnJSdHBzbUl2Y1VHTHlCT29fQV9LVW93enJRWW41UkhQMlY1SUM1Uk94a21LYWlBaFZ1OGVrWTAzTmxzQlhadE40YkE4RmlWdGY0cHU4WW9NQWRMa1pZMXk5U0pYakdQSjdIVDdpeklEZklWOXhURmRLa2t1enc4X0hXekExX2Q0c0IwTnpPdXpqVE5VeGN4eklsVUpHaUsyUExZQQ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-05-04",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "csoonline.com",
      "source_type": "Public reporting",
      "summary": "Security agencies draw red lines around agentic AI deployments csoonline.com",
      "title": "Security agencies draw red lines around agentic AI deployments - csoonline.com",
      "url": "https://news.google.com/rss/articles/CBMirgFBVV95cUxQeDJzX3JvbW51SWI2Vi16YnMzd3lhaUxkbUdCNDlCMzBnQTA1NDlPN0gzU21yb3pKMk9sS3FSRlpQcDVrcFZuUU54eUVjdWljYXNXQnFfRlZtQS1YdnZnLUdjQUllal9DUUxtYlg5TUFYUTQ4VFpvTzBFZ1A3UmMzZHNtQk1CNWlpLWh2RldwQThCeDNpVjRTU2JITkk4Q29EeHN6cE9HZ3BYZ1NLMnc?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-07-14",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Tech Times",
      "source_type": "Public reporting",
      "summary": "Ant Group Open-Sources Agent Security Tool Days After Agentic Ransomware Hit Tech Times",
      "title": "Ant Group Open-Sources Agent Security Tool Days After Agentic Ransomware Hit - Tech Times",
      "url": "https://news.google.com/rss/articles/CBMiywFBVV95cUxQZWJSWFBzWjlQeDNPMXFSdkdXX0ZNMklCeUh0UGw1ZTVadkFjX2ozRkEtTzdXR042RzJsMC1XV3AtVkN5a3IxYnhWazRVSWdhTmY1SEw2dmpvRV9fbmx4dDNFaHY1ckRiN1UtZUpXQnE4ZzM5bmRvWlJOa3VOdGNkNlk0V1R6WHdaMVZlb09JX1hNY29mc1N0d3JVdG1iMXJvQjFkNldXUXd4dXJzQ1F5dGFqb1RnbmFYellPUllYM0NfMUdjSG4xcGJxMA?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-07-07",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Security Boulevard",
      "source_type": "Public reporting",
      "summary": "AI Security Incident \u2013 JadePuffer Ransomware Leverages AI Agent to Automate Attacks Security Boulevard",
      "title": "AI Security Incident \u2013 JadePuffer Ransomware Leverages AI Agent to Automate Attacks - Security Boulevard",
      "url": "https://news.google.com/rss/articles/CBMivAFBVV95cUxPalpGSUpvUnk3WktRcmdtRGlIRnd0REtXV2M0TXNLMUl0UXpFY0xtbjRnUUM1LVJpdE56YUc4anJFWDlmWlprV29XSFhPc1FfcDFLdEVSb21yS0VMTWlobW03WDBYQ3J6N0pDa0RtVm9wbmVsT2VQZGlLVzRxV1dFSjRpdXdFc1pzNmpmOExPRzlXdW1qaWNPMzAzeWllbGVWLXI3X2o3V0ZNT19WREVWWERCTk50RjNXMXhCNA?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-06-30",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "TechBullion",
      "source_type": "Public reporting",
      "summary": "AI Agent Security Best Practices: A 2026 Checklist Mapped to OWASP TechBullion",
      "title": "AI Agent Security Best Practices: A 2026 Checklist Mapped to OWASP - TechBullion",
      "url": "https://news.google.com/rss/articles/CBMilAFBVV95cUxQSTR3ek1NYUdkME1mLTQ4V0t1M3BBeDRaUHlkQk5qRzNTc2NSVWduYklPd1lGS3NSV2VobGNnUndDaGtPdFJHUDBPaEJINUk3eTNVdDhtcTVVNzA2U0dSeG56a2Y1T051STdtTy10dVNiYkROY1ZxaTNXbzhRRUVNRjVaQ0VzazB1d2U5c0daSlQ4eS1I?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-06-24",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "wiz.io",
      "source_type": "Public reporting",
      "summary": "AI Agent Security: 6 Risks to Address and How to Do It wiz.io",
      "title": "AI Agent Security: 6 Risks to Address and How to Do It - wiz.io",
      "url": "https://news.google.com/rss/articles/CBMiZ0FVX3lxTE8wdE1jOGZYSXRENXNlcHBYZFdIeU43UFlVblMxMHhIUzBlM0xuODdzcXJMeU9YT3BPcFczM2JSM3B6QTBBMVZweWlxMVJYWG4zU2NLb1JlMGJSbkxIdnRycVFuOHNBY0E?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-05-31",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Tech Times",
      "source_type": "Public reporting",
      "summary": "Enterprise AI Agent Stack Takes Shape: Asana and Palo Alto Buy Execution and Security Layers Tech Times",
      "title": "Enterprise AI Agent Stack Takes Shape: Asana and Palo Alto Buy Execution and Security Layers - Tech Times",
      "url": "https://news.google.com/rss/articles/CBMi1AFBVV95cUxPb1NqUHRxVVVfTmFIbnZoRERVdm5WNm8xekY3czV0QUZPaDkxbzZ1ODlFWVdUSl9CejA4REYtNHVjaDBHRGlaNWZHbFpMdWt1RUxQbjdIbmUzRmZjV285MVNlcFhHN2VYdVJ4aWFUeUZsY3d2eFZ0LTZ2bjNTNEZiMXRDNmlmXzFPUWowUW5BT0E1bVpFbHRHeEdqVHNEWVJxZEZqeVpqQXVaWExucDhXTFBzNldUQ01wSnh5U2NlRXlubHUwN1hTeDh3Z0syY0Vja3JVRQ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-05-30",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Tech Times",
      "source_type": "Public reporting",
      "summary": "AI vs AI Cybersecurity: Sysdig Documents First LLM-Agent Intrusion in the Wild Tech Times",
      "title": "AI vs AI Cybersecurity: Sysdig Documents First LLM-Agent Intrusion in the Wild - Tech Times",
      "url": "https://news.google.com/rss/articles/CBMiwwFBVV95cUxPOVV1bFc0SVoyX0g5bFd5TjNQTFVndF9OZWJaUGU5cThzWjBBd0w3UTJKb01yWmQ3cmxvRGplcTZrTXNzNlBHUnhPLW5fdk1VcUZuYXhFT1BRVFB6Zk14SmYzazlUSVFKcVZteHpxWmhxWVY3S1lxQlJHMjJUdm4xWmJwQWZUZ1pYb1QwSUhIeTJ4RUZURm9lV2lqVXZrVERuSjhObWFOdW13dUtmclhhRUp1aE10Z2ttS04tRmVEUVBJdUk?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-05-20",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Blockchain Council",
      "source_type": "Public reporting",
      "summary": "Security for AI Agent Managers: Key Controls Blockchain Council",
      "title": "Security for AI Agent Managers: Key Controls - Blockchain Council",
      "url": "https://news.google.com/rss/articles/CBMisAFBVV95cUxQRzlQQXFCWTFYY3RBNHVKZVRRb3BYUUZLUlhwbmp0X2lvYWFhLUNCakY2YXZjQ0hnMFBUa0JzalN4V2RqaHUyeXprVnJ2R3VUVDVRdEVZeGdrNFlCMDA2NWRZWWFvU1JyTXZTZWxsOVN1QU1GclZCU3pkWFBIS2Z4b1p5eFAxNUdUZEZ0QXFLZEg1QkZNVWxMRjU3VGRsdTJteVRqRVdFM1gxUHc0SFFUZA?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-05-19",
      "detection_surface": "Prompt-hash transition, tool call sequence, and session trace",
      "failure_pattern": "Prompt injection / instruction override",
      "recommendation": "Require approval before sensitive tool use and restrict untrusted input from tool instructions.",
      "relevant_awr": [
        "AWR-111",
        "AWR-001"
      ],
      "severity": "High",
      "source": "Substack",
      "source_type": "Public reporting",
      "summary": "How prompt injection broke Nvidia's sandboxed OpenClaw agent Substack",
      "title": "How prompt injection broke Nvidia's sandboxed OpenClaw agent - Substack",
      "url": "https://news.google.com/rss/articles/CBMieEFVX3lxTFBpNXdvWHlmb2FZdXd1RVhJNUJBeE51c2lfM0xIbjdyRUtqalZTVHNxU3JiYk0wZE9maDM1cTd1Y0ozSUdrQkwtTWZqZncyWDNzSGlMNFJ4eldvMFREbWtxanZ5NG5rVXF3QnVYVFRXazZINEdkZVVDaA?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-11",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Escudo Digital",
      "source_type": "Public reporting",
      "summary": "Another AI model escapes its sandbox to search the web for answers Escudo Digital",
      "title": "Another AI model escapes its sandbox to search the web for answers - Escudo Digital",
      "url": "https://news.google.com/rss/articles/CBMi1gFBVV95cUxNTGd2Qk83UUFHODJSWEx5eHdrRnVINDhIcVdKX1c3YUs3WnhURDZGZEltMHh2M3Z3TFg4ZHZMYUFtcE56SU5jRVhXSzJ2QTZpMTlLZ0RrU0JfR2lwUUJfaDZ1WV9ZY2wxZmtVMjVsSEtmMDUxdEhsWjJsQ21KdVczbHl3RWNKR3Y5OTM5aU02TnRsTmhyWjFfbGRraUQ3MEY5Z1Fhd3AzMG5aZWl5VUtWbkxyc2c4ZTJicEFhdGlmcjV3YW1La3dRQTVORktrVFo4M25BSnZn?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2506.06226v4 Announce Type: replace Abstract: Provenance graph analysis plays a vital role in intrusion detection, particularly against Advanced Persistent Threats (APTs), by exposing complex attack patterns. While recent systems combine graph neural networks (GNNs) with.",
      "title": "No Data? No Problem: Synthesizing Security Graphs for Better Intrusion Detection",
      "url": "https://arxiv.org/abs/2506.06226"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-01-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Cyber Magazine",
      "source_type": "Public reporting",
      "summary": "AI Agents Drive First Large-Scale Autonomous Cyberattack Cyber Magazine",
      "title": "AI Agents Drive First Large-Scale Autonomous Cyberattack - Cyber Magazine",
      "url": "https://news.google.com/rss/articles/CBMikAFBVV95cUxQMWFwRGpqUkJORzAzbHBiWUJ0SnlrVjhYWGJ0MTZxSVYzd003d1JsQlBaZmtnTDlCZXByS3h5NHRrVTVET213bUUzZmpWdTNDNk5MRHRVMW1GTnAyd0Jwb0h1NXh0YVpRQmRFQzg5SklTSDdDMFZySS1pak03eXVPMzFLcWxZMnd5TUtaeWtfUmc?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-08-10",
      "detection_surface": "Prompt-hash transition, tool call sequence, and session trace",
      "failure_pattern": "Prompt injection / instruction override",
      "recommendation": "Require approval before sensitive tool use and restrict untrusted input from tool instructions.",
      "relevant_awr": [
        "AWR-111",
        "AWR-001"
      ],
      "severity": "High",
      "source": "csoonline.com",
      "source_type": "Public reporting",
      "summary": "One-click flaw in Atlassian Rovo exposed enterprise data via prompt injection attack csoonline.com",
      "title": "One-click flaw in Atlassian Rovo exposed enterprise data via prompt injection attack - csoonline.com",
      "url": "https://news.google.com/rss/articles/CBMiywFBVV95cUxOeWZCT0ZJOVVuSlRRckZEM3hUN0NjVDBaUndXOWVfVU1YWjN0SUZIUWJJeGIwQXF1UzFadEhxa1U3ckZnVWQ2ZFRnbVlLaTdESHlBRjh2ckUtWmVZVDBFQ0Fiay1CMXBGNEM5Sm5yaDRGYU5NV0NERUxzbjA3WFRUR0lxZ18wdXJTZi1TSlV6cFVKYmdjZktUeTJmZG0tSnFQcEtFbUpiQkpWUkZ5a1Z1MWR1cDltRVFXRHdhdjhoVnhhZ3RiV041QXc2VQ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-08-06",
      "detection_surface": "OS-layer scope-lock enforcement (Patent C202): filesystem, exec and TCP allow-lists with a signed enforcement receipt, plus egress-destination drift",
      "failure_pattern": "Containment escape / unauthorized network egress",
      "recommendation": "Enforce network boundaries at the OS layer rather than in the prompt \u2014 an instruction saying the model has no internet is a guideline, not a guardrail. Scope agents to an explicit TCP allow-list and alert on any denied connection.",
      "relevant_awr": [
        "AWR-286"
      ],
      "severity": "Critical",
      "source": "Chosunbiz",
      "source_type": "Public reporting",
      "summary": "Meta test shows Muse Spark hacks external system, fueling AI security fears - CHOSUNBIZ Chosunbiz",
      "title": "Meta test shows Muse Spark hacks external system, fueling AI security fears - CHOSUNBIZ - Chosunbiz",
      "url": "https://news.google.com/rss/articles/CBMiekFVX3lxTE01dDRnMXQ2VzZJUVdUa0s2cEtaZmpxVzJWVzBQeE5MZnoxRFhld0kxSVlJUnQ0eWEyOWhwRnpzdnVnMEZpLWJ6dUwxcDVyZlZGbld2RTFJN3pHWFZQVTFkMzB6VmcwMk9FLTJGeGx1VzZvdWtzWHoxb2dB0gGOAUFVX3lxTE9KYnh4TFBCQng0bndJbkVsOWNuUERvQ3pkUzU0TjZMb2lJLVdrNE1OR0h4VUpCUW5xZllOYzF4bWw4cEVZLTVSbkI3QlUwbFJWOHNyV3RZVmNzX0Iya3lOSDl1SDFqajl0b0F3Vk5teVR6ZFRTVDRLc2o0NEdlVVJTeGFxSThnSkluSlVsdEE?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-07-30",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Unit 42",
      "source_type": "Public reporting",
      "summary": "Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks Unit 42",
      "title": "Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks - Unit 42",
      "url": "https://news.google.com/rss/articles/CBMifEFVX3lxTE9LV3htRFIydFlrVy1ZelByWWk2RFpkNGlvUWtvVksxcktJZVJkSWJpSjJLd25XbmRmYTN4UjVaTzlCSXB1clVQZzRoelFEdm1yM09Va2szZnQzN3N5cU9BUUpqNGFqUW1hM0llUmV0d3p0VXZkVk90MzFwRTk?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-07-06",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "The HIPAA Journal",
      "source_type": "Public reporting",
      "summary": "AI Agent Conducts First Fully Autonomous Ransomware Attack The HIPAA Journal",
      "title": "AI Agent Conducts First Fully Autonomous Ransomware Attack - The HIPAA Journal",
      "url": "https://news.google.com/rss/articles/CBMikgFBVV95cUxOQkF5Xy0ybDhERzlSYjR4N2l3QXhNZXY0ZjlVejBKR3FMeVlMb1RvRzdubkdOdE44OFp2M00wTE5aQnZtRF9wNVBYZEU3bFFOUzV6eUZTRFBURFA0Q0N6N3g3Q1lOQjBHNEhyZ0lxUWpyR3RhNjhSU2dILUJiSVBObzEyYXo1dFhzbmd3YVptbTFKQQ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-07-03",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Escudo Digital",
      "source_type": "Public reporting",
      "summary": "Inside JADEPUFFER: The first ransomware operation driven by autonomous agents Escudo Digital",
      "title": "Inside JADEPUFFER: The first ransomware operation driven by autonomous agents - Escudo Digital",
      "url": "https://news.google.com/rss/articles/CBMi4wFBVV95cUxOY0JwM2VEbnl4ZkJsYzVtMHR2RzV6UWRiRDdRT21SeTFnc3pUeUdMQklNTmlsd3RxYklyZ3ZJSlotSjlfQ01TOVVrX1BPekRzc3U0RGxPbmpqTHQ3ZllJcGtGZGZFQWpKN1Y2ODVORGl4YWp3NllwOWwxZDBaclFvdFBaQkVaa25sTTlCTmVYTUZYeVRadHlNc0Q4bTZZT3NZb3IwRkFrTjl6TGEtTDZWSHVVaUR0emQwUlJsMzZaS3ROaXNRQlUxcVRMTUhqUE9kbThFdTBSNV82ZlliSjA0RGRYOA?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-06-23",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "The Association for the Advancement of Artificial Intelligence",
      "source_type": "Public reporting",
      "summary": "Deceptive Misuse of Low-Code Platforms: Visualizing the Performance of Disruptive Cyber Effects from Human and LLM Agent Attackers | Proceedings of the AAAI Symposium Series The Association for the Advancement of Artificial Intelligence",
      "title": "Deceptive Misuse of Low-Code Platforms: Visualizing the Performance of Disruptive Cyber Effects from Human and LLM Agent Attackers | Proceedings of the AAAI.",
      "url": "https://news.google.com/rss/articles/CBMiaEFVX3lxTE5VUThfLWRLeGY5a0hLdTRGSlJCaHhDLTZxMDhpNUItYlZ6eEZTTy1oVFdad1o5NW5iM1J5QVZVNG5nOVN4QmZtTVVaSktpSGVjTmk5Qkt3OUJMZEF5ckpKYkx2UGZNeDE4?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-06-01",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Field Effect",
      "source_type": "Public reporting",
      "summary": "Critical Marimo notebook flaw exploited in LLM-agent-driven intrusion Field Effect",
      "title": "Critical Marimo notebook flaw exploited in LLM-agent-driven intrusion - Field Effect",
      "url": "https://news.google.com/rss/articles/CBMiekFVX3lxTE95aGhPUGRlbVNpS08tUld1ZmlRZ1VwMGxYQnVyczNOWHM4MnRZWnNiVVNtRDZZdGhfZGxvUzBKVU9KaW8tbjV6Vkp5QkFrZjd3YWVQOFk3eVZOMGJ4dDV5R3RLdkdqdFBFS2VZMjc4X1gtTW9qYW93VS1B?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-05-29",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "The Hacker News",
      "source_type": "Public reporting",
      "summary": "Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit The Hacker News",
      "title": "Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit - The Hacker News",
      "url": "https://news.google.com/rss/articles/CBMie0FVX3lxTFBBUVM5YjR2S1dKdWt0dlF5eUJPTnlJcUtEY2QyS21HeWI2OEM5bjdtZmwyZWhMbFkxWXhYdVBKa2RDZjVfc3paNDQwQnRGdlREX0NkTHRsdHJYR1UyblJKNEVaRUdZU2I3elFScktKT1htQTVWLTVKZTZoSQ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-05-08",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Towards Data Science",
      "source_type": "Public reporting",
      "summary": "The AI Agent Security Surface: What Gets Exposed When You Add Tools and Memory Towards Data Science",
      "title": "The AI Agent Security Surface: What Gets Exposed When You Add Tools and Memory - Towards Data Science",
      "url": "https://news.google.com/rss/articles/CBMirgFBVV95cUxPNWJmNVNRQUZVakZVV3hYazNRM3gwSURWdmljNFF5V2ZMeEdrT2hPT1dXQUVWZXFGRmRCNU5oZ2lJTzI5ZFRpNmtoSlNmMjIzbDh6Z1JxNHFEV1ZSY1hmcE1wNnJqaGVNcUJHdFJJeEpzSUpaRHJDeVFfNEZPS0toSkpFUHliWmd5eFhLTjZ3VDlKd2hFVGZEVms1RmZCUDZXR2xBTF9qbGpqT1Z1Y1E?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-04-02",
      "detection_surface": "Egress destination, payload metadata hash, and session-level intent drift",
      "failure_pattern": "Data exposure / exfiltration risk",
      "recommendation": "Restrict egress, monitor destination drift, and keep sensitive outputs behind review gates.",
      "relevant_awr": [
        "AWR-111",
        "AWR-006"
      ],
      "severity": "High",
      "source": "VentureBeat",
      "source_type": "Public reporting",
      "summary": "512,000 lines of leaked AI agent source code, three mapped attack paths, and the audit security leaders need now VentureBeat",
      "title": "512,000 lines of leaked AI agent source code, three mapped attack paths, and the audit security leaders need now - VentureBeat",
      "url": "https://news.google.com/rss/articles/CBMipwFBVV95cUxOSUNMNjhmR3dMOHNWalBwYjJScDZIT25DMjdNc1JqLXJPMWJIOFc4akMtMXBMeDRFaTdfalQ2aFdDMmVETmQtd1Rjd2dWSG1zdU1CTzFPTEZDTzY5UU5uVTJzT2I1V0hWRnUwdW1fQW9PYWdkbGJhQUk3a1E5TmpNUTBMUVFlTGYyS2laZGdNZDROOTNNd3VRN3dXZzB3MDdQcWpha1pTUQ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-03-31",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Snowflake",
      "source_type": "Public reporting",
      "summary": "What Is AI Agent Security? Snowflake",
      "title": "What Is AI Agent Security? - Snowflake",
      "url": "https://news.google.com/rss/articles/CBMibkFVX3lxTE1QeTlDTTNhajkwQzB4c0dMRjJ5M3MtckFmVmowc3cza1FJXzVKR1VDaWxfeFZCMzNMY1FNdDRHUlFPdmRwVzJqZGZVNFdkUk12eDM2NjcySmdlcTRXQUxjcWVha3hJNU5keGQxREZn?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-03-24",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Bessemer Venture Partners",
      "source_type": "Public reporting",
      "summary": "Securing AI agents: the defining cybersecurity challenge of 2026 Bessemer Venture Partners",
      "title": "Securing AI agents: the defining cybersecurity challenge of 2026 - Bessemer Venture Partners",
      "url": "https://news.google.com/rss/articles/CBMikwFBVV95cUxOVFdONVNJWG5jcklUMEJDMXZFWjRwWnI0Wno4dGlYVGE4WkJXblYzeUZGc3RVT25UUW1SX3FuMXhwTVBQcFRlSjMxRXVlZ0ZVdXZCRzUtZGpyb3VFUm9UZXV0NU45OTB1dHRVR2JQSkhZVk8wc0xsQVNBb3dub0pUSnF6SWVJUDRHTFR4V19Wd0tLODg?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-03-23",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Palo Alto Networks",
      "source_type": "Public reporting",
      "summary": "Prisma Browser: Agentic AI Governance & SASE Security Palo Alto Networks",
      "title": "Prisma Browser: Agentic AI Governance & SASE Security - Palo Alto Networks",
      "url": "https://news.google.com/rss/articles/CBMiggFBVV95cUxNYmtKdDlOYnplc0hrUDVaMUNyOThPVDU5bTZVOU56V2xqeWt1cXk3UjZRYjlBYnVIMkxEMVBKeF9fUkljSzZieWtzdWd5aFp5S3lrN19Cbkg1ckdmdk5nZXRlemtKZWFHZVlyTEhWUjhZWXZhY3JGU25XQXUtN1JfdDVn?oc=5"
    },
    {
      "also_reported_by": [
        {
          "source": "NewsBytes",
          "url": "https://news.google.com/rss/articles/CBMirAFBVV95cUxNTERCcVh3amlkdjBfOU9oZmdDTlExRDFvNW5maXNYeHRFaWwzUzdDU3NOOHdtTW12TnFpTXoya2c3NUtLamJ5QnptUzBGY3RTemZET0tCbnJHcTM0U3RhZ3pWQVJ1Sks0YS1lWUJ0OFZYYUpaeVR5Y0M4V0hKeHliMVpQeXQ4el9fVmJMU0gzNW04RktCblV5Z1hKb1JmbTJfTS1hS2kwUW1iNW1N?oc=5"
        }
      ],
      "confidence": "Likely Mapping",
      "date": "2026-03-19",
      "detection_surface": "Egress destination, payload metadata hash, and session-level intent drift",
      "failure_pattern": "Data exposure / exfiltration risk",
      "recommendation": "Restrict egress, monitor destination drift, and keep sensitive outputs behind review gates.",
      "relevant_awr": [
        "AWR-111",
        "AWR-006"
      ],
      "severity": "High",
      "source": "livemint.com",
      "source_type": "Public reporting",
      "summary": "Meta AI agent goes rogue, leaks sensitive company and user data in major internal security breach: Report livemint.com",
      "title": "Meta AI agent goes rogue, leaks sensitive company and user data in major internal security breach: Report - livemint.com",
      "url": "https://news.google.com/rss/articles/CBMi_gFBVV95cUxOV3MzSS1PYV9FODlLTXp3bFFzbGJvZ201R29OdXJRS1BYMG5HdG9WMk9QcURwR0dBVW1wME03Q3p6SDNMVWVQMG13eW9xOVJrYXcxVUxXeXdfbnlzaGNaVE04d2ZuVDhnb01XTVloYTVuX0hrcnU2cmt4SUYtODNkUHFrNVlFU2JGcFZvYUM1N1lGV3F0YVBFaG5MbTVsYTk0NG5mRnA1ZkljNWZFMDdjTU9hVGtWeUxYYlRoUWNWY3YwaXJkU2VWUFRZRVhLVi0yV3JCUzU0dVFWdFh3ZmdKYWE2M1RMMzZnUzBETThhd0NENWs1QmE5SFZTSFN1UdIBgwJBVV95cUxPbUhGY2Y0TW10bUF4Y0wydGdiRHM0ak14QTlLOU5ReS1jaEFva002eFVrS1hiekdlQVNiYS0zYWFBbTVMQUpJbWdXSG82VHZScU1mUVZLcF9vcFpEZUJqaTRIbk1fT2pNNG9KNjJFb3hhNFVqaGhVZmZTeTF6MUdYMTNUWHBzVE9lOTFmQlg3Qktob3hySVRpUXhEeS1FY2wyTWVCNmphU0t4T0F6eUR1a05OeFRfRGp5NFRYQnFGQnU2X096NjBfaVBXTWpkWGtUQndra0VzcjRWWWxpU2NlNEdmN0h1d19HVnd3bkZnekt2UDdWOGlpVXVmQzkta1hSVzRv?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-03-18",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Unit 42",
      "source_type": "Public reporting",
      "summary": "Navigating Security Tradeoffs of AI Agents Unit 42",
      "title": "Navigating Security Tradeoffs of AI Agents - Unit 42",
      "url": "https://news.google.com/rss/articles/CBMiggFBVV95cUxNTmlfZmlTOHZwaXh4Nk1aeXNfcG5KV3AxRGJtUFdSaUdfYmstMmZKVlR0Zm05dDBKZUp0MDU1RGV4cGFwZ3VYNzZRelE5N2Y1TEF4XzhHa2p0N0lOUkwzNVlXWnlHWkF4R0NRWWVrREh3c0x4SDl6TVQySmpzVlRQd0VR?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-03-10",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Help Net Security",
      "source_type": "Public reporting",
      "summary": "Singulr AI\u2019s Agent Pulse delivers enforceable runtime governance and visibility for AI agents Help Net Security",
      "title": "Singulr AI\u2019s Agent Pulse delivers enforceable runtime governance and visibility for AI agents - Help Net Security",
      "url": "https://news.google.com/rss/articles/CBMi0gFBVV95cUxQTDdSYXh3ZEc5ZjhscEhYdS1kTTdTRTVnaHE2OWFvTWxYRTBWTTFiMjNNVlhfaWpwRnUwS3ZZRGVKSGlhaGVnckRIdEVRc1d3MGZTTzdna3p0NUQyeFI3Z1k0dXZXTVF0SW0zSWRCQkpUalF4M2xDckxCSzhlX0syTzFMVmQzd1VqQ0RfQkdUSmtTa19PR0ZfVjNKejRqeUFGdEwyek8ycENZaWhxTmszaVU1dUJZVDlEZHFoYjJJc0NPcndqVUVNekVqb0Z5M2ozcWc?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-07-01",
      "detection_surface": "Prompt-hash transition, tool call sequence, and session trace",
      "failure_pattern": "Prompt injection / instruction override",
      "recommendation": "Require approval before sensitive tool use and restrict untrusted input from tool instructions.",
      "relevant_awr": [
        "AWR-111",
        "AWR-001"
      ],
      "severity": "High",
      "source": "The Hacker News",
      "source_type": "Public reporting",
      "summary": "Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands The Hacker News",
      "title": "Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands - The Hacker News",
      "url": "https://news.google.com/rss/articles/CBMigwFBVV95cUxOeFptMWpkSko3UmwtVXdmSHBWQjN3MEVvVU4zOUtBaEhCSHREckNCVXVmZ2haMFJmZWxadWo0MlFtdVZCaDRyWkMzeXpwbWdqak5BY3o1WlFiUk5BSnhjeTJfVXBUQTk4c1dKZ2pGSUV3cFJsdHRDTEVMTTlGUEJIZ1NUbw?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2025-12-22",
      "detection_surface": "Prompt-hash transition, tool call sequence, and session trace",
      "failure_pattern": "Prompt injection / instruction override",
      "recommendation": "Require approval before sensitive tool use and restrict untrusted input from tool instructions.",
      "relevant_awr": [
        "AWR-111",
        "AWR-001"
      ],
      "severity": "High",
      "source": "OpenAI",
      "source_type": "Public reporting",
      "summary": "OpenAI describes prompt injection as an open challenge for agent security and discusses red-team driven hardening for browser-agent workflows.",
      "title": "OpenAI discusses hardening browser agents against prompt injection",
      "url": "https://openai.com/index/hardening-atlas-against-prompt-injection/"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.14216v1 Announce Type: new Abstract: Penetration testing is essential yet resource-intensive. Although large language models (LLMs) show promise for automating security auditing, existing agents mainly execute end-to-end workflows in simplified linear scenarios..",
      "title": "MazeRunner: Nonlinear Task and Clue Orchestration for LLM-driven Black-Box Automated Penetration Testing",
      "url": "https://arxiv.org/abs/2608.14216"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-04",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "The AI Security Institute (AISI)",
      "source_type": "Public reporting",
      "summary": "Incident Report: unsanctioned agent behaviour during cyber testing The AI Security Institute (AISI)",
      "title": "Incident Report: unsanctioned agent behaviour during cyber testing - The AI Security Institute (AISI)",
      "url": "https://news.google.com/rss/articles/CBMimgFBVV95cUxOaUZaRW5ReTV2VjNHQUZneFRBNTFQNG9mclc0dHBfLTRFSzEyazAxdDE3S1E1c2lzOS12TFZkTzNnRlk1Q1lpQVZ3MHNlbXpzX2JDaEJUckNDekNhenBHZ05MZTQwLVpYR3VXY0ZMNnZBSkw2cGhwQUxMMHVEbml5aFRKLW0yN1JSaVV3djcza24xaVMyNVREVG9B?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-07-31",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Tech Times",
      "source_type": "Public reporting",
      "summary": "SecRespond Benchmark Exposes AI SOC Blind Spot: All 23 Frontier Models Miss Silent Intrusions Tech Times",
      "title": "SecRespond Benchmark Exposes AI SOC Blind Spot: All 23 Frontier Models Miss Silent Intrusions - Tech Times",
      "url": "https://news.google.com/rss/articles/CBMi4AFBVV95cUxPNFFpQnV5ajdDbEJ6R2VDb0M2TmJsdjdacTliaDkxMUt4d2dYcHA2TVVHRVhrYUhzMEdoUDhrNlREWk5XS01qbTFlMXRVSXd0cDh0VlFGVjl0SGp5c0N0RENrbU50RjU5ZVliUVJqcXZSbzU4RW9hZXlhdC1TX3NXNmpzcXQySjNrTEtzemE5VkxCbEFrVE5EMlRBNF9VQzA5RmlLbEJiaEhFMlUxanRnUUxvbjE5WTBsVzNxUm9xRjU3bjhrejRfOHc3Q1ZwWHpjb3FlbjdTbVUzYzNrYXJaLQ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-05-13",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "wiz.io",
      "source_type": "Public reporting",
      "summary": "Securing Agentic AI: What Cloud Teams Need To Know wiz.io",
      "title": "Securing Agentic AI: What Cloud Teams Need To Know - wiz.io",
      "url": "https://news.google.com/rss/articles/CBMiakFVX3lxTE9EZndqR3BUbmJpVURNNkVPcjg1d3RIaUxMSUx5Qkl5QjJhanFQeHN4b0VKM0JTMk9MakVOTWtHSkVsWFlIZEE5Rm82N1FMYktEWVhtUXRrNzZ0YWh1UWdWNGZDMkM3NEpNNlE?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-05-07",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Microsoft",
      "source_type": "Public reporting",
      "summary": "When prompts become shells: RCE vulnerabilities in AI agent frameworks Microsoft",
      "title": "When prompts become shells: RCE vulnerabilities in AI agent frameworks - Microsoft",
      "url": "https://news.google.com/rss/articles/CBMiuwFBVV95cUxQU3p1SFVidnhmS2lIcGNTbUEwVmxRVlUwOHpsWlZySmhObzE4MlMyN3NWWjh5MzR2cVNvRGlERVhlS1o3ZVg4b1JnYTZXanA4YjZPZ3JwNlR3VFF6Y2VSaU9FTzVXVlNaczlqZWNYUlFFZXQ2SHdYcTZPOVFscEd6Q3diNlQtVnZCRlJnY2JreHRaUTctOVY0Wll0SlZLYy1zallsOVc3NVNNSjFvUGd2aHlfZjV2X1pvRXRJ?oc=5"
    },
    {
      "also_reported_by": [
        {
          "source": "Startup Fortune",
          "url": "https://news.google.com/rss/articles/CBMikgFBVV95cUxQdnNwU0Z5ZnVwZUh6RDVxUEx2RlNlSUtPQWlCS0wzZjYzNDFXQVIyaFIwaWRaWWpPY3FjMjEyWUhXMDBlZGJDMEZ0UkZidUdFUFZWczhrOVY0dmQ4MC1nOWtfNXpEc2lwQVQ3OHR6LWp4ei1hd0NSRTlITzJzeVlGWUQ1VVZrY1poYWVuOFVYZHgyZw?oc=5"
        }
      ],
      "confidence": "Likely Mapping",
      "date": "2026-03-31",
      "detection_surface": "Egress destination, payload metadata hash, and session-level intent drift",
      "failure_pattern": "Data exposure / exfiltration risk",
      "recommendation": "Restrict egress, monitor destination drift, and keep sensitive outputs behind review gates.",
      "relevant_awr": [
        "AWR-111",
        "AWR-006"
      ],
      "severity": "High",
      "source": "Crypto Briefing",
      "source_type": "Public reporting",
      "summary": "Anthropic\u2019s Claude Code leak reveals autonomous agent tools and unreleased models Crypto Briefing",
      "title": "Anthropic\u2019s Claude Code leak reveals autonomous agent tools and unreleased models - Crypto Briefing",
      "url": "https://news.google.com/rss/articles/CBMibEFVX3lxTE1Ud0pLYnJxNmdsWGE4MTFJQ0l1LXE2SWNWbUFPbVpZdkk1S1RpcFFFdGFvSUpwbmlZR1ZBeFkyNm5BRFJ2dzZOZXlLTUJmM3RiQVljZnBmT2F6QmhGS0dLamdaejhvNFFTSmE3NQ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-03-23",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "NVIDIA Blog",
      "source_type": "Public reporting",
      "summary": "How Autonomous AI Agents Become Secure by Design With NVIDIA OpenShell NVIDIA Blog",
      "title": "How Autonomous AI Agents Become Secure by Design With NVIDIA OpenShell - NVIDIA Blog",
      "url": "https://news.google.com/rss/articles/CBMid0FVX3lxTE5MVDdNZXdCLTFhOXBaZDhQb25wUXRJaXlieHVrb0hoNVJRLU5rbTlxTU1HdzlsS1V5alJ5cVJzME1JeEgxNHRYSW00LXo1akFwWE5FZTdzaHJ6TW1JdllVUU5TdlN2Um5lZWhxUnVxT0lIZkJFeWw0?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-02-12",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "SC Media",
      "source_type": "Public reporting",
      "summary": "Scaling SaaS security to manage agentic AI SC Media",
      "title": "Scaling SaaS security to manage agentic AI - SC Media",
      "url": "https://news.google.com/rss/articles/CBMigAFBVV95cUxOeXNsUVhJT1JNVTFrRVZEWWVjaWNiTHBTdUVDVUxIci1rY1lzZEViSGRnQ3pNWHRva1RpVkVodk9ObXI0WENVSmRlc0VNU3pnY1ROeVllandDa0doSkp5MWFrWlVMNkhLRkxYU0Fxc0xHVHBaMDlQY3ZkaDcySWl0Ug?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-01-04",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "The Register",
      "source_type": "Public reporting",
      "summary": "Palo Alto Networks security-intel boss calls AI agents 2026's biggest insider threat The Register",
      "title": "Palo Alto Networks security-intel boss calls AI agents 2026's biggest insider threat - The Register",
      "url": "https://news.google.com/rss/articles/CBMivgFBVV95cUxPM3psOG9QTWo0MHZrWmZSRVR3RUNjaVE0N0FybzVEUmNrX1NzN253aG9xdUhGMkY3bEkzcG1DYXpBeTZHR3l0VEd3Vmsybm5tXzRneVltblotakxTSTdQMmZBZ25tSlR6YVJWbk4yVWhRcVN3eFU5ck94bl81RzhLOUpkbUNRV1U4RFI5TExVUi1oUjBzUHdKWjlHU3YzNU5IVUJZd0xIYVoxUW0tRHpGaXpJLUM5dW1WRUxwaVZ3?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-12-09",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Help Net Security",
      "source_type": "Public reporting",
      "summary": "AI agents break rules in unexpected ways Help Net Security",
      "title": "AI agents break rules in unexpected ways - Help Net Security",
      "url": "https://news.google.com/rss/articles/CBMieEFVX3lxTFBiclRSUDN4dzQtUDE3dnpyblVPQzlyaGplNjJqcmN2VmZtRWQwa3dQMjFjNnkwZTVkYy1BOW5IZTlqVWdPeHFCUlNtRFR1OVFyZnF5bTdJTnJFTkIyY2NvR0M3alFPU2RyQWJQQXFHUVdKdUZ6bUwxdw?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-12-08",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Help Net Security",
      "source_type": "Public reporting",
      "summary": "NVIDIA research shows how agentic AI fails under attack Help Net Security",
      "title": "NVIDIA research shows how agentic AI fails under attack - Help Net Security",
      "url": "https://news.google.com/rss/articles/CBMihwFBVV95cUxPU2pWTmdoYWRnZ1hfS2NyOWhMMldhb1FadkxmU2VGd3RsX2E2NWdhMmtyM2RUUHAxRjhhazg0akVwcV9jVC0zOXdabUtoTGFjRkZHaVNfXy1rbWZDTjk0TWFEV2dRRVMxNkNYcV9RTXJzbWNBeFQxNUs5RkxseVJzcHM0cy1mem8?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-11-26",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Palo Alto Networks",
      "source_type": "Public reporting",
      "summary": "Agentic AI Security: What It Is and How to Do It Palo Alto Networks",
      "title": "Agentic AI Security: What It Is and How to Do It - Palo Alto Networks",
      "url": "https://news.google.com/rss/articles/CBMie0FVX3lxTFB6cThVWTAyNXJQeUIwbVBlNVFqQmZoMGtCaEltZHRWRlFYb2ttZF9iSEJnYjZEZURHYzFxTmlEblU4a0Y1bkRSVTBmR1gwMlNNS21USFRmTzh4YzVpdVdJYjlMaGlub1MtRXZXeDdZWkRhbFFWRkpTZ0U4NA?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-11-22",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Medium",
      "source_type": "Public reporting",
      "summary": "Security in Agentic Communication: Threats, Controls, Standards, and Implementation Patterns for\u2026 Medium",
      "title": "Security in Agentic Communication: Threats, Controls, Standards, and Implementation Patterns for\u2026 - Medium",
      "url": "https://news.google.com/rss/articles/CBMi0wFBVV95cUxOOUhKMHk5Y3VESmsxT2s0d0dQSnZhcVotRE13T1RoQXhYS09SelcxUEU1YUFhbXlTYzJvQ2NBLW9WaFJ2dTMwT1plNE9POXZMRDFqS3BGc0VQajR5M2J1V05JZmZEMVhYNWlzT251enl4bGpaSVI1ZFNKa2xoMU5XOFRYSTl3bHZmc25jdTNidkxnb3d0dmUwd3c4bXNGSzU2dUkxalFBbW9jOF9manF6b3ZlVVZUWU50QzVJSWR4UE5SZWlsM0hvY09Yemp5Q0EwRTZV?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-10-04",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Medium",
      "source_type": "Public reporting",
      "summary": "Hardening AI Systems: Security, Robustness, and Safety for Generative & Agentic AI Medium",
      "title": "Hardening AI Systems: Security, Robustness, and Safety for Generative & Agentic AI - Medium",
      "url": "https://news.google.com/rss/articles/CBMivwFBVV95cUxQdGdVWllTdE51eFZaNHhSdmdKX0k5RHUwNmdyT2FXczhGd2JQT21JZ1FRdUl5bjYyZ1RwRC1xODM2d2ZWTXNSdlpROHNDeGJOWjQzaUt2d25TclpvZjl3QUlORjVUMzFmbElRUGdGbkJwMzF2VEx6YmFRZnZCOENYWkZ4VkJBU29ESHlCRkg4SU9SckhEekJScXBhY3dUT3Q2NV9UREJkb3hXem4yS2NjckduS3pyc0xTZW1mYVp3cw?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-08-19",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "TechTarget",
      "source_type": "Public reporting",
      "summary": "9 Agentic AI Security Risks and How to Prevent Them TechTarget",
      "title": "9 Agentic AI Security Risks and How to Prevent Them - TechTarget",
      "url": "https://news.google.com/rss/articles/CBMipAFBVV95cUxNbWVGU3lXRldSSTJwWmlmdXFDRDREZ3V2U2RGSGNCbVA0ZkFWY1JNdDJIQjZ0YXRUUUw2MkJrMmxCSnlrdmc3ZHIxTFNRLXBkcDJENXJsbU1JZHlFSk8zVFFjcDF5U3NLWnE1emZpeG9lOExoQXliTk81Y0doVk52eXNJQUFkMENEVkhGNnA4Q0FWaGJkNF9sWlVUcFR4clBYRVNqMw?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-08-18",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "CX Today",
      "source_type": "Public reporting",
      "summary": "A Customer Service AI Agent Spits Out Complete Salesforce Records in an Attack by Security Researchers CX Today",
      "title": "A Customer Service AI Agent Spits Out Complete Salesforce Records in an Attack by Security Researchers - CX Today",
      "url": "https://news.google.com/rss/articles/CBMiywFBVV95cUxPeHpQbzF3MHk0dC1kVUJRSnpBUlBhQmJvczI3VFFneVZJZ1h0Q3RJN1V6anl2YjN6Z2NtQi1MaE1UcGpZTlhjcEUxYWZjWVZZWVh3dTR5MEFWOUhhOTY5dXBCY0ZFNFJjWjJJc2VUVmZMbWNpVFdGSXVpYVNBUzJpa3EwWDJDNXRyOFpDbERfMmdTSjZIUTBuTHpUSnBMTWRLd2dnUWZicE5kRnJrYUF2cUotSDVseWU2ampjZS1sOXVqYmNkamRnb3FfVQ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-08-17",
      "detection_surface": "Event cadence, repeated action pattern, token spend, and progress stall signal",
      "failure_pattern": "Runaway loop / economic anomaly",
      "recommendation": "Set cost and cadence thresholds with automatic holds for repeated or stalled actions.",
      "relevant_awr": [
        "AWR-114",
        "AWR-108"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.13404v2 Announce Type: replace-cross Abstract: Background: Iterative feedback loops are the dominant paradigm for improving LLM-generated Infrastructure-as-Code (IaC): validators such as Checkov and terraform validate feed error signals back for successive repair.",
      "title": "Does Fixing Break Security? An Empirical Study of Security Degradation in Iterative LLM-Driven Infrastructure-as-Code Repair",
      "url": "https://arxiv.org/abs/2608.13404"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-06",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "storyboard18.com",
      "source_type": "Public reporting",
      "summary": "After OpenAI and Anthropic, Meta reports AI model security breach storyboard18.com",
      "title": "After OpenAI and Anthropic, Meta reports AI model security breach - storyboard18.com",
      "url": "https://news.google.com/rss/articles/CBMisgFBVV95cUxPbmpwV19pUFdZQmJ5aG5QRTZJa0R4UFpVWFkwSl9iZmpQVkZJTmlaYUFmeW9qcE5RQTRSSHNsS1Q4SGlsdHFMR3Q2N1BaZkhSZGpVSElaVlVzQUdsVEJvRkFHdlp5QVRaZUhxYkprQkVPd3FpMUNGNnRTc1ZDUzk2RVNtLWhNMWRKZk9EczFWNklYY013cGU1bEVMZDlsYVNKZVN4MTJGU1pfLTVNOVBGMU1B0gG3AUFVX3lxTE9EZ1h1cGpscEFWRThJa3JUd3kwbUhaMjRNZU5oNXpTTm43YjZ2YVpKM25ENExtT3RGX2JWYUs4WWxDZ0w3UkZrYlVWakY4Vlc5RHZHYTFzMGp0eWwzbmV1SHRCdVlmTWFFVmNITDBpVzU1cWdQb1NpQVhDcHpjeENVYnpyQTZ4bXBOeEdPRW1RT0lpRXNWaWFTbVZmV2JMN1BmcTlHV0EyLXMzWXJmY3k2ZGZQdjBDbw?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-06",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "thevibes.com",
      "source_type": "Public reporting",
      "summary": "Meta AI model exploits security flaw during cyber test, raising fresh safety concerns thevibes.com",
      "title": "Meta AI model exploits security flaw during cyber test, raising fresh safety concerns - thevibes.com",
      "url": "https://news.google.com/rss/articles/CBMi0gFBVV95cUxOSjhDRzFMZm83amM3YVZreTZQU05pVzBwb0RBQkVXdmprM2hWUDJRc3BEVzJtVEpzaEhMbllTQThNZzRHV29yaEJaQ0pKZnR2aGgxVlBHbHllY1cyWnp5a3BQTWVlYi12QW4xWWhLbDlSZFYtOUxEWE9XNHVHU2w4ZElsNm42V2ZEZWdsODl3bFQwZi0yWFN4R2UxM2VjZXNfT2tEVjFlcnZUY3VCRl9jRWRlaGJPdWRBQ2tGOXUwRldTRi1PTm9ESnRjMnRpNkNld2c?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2025-12-13",
      "detection_surface": "Prompt-hash transition, tool call sequence, and session trace",
      "failure_pattern": "Prompt injection / instruction override",
      "recommendation": "Require approval before sensitive tool use and restrict untrusted input from tool instructions.",
      "relevant_awr": [
        "AWR-111",
        "AWR-001"
      ],
      "severity": "High",
      "source": "ICT Express",
      "source_type": "Public reporting",
      "summary": "A survey of LLM-powered agent workflows catalogs prompt injection, plugin, connector, protocol, privacy, and system attack techniques.",
      "title": "From prompt injections to protocol exploits in LLM-powered agent workflows",
      "url": "https://www.sciencedirect.com/science/article/pii/S2405959525001997"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2025-11-21",
      "detection_surface": "Prompt-hash transition, tool call sequence, and session trace",
      "failure_pattern": "Prompt injection / instruction override",
      "recommendation": "Require approval before sensitive tool use and restrict untrusted input from tool instructions.",
      "relevant_awr": [
        "AWR-111",
        "AWR-001"
      ],
      "severity": "High",
      "source": "TechRadar",
      "source_type": "Public reporting",
      "summary": "Reporting on ServiceNow Now Assist research describes second-order prompt injection risk where lower-privileged agents may influence higher-privileged workflows.",
      "title": "Second-order prompt injection can turn AI into a malicious insider",
      "url": "https://www.techradar.com/pro/security/second-order-prompt-injection-can-turn-ai-into-a-malicious-insider"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-08-17",
      "detection_surface": "Egress destination, payload metadata hash, and session-level intent drift",
      "failure_pattern": "Data exposure / exfiltration risk",
      "recommendation": "Restrict egress, monitor destination drift, and keep sensitive outputs behind review gates.",
      "relevant_awr": [
        "AWR-111",
        "AWR-006"
      ],
      "severity": "High",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.13806v1 Announce Type: new Abstract: Hardware authenticators deliberately resist private-key extraction, yet replacement, disaster recovery, and controlled migration create a legitimate need for portability. Existing guidance for device-bound credentials commonly.",
      "title": "Vaulted Passkeys: A Device-Bound Proposal for Authenticated Credential Export and Import",
      "url": "https://arxiv.org/abs/2608.13806"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2507.13505v2 Announce Type: replace Abstract: Cybersecurity simulation environments, such as cyber ranges, honeypots, and sandboxes, require realistic human behavior to be effective, yet no quantitative method exists to assess the behavioral fidelity of synthetic user.",
      "title": "PHASE: Passive Human Activity Simulation Evaluation",
      "url": "https://arxiv.org/abs/2507.13505"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.13030v2 Announce Type: replace Abstract: The emerging Internet of Agents enables LLM-powered agents to discover peers, invoke tools, and delegate tasks across organizational boundaries. Existing protocols increasingly define how agents exchange messages, but not how.",
      "title": "InterSAGE: The Secure and Verifiable Interoperability Protocol for An Internet of Agents",
      "url": "https://arxiv.org/abs/2608.13030"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-08-05",
      "detection_surface": "Egress destination, payload metadata hash, and session-level intent drift",
      "failure_pattern": "Data exposure / exfiltration risk",
      "recommendation": "Restrict egress, monitor destination drift, and keep sensitive outputs behind review gates.",
      "relevant_awr": [
        "AWR-111",
        "AWR-006"
      ],
      "severity": "High",
      "source": "en.softonic.com",
      "source_type": "Public reporting",
      "summary": "Autonomous software agents face fresh hacking attacks: hidden instructions can leak your data en.softonic.com",
      "title": "Autonomous software agents face fresh hacking attacks: hidden instructions can leak your data - en.softonic.com",
      "url": "https://news.google.com/rss/articles/CBMiwwFBVV95cUxOaUZGbnIwY2JqYTlCZUJqQ2k5VWpfQXdBdk0xeXJJMXR2ckM4Qkl3RE8zVmhsTU82TlZTOHVFS0cxSVF0NkV5UTBPUlhfc1owMkdJdkFRSGR4T0FJNlYwNkZGdHRYWkx0WTc0Qm5NZlVQakplUy1IbDlNbEtLSm5nUF8zYVBDamdzblJuQUNCZ2hvS3VuS2Z3Y2xROTVxczE3czE0QjNtanQ3Z2YwUWR6OHdfbUFWMXBTR1laeWk4dGRKVFU?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-05-04",
      "detection_surface": "MCP graph edges, privilege expansion, and scope explosion",
      "failure_pattern": "Connector or tool-surface expansion",
      "recommendation": "Pre-register tools, review requested scopes, and alert on unexpected graph expansion.",
      "relevant_awr": [
        "AWR-112",
        "AWR-113"
      ],
      "severity": "Medium",
      "source": "OWASP Foundation",
      "source_type": "Public reporting",
      "summary": "OWASP describes MCP tool poisoning as a runtime trust-gap issue where malicious tool responses can inject instructions into an agent context.",
      "title": "OWASP describes MCP tool poisoning as an indirect prompt-injection attack",
      "url": "https://owasp.org/www-community/attacks/MCP_Tool_Poisoning"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-04-23",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Yahoo Finance Singapore",
      "source_type": "Public reporting",
      "summary": "Tencent Cloud Cube Sandbox Goes Fully Open-Source, with Five Major Breakthroughs Enabling Large-Scale Agent Deployment Yahoo Finance Singapore",
      "title": "Tencent Cloud Cube Sandbox Goes Fully Open-Source, with Five Major Breakthroughs Enabling Large-Scale Agent Deployment - Yahoo Finance Singapore",
      "url": "https://news.google.com/rss/articles/CBMihwFBVV95cUxPeFRJVk1nVUUzTThFS295bkJtdDRZREdaMmRESTR0Umk3dUlpOWZEY1dQMlU4cTExOEJmOE1mU0JTQmd1cDdWX3h5eGY1V295MHh5YTJWN09HSk9QbUR1S05wNTNvRU9aaEM0UVJPRVhmT3FzVnB3VzhRNFpwbGZJbmc4MTZwV28?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-06-19",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Infosecurity Magazine",
      "source_type": "Public reporting",
      "summary": "Researchers Warn of 'Living off AI' Attacks After PoC Exploits Atlassian's AI Agent Protocol Infosecurity Magazine",
      "title": "Researchers Warn of 'Living off AI' Attacks After PoC Exploits Atlassian's AI Agent Protocol - Infosecurity Magazine",
      "url": "https://news.google.com/rss/articles/CBMifkFVX3lxTE9XMlliSUZfbUU5Y05Kdk5HQTFhc1NJejFkMlR2UGR3eDVFVFFtVU1xeGxvbnp3S0ZOTDRNc3R3OENUaUVoS21LbllJd3ZuUEg2Q2pLcVVHa3B5X0t0SnBJcFQ5OE4tX2hQbk5uOGs0YzdVSGtWVUdBUFdlb3pGZw?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-06-12",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "TechTarget",
      "source_type": "Public reporting",
      "summary": "Datadog AI agent observability, security seek to boost trust TechTarget",
      "title": "Datadog AI agent observability, security seek to boost trust - TechTarget",
      "url": "https://news.google.com/rss/articles/CBMivAFBVV95cUxOSmxQN0RZSFE3UnlwMU1oZXlVaVBVU3NMSm8wNUxvQkQ3NjF4ZEZwTWVYbjRXS1RYRFBnUHlmUWdUVEhPZUxnMHh4XzBPNUN0TDk0SGJuLTB0OTc3RG5LLTJwdnpSNEFBOVc5T21qdnc5cHFVQjdGbE5obUpKdGE1aFhORHVVZFpjOTIteW5Vck43UHA3UmViY2FVcnJrOHJMcGdMX3JBTlhWQjFSbmJFQlJQVkI5eGdVSlNpXw?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-06-09",
      "detection_surface": "Egress destination, payload metadata hash, and session-level intent drift",
      "failure_pattern": "Data exposure / exfiltration risk",
      "recommendation": "Restrict egress, monitor destination drift, and keep sensitive outputs behind review gates.",
      "relevant_awr": [
        "AWR-111",
        "AWR-006"
      ],
      "severity": "High",
      "source": "AI CERTs",
      "source_type": "Public reporting",
      "summary": "Claude Security Risks Surge Amid Code Leaks and Credential Theft AI CERTs",
      "title": "Claude Security Risks Surge Amid Code Leaks and Credential Theft - AI CERTs",
      "url": "https://news.google.com/rss/articles/CBMimAFBVV95cUxOVmpBUE0zOEI0YlB5bF9tMEU2RkZjWmhyZ3JtTmhDcm4xNFowWGRkNGE5RkMzUFQwNXdGZzdCTEx1Zlc2N2xkODhGQmdhZmZoUXNwZndib0dMYjNiUVJhWmJlWUlNQmpLcTRWaWd1bWFCdVRYdXVwOFYwUnFwV09DMWQzOHNkMG9xQk1uNmYwZ0ZaNXQ5cXo1TQ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-02-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "The Futurum Group",
      "source_type": "Public reporting",
      "summary": "Can Proofpoint Secure the Intent of the Autonomous Agent? The Futurum Group",
      "title": "Can Proofpoint Secure the Intent of the Autonomous Agent? - The Futurum Group",
      "url": "https://news.google.com/rss/articles/CBMilgFBVV95cUxNNEF2X3cwSnB3dHRsV1hkYWJpSjVxNkJRSmZNaGtNR1U1dDFFODZzMUlFQ3dvUmVFVW1DRUdFUkJpSG1wVW96YVBidXdRV0xvaHhsSzFfTi1tOXZ6eHlWeS1ucXduOXktU0hGNHpYYmxhMWhIWURNVk1QNnVOSzBYUzlyOUlTNWVsRGc4bzYyajE3RlBvYVE?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-02-13",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "VentureBeat",
      "source_type": "Public reporting",
      "summary": "How to test OpenClaw without giving an autonomous agent shell access to your corporate laptop VentureBeat",
      "title": "How to test OpenClaw without giving an autonomous agent shell access to your corporate laptop - VentureBeat",
      "url": "https://news.google.com/rss/articles/CBMirgFBVV95cUxONlFDd2c1b3RYWm9jbGdTZVAzeHQ0M3FSUUxFend3TjBJa05EVlpJZi0wSWFQbUs3RmV4enBSS3RCbWVqWGg4Tjh0NUNDUWttQTVNdWNhdjJNcUR5aWhIaG0wUDk2TC1IMjJOR0g2a1ZNR3hpbEZ0QTFrZVZDc1JMZVNDNVp4LVppTHlLbjJ5MHI5dW9hcndVYnZPMzhkbjUtMGlVZjRLc29NOGczdXc?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-11-18",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "PR Newswire",
      "source_type": "Public reporting",
      "summary": "Palo Alto Networks Announces New Prisma AIRS Integrations With Factory, Glean, IBM and ServiceNow to Secure the AI Agent Boom PR Newswire",
      "title": "Palo Alto Networks Announces New Prisma AIRS Integrations With Factory, Glean, IBM and ServiceNow to Secure the AI Agent Boom - PR Newswire",
      "url": "https://news.google.com/rss/articles/CBMiiwJBVV95cUxOVjBVRHIzajFBd3dnM1FsOG9KWDZWSVp2VEt3dGstSVNTMXMycy00dDJJLWMySVJydTItYzlWdjRCcUNhUi1RaVB2bGo0dXY5U2ZFb01TaGR6Q0xOU0J0NHNVSzRXUGRQREZabkFJaDhtVE44eUJwSU12YkJPUVNOMFBNLWtuT205UXRkRURuZE8yTmt2cWc4XzEzZ3hyTnZDdnB3OHZnbkd1bTk5Ym03NXZkaUJwOEJzMGVMQ0MzUF92VWwwZ0dOek11VzFZVmlYeEF5azNxcnk1ekhIS2N0TjNMa2lFTmRYSE5qdWVGS2RwakZodV9jdlBxSjFvNWtCQnhGN0dULTl3N1U?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-11-18",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Medium",
      "source_type": "Public reporting",
      "summary": "Vibe Hacking and Agentic AI Misuse: Lessons from the First Documented AI-Orchestrated Cyber\u2026 Medium",
      "title": "Vibe Hacking and Agentic AI Misuse: Lessons from the First Documented AI-Orchestrated Cyber\u2026 - Medium",
      "url": "https://news.google.com/rss/articles/CBMi0AFBVV95cUxPN3dPTGwyZGlzd2YwV2taWHN1dkFIeDVER0FYdFYyN2h6eDh6NjR2Y0RPYmh1YVNYekVoaEhTOXZmT0Uta2dNa0szUHN0VmxkTWxDVkhaU1hBN3gxUWlPTVpoVXowWWtJQ0llcDFJeFJtTXhsNEhyaVhmQmdZSnRwUFhjSUVGWTZqbFVncmNnYzhVLXJuLWVUanZ5dzlwX0VLdGRGTWZ1QVhjVjRtb0NRR2pCaFdGU3NNc3JoWXd2dW5qY2J0VDFmazZYM2wzeDVa?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2025-09-25",
      "detection_surface": "Egress destination, payload metadata hash, and session-level intent drift",
      "failure_pattern": "Data exposure / exfiltration risk",
      "recommendation": "Restrict egress, monitor destination drift, and keep sensitive outputs behind review gates.",
      "relevant_awr": [
        "AWR-111",
        "AWR-006"
      ],
      "severity": "High",
      "source": "darkreading.com",
      "source_type": "Public reporting",
      "summary": "Salesforce AI Agents Forced to Leak Sensitive Data darkreading.com",
      "title": "Salesforce AI Agents Forced to Leak Sensitive Data - darkreading.com",
      "url": "https://news.google.com/rss/articles/CBMilwFBVV95cUxOVk9RcmQzRG54M2E1NHROOUFpNmQ1RjZqcjdTa3N2Nm1DbWtGY01SdXpJTmFCOXFER0hib183QWUydkZJaEhqYWhHTkxVLWZ6cnN1eVVkWHE4WjdDZzZWWnNwYzFTQ3BQUnZwMllxRHBRdy1uRXdXcE5Td0VheXBCS3dIclBaQU1WdU5FS1FYaVVZdFBxZXRV?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.14089v1 Announce Type: cross Abstract: Safety classifiers deployed with large language models often fail for two reasons: their decisions reflect the policy learned during training rather than the deployer's desired policy, and their performance degrades as.",
      "title": "Regime-Conditional Verification: Correctness Estimation for Adapting and Monitoring Safety Classifiers",
      "url": "https://arxiv.org/abs/2608.14089"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-07-24",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Time Magazine",
      "source_type": "Public reporting",
      "summary": "How OpenAI Lost Control of an AI Model\u2014and What Needs to Change Time Magazine",
      "title": "How OpenAI Lost Control of an AI Model\u2014and What Needs to Change - Time Magazine",
      "url": "https://news.google.com/rss/articles/CBMicEFVX3lxTFB2SXZ0SXhYeUpETjZ2T2N1aDNZaml2bzZYUmpSWlhnMENQZ2VZTWNCemJsT24zWHNQQnJ6UlZraVd0Wk1wdkNrUXdGLUhQeENDWjJTd0ZiSmUtcWU0aXd5V2xWbmt4cHFnMkFhaTlEaGg?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.13905v1 Announce Type: new Abstract: HTTPS website fingerprinting (WF) aims to identify visited websites from metadata observable in encrypted traffic. However, real-world deployments introduce a significant out-of-distribution (OOD) problem caused by temporal and.",
      "title": "CipherSight: Robust Website Fingerprinting via Record-Resource Semantic Supervision under Distribution Shifts",
      "url": "https://arxiv.org/abs/2608.13905"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-03-26",
      "detection_surface": "Prompt-hash transition, tool call sequence, and session trace",
      "failure_pattern": "Prompt injection / instruction override",
      "recommendation": "Require approval before sensitive tool use and restrict untrusted input from tool instructions.",
      "relevant_awr": [
        "AWR-111",
        "AWR-001"
      ],
      "severity": "High",
      "source": "SQ Magazine",
      "source_type": "Public reporting",
      "summary": "Prompt Injection Statistics 2026: Hidden Risks Now SQ Magazine",
      "title": "Prompt Injection Statistics 2026: Hidden Risks Now - SQ Magazine",
      "url": "https://news.google.com/rss/articles/CBMiY0FVX3lxTE5zYVJCLWo5OHhWTDg3RmZTbE8yemR0OUFsUV9rd293c2dyRHhXT2hBcmhwWnJpSW50dU1lTHZsYlJuLVdtOFNsZnFrSVY4b1FGMVpNcjYtejk4S3ljc1NRVkhkZw?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-03-03",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Cybernews",
      "source_type": "Public reporting",
      "summary": "AI bot posing as \u201csecurity researcher\u201d hacks major GitHub repos from Microsoft, DataDog, and other Cybernews",
      "title": "AI bot posing as \u201csecurity researcher\u201d hacks major GitHub repos from Microsoft, DataDog, and other - Cybernews",
      "url": "https://news.google.com/rss/articles/CBMilAFBVV95cUxOZ01Yd1loZHhNMDhFY1Nva1pWandKTmZnSFZzX1Y4eGtMbGlRR1F0bm13MFNiTDJGZjV2R3RyMS1pMllvai1mVzZ5U0xGRXVhd0hLcjhseThnbTBzOGVpWHV3ekIwR3BUYV9TeHY5enlIcGJzRjlvbll1NGdsaVhCX0ZoTGZqU2tTMXViaWhyNjVDNmdB?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-05-28",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Palo Alto Networks",
      "source_type": "Public reporting",
      "summary": "Empowering AI Agent Developers with Prisma AIRS Python SDK Palo Alto Networks",
      "title": "Empowering AI Agent Developers with Prisma AIRS Python SDK - Palo Alto Networks",
      "url": "https://news.google.com/rss/articles/CBMitAFBVV95cUxOUFo3d3Rrd2FNT3hkUjh6VEExdG1TaUNZMEp4bTFpZGk2THptLUJXRmI5ZFdydFcxQXh5R0c2QUE5RGtIOXVlVWJLZllCLVJ6MDBLWk04OW1tRTQwbDBDT2pjajFPWC1SaDNuYmZESlBMSjJhQjFRWm5JckI0QkNIXzEtYmE5MnFyd3pHVVNiTldORjFpb1lRa3JabDNUQ2hCaVBvSmdPSEFYMVBEaGJMZ21BYzE?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-05-01",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Unit 42",
      "source_type": "Public reporting",
      "summary": "AI Agents Are Here. So Are the Threats. Unit 42",
      "title": "AI Agents Are Here. So Are the Threats. - Unit 42",
      "url": "https://news.google.com/rss/articles/CBMiZkFVX3lxTE1mZktNVmRnWUVaRGRXZW04VHhEeU9GTjBzMXNKWTFCdS1Zd19Ncmtsa3pqdGMyV0dIbzU2ZHIzQXhuYVVnWENha2hIUjhXZnBJVVNWVW56QmlTS3Y3QWNma0ltVHZvUQ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.13685v1 Announce Type: new Abstract: Weird machines are latent computational capabilities that emerge from the composition of architectural components. Prior work has studied this phenomenon extensively in software systems, including x86 instructions, ELF metadata,.",
      "title": "Weird Machines in Transport Layer Security",
      "url": "https://arxiv.org/abs/2608.13685"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.13792v1 Announce Type: new Abstract: Smart-contract audits cover defined artifacts at a specific time, but the label audited is often treated as project-wide assurance. We analyze audit history and incident-path scope across 135 DeFi security incidents using the H1.",
      "title": "The ack3 H1 2026 DeFi Incident Dataset: Audit Scope Across 135 Security Incidents",
      "url": "https://arxiv.org/abs/2608.13792"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.13803v1 Announce Type: new Abstract: This study examines user perceptions of mobile applications (apps) versus web browsers for accessing online services, with an emphasis on security, privacy, and usability aspects. Through a combination of an experiment and a.",
      "title": "Mobile Apps vs. Web Browsers: A User Perception Study with Android Apps and Google Chrome",
      "url": "https://arxiv.org/abs/2608.13803"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.13846v1 Announce Type: new Abstract: Noise flooding is a standard defense against decryption attacks on approximate homomorphic encryption, but its security proof is unusually sensitive to composition. Replacing each of $q$ adaptive decryption answers with a.",
      "title": "Verified Pythagorean Composition for Adaptive Cryptographic Games: Noise Flooding in Homomorphic Encryption",
      "url": "https://arxiv.org/abs/2608.13846"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-08-17",
      "detection_surface": "MCP graph edges, privilege expansion, and scope explosion",
      "failure_pattern": "Connector or tool-surface expansion",
      "recommendation": "Pre-register tools, review requested scopes, and alert on unexpected graph expansion.",
      "relevant_awr": [
        "AWR-112",
        "AWR-113"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.14370v1 Announce Type: new Abstract: The modelling and analysis of secure business processes require the incorporation of security annotations into process models. Although BPMN extensions, including SecBPMN2, exist for this purpose, the derivation of accurate and.",
      "title": "A Hybrid LLM-Based Framework for Automated Security Annotation Generation in Business Process Models",
      "url": "https://arxiv.org/abs/2608.14370"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.14532v1 Announce Type: new Abstract: As spacecraft become more software-driven and interconnected, onboard flight software is an increasingly important security boundary. Popular flight software architectures often treat onboard components as trusted peers,.",
      "title": "Trust Without Boundaries: An Architectural Analysis of Satellite Flight Software",
      "url": "https://arxiv.org/abs/2608.14532"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.14533v1 Announce Type: new Abstract: Vulnerability detection via static analysis traditionally relies on security experts encoding insecure coding patterns into algorithmic rules. However, this approach often focuses on syntactic patterns and overlooks deeper.",
      "title": "Finding Vulnerabilities via LLM-Augmented Semantics-Aware Type-Checking",
      "url": "https://arxiv.org/abs/2608.14533"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2411.13249v2 Announce Type: replace Abstract: Lockdown Mode, introduced in 2022 as an optional security hardening setting for Apple's operating systems, aims to protect users from \"some of the most sophisticated digital threats\". We present the first academic analysis of.",
      "title": "Experiencing Apple's Lockdown Mode -- The Challenges of Providing Technology for At-Risk Users",
      "url": "https://arxiv.org/abs/2411.13249"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.02264v2 Announce Type: replace Abstract: The modern transport protocol QUIC is designed to enhance network performance and security, but it remains vulnerable to handshake flooding attacks. Such attacks exhaust CPU resources by forcing the server to perform expensive.",
      "title": "TurboRetry: Mitigating Large-Scale QUIC Handshake Floods with Off-the-Shelf DPU Offloading",
      "url": "https://arxiv.org/abs/2608.02264"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-07-31",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "weddings.lavenderhotels.co.uk",
      "source_type": "Public reporting",
      "summary": "Inside the Dangerous AI Security Myth Companies Keep Buying weddings.lavenderhotels.co.uk",
      "title": "Inside the Dangerous AI Security Myth Companies Keep Buying - weddings.lavenderhotels.co.uk",
      "url": "https://news.google.com/rss/articles/CBMimAFBVV95cUxQWm5fNFMzSEdudjc1REZOMmh3ZXpGZTlvczBiYk40NGdQRC1RYmd2QlBlSjdIeExNdXUxcHNVVnlXVkhub0FmdngyMlJpUUduRGN0dVpWeFlXemU3MHc0cXlLeG9pVk02Xy1iVWVLRGhvZmpCNHhpTHVQLUNsbXdoYk9iazNUQlJINkx1cWh1cVExdkp0bnJkNQ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-07-21",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "OpenAI",
      "source_type": "Public reporting",
      "summary": "OpenAI and Hugging Face partner to address security incident during model evaluation OpenAI",
      "title": "OpenAI and Hugging Face partner to address security incident during model evaluation - OpenAI",
      "url": "https://news.google.com/rss/articles/CBMifkFVX3lxTE5QM0NxYjlpZlBQVHNUaVZta3E1aGJ5LTZHcTg5bEU5T3JCbVdIc19BUk5pcFBlR0RNaDhoYVhGRm95TjVTMVZMLU9XOE1MeEhNQS02VGI3TDh6bWktZ2VoYU82eWFVcVJTM0NKbkUtWU83a2IzNUdvZFVCeDVzdw?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-05-03",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Augment Code",
      "source_type": "Public reporting",
      "summary": "What Is an Agent Execution Sandbox? Augment Code",
      "title": "What Is an Agent Execution Sandbox? - Augment Code",
      "url": "https://news.google.com/rss/articles/CBMiakFVX3lxTE92MHRQOUd6ZlZIZjFPaFdLVkotYTZNbHJSRzR3QlJkb2J5N0wwWnJnNWh1YWhUcURNcHNSbjIwVTNwTXBBMVhTUGt4MmlDakZTQm9hUm1kOG40U3I5SURTdG9sNUdSemFBQ3c?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-02-19",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "PR Newswire",
      "source_type": "Public reporting",
      "summary": "Netzilo AI Edge Delivers Enterprise-Grade Visibility, Sandboxing, and Governance for OpenClaw Agents PR Newswire",
      "title": "Netzilo AI Edge Delivers Enterprise-Grade Visibility, Sandboxing, and Governance for OpenClaw Agents - PR Newswire",
      "url": "https://news.google.com/rss/articles/CBMi6gFBVV95cUxOWHVkakcxeHNfS3Z3VlB3MmZBQXBvZ2JsTS1obGoyTUFOMk53UVVGMEd2WkpWUDhtSUg2ZXpxV0JIZGZieVVWbHZQRXhxakxuWUdYOUg5QVpnam1zQzlZNmNaQzNFY2hlTUcwOHB1V2xGNDd0TlY3Tk9TSHlabTdjMXIwUlFMeXdKaUcteWZqRzh5ZGVUTGlFbnFtVzIxUTUtTnR5eGFLTGJTUllYU1NXSU4zSkJqOU10UF8ycHV2ZExhdlFGdFNCWWJDRElrSkk5OXhOUkpkc0pJOUU2U0NqVm1DUnVrUzY5dnc?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-06-23",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "The Association for the Advancement of Artificial Intelligence",
      "source_type": "Public reporting",
      "summary": "In-Context Autonomous Network Incident Response: An End-to-End Large Language Model Agent Approach The Association for the Advancement of Artificial Intelligence",
      "title": "In-Context Autonomous Network Incident Response: An End-to-End Large Language Model Agent Approach - The Association for the Advancement of Artificial.",
      "url": "https://news.google.com/rss/articles/CBMiaEFVX3lxTE9uYzdFMl9xeVNjdDRudVkweXhwNENTM0pZMlZmYmlPUFpVdF9xV21nZFZTVzdrOWVpbGFqRDVaTDVFcGl2dzdkbnk1a2hsdXBBYy0xZHo2S0xwMVhRclJIZ0dSVm9Sc2Fp?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-06-09",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "SiliconANGLE",
      "source_type": "Public reporting",
      "summary": "DTEX adds AI Risk Management to track how agents and employees use AI SiliconANGLE",
      "title": "DTEX adds AI Risk Management to track how agents and employees use AI - SiliconANGLE",
      "url": "https://news.google.com/rss/articles/CBMimwFBVV95cUxQR0U3aDhqMmNBTDd1cklsVm0yc29YZ3ZVLTJQdXlJNG5nRDNoclhSRmo4UEJCQTZIU21HR0d4SC1Ga29ZU2lJV2c2TkFHUTZhSTFDcENTa3hnX3h4WHpncWR1eFo2M3JpVFU2cTFtLVpMR01lMms2UVNmOUdNNWZEaWR2Y3RtZFNhbzM4U25vNkgtd2IzM3NBcWp6dw?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-02-27",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Medium",
      "source_type": "Public reporting",
      "summary": "\u201cTell Claude It\u2019s a Bug Bounty\u201d: A Case in AI\u2011Enabled Intrusion with LLM as Attack Multiplier Medium",
      "title": "\u201cTell Claude It\u2019s a Bug Bounty\u201d: A Case in AI\u2011Enabled Intrusion with LLM as Attack Multiplier - Medium",
      "url": "https://news.google.com/rss/articles/CBMizwFBVV95cUxNeGFxZ2VsVmFSbUlkejZkcU1OVVNGYU1iZGxHVUhoRG90MWZfczBhVE1hZXZ5bDFJODBFVm5WRUI1SGVFdEpkN3VhQ2puSkhJUTJPNk5HUE9XbnhBcVlVT0RURXZTTVhqaW00Wms0bXVMdU95OXN3Und0WlhZWVpIb0M5aHplQ3JLVGQ0UUFmUExaT25iWUJFaWVGWlA2ZDNZS0VhZ2tiTnVDalEwYzI0a2hPbnppX2dISnFHcms0RXluampkUldoSE9uS21wcUE?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-01-28",
      "detection_surface": "Prompt-hash transition, tool call sequence, and session trace",
      "failure_pattern": "Prompt injection / instruction override",
      "recommendation": "Require approval before sensitive tool use and restrict untrusted input from tool instructions.",
      "relevant_awr": [
        "AWR-111",
        "AWR-001"
      ],
      "severity": "High",
      "source": "Snyk",
      "source_type": "Public reporting",
      "summary": "Your Clawdbot (OpenClaw) AI Assistant Has Shell Access and One Prompt Injection Away from Disaster Snyk",
      "title": "Your Clawdbot (OpenClaw) AI Assistant Has Shell Access and One Prompt Injection Away from Disaster - Snyk",
      "url": "https://news.google.com/rss/articles/CBMiW0FVX3lxTE1RLXlhNmVOSU1JdGZKb3JpU2xPUnJiTzBuajRDRDhqQ09wRk9hcF9HRW9CM1lqSGFKWFhSRl9zMVRUaGxDRS1oOTRfTnJUekp3MElmRGRKSXQ4M00?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2025-10-08",
      "detection_surface": "Prompt-hash transition, tool call sequence, and session trace",
      "failure_pattern": "Prompt injection / instruction override",
      "recommendation": "Require approval before sensitive tool use and restrict untrusted input from tool instructions.",
      "relevant_awr": [
        "AWR-111",
        "AWR-001"
      ],
      "severity": "High",
      "source": "Axios",
      "source_type": "Public reporting",
      "summary": "Invisible commands, real threats: The rise of prompt injection in AI Axios",
      "title": "Invisible commands, real threats: The rise of prompt injection in AI - Axios",
      "url": "https://news.google.com/rss/articles/CBMinwFBVV95cUxOMlFjVXJnWWxHbmM0Y2RQb2UyVzM5a1FVNW9Tbk9mTDBJZ3RjSDRWZVpocHJ6XzBtdG5UV3VqWFRNQ0FHYkNaT1BmTmw2Wl9WQnRMTHMtWmpkOTFGUEFKYmM5Ri1abnJKc255VEd4a3NadDlsZkZneU56aHhmQTZjWFZLZ0dfRDkxdFZ2UzROZm9WTlI1ZmdUNXlSRFoyak0?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.13659v1 Announce Type: new Abstract: As AI-generated sexual content (AIG-SC) is increasingly produced, online communities have emerged to support creators' needs. To understand whether and how community governance attempts work to prevent abuse while supporting free.",
      "title": "\"I Thought You Were The Uncensored Place\": Norms, Rules, and Moderation in AI-Generated Sexual Content Communities",
      "url": "https://arxiv.org/abs/2608.13659"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.13784v1 Announce Type: new Abstract: Independent implementations of a cryptographic standard should reproduce the same known-answer results, yet agreement is meaningful only when the corpus, revisions, public interfaces, exclusions, and evidence are precisely stated..",
      "title": "A Reproducibility Protocol for Cross-Implementation Evaluation of Post-Quantum ACVP Test Vectors",
      "url": "https://arxiv.org/abs/2608.13784"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.13815v1 Announce Type: new Abstract: We present TLF (Transceiver Lifter Framework), a tool for recovering RF transceiver configuration and runtime behavior from bus-level traces captured between a microcontroller and its transceiver IC. A stateful protocol decoder,.",
      "title": "TLF: Rapid Characterization of RF Transceiver Parameters in Embedded Systems via Bus-Level Interception",
      "url": "https://arxiv.org/abs/2608.13815"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.13920v1 Announce Type: new Abstract: Hardware attacks like Spectre exploit built-in processor vulnerabilities, leaving anomalous footprints in Hardware Performance Counter (HPC) metrics. While machine learning can detect these footprints in controlled settings,.",
      "title": "Characterizing the Variance Envelope: A Multi-Dimensional Analysis of Spectre Telemetry Across Architectures and Workloads",
      "url": "https://arxiv.org/abs/2608.13920"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.13928v1 Announce Type: new Abstract: Accurate vulnerability severity assessment is essential for prioritizing remediation, yet manually assessing Common Vulnerability Scoring System (CVSS) base metrics remains labor-intensive. Existing automated approaches often fail.",
      "title": "CoSA: Context-Aware Severity Assessment via Context Analysis with Large Language Models",
      "url": "https://arxiv.org/abs/2608.13928"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.13930v1 Announce Type: new Abstract: Existing labeled Bitcoin datasets are largely derived from community-reported abuse, blockchain heuristics, incident-specific collections, or proprietary labeling processes. Their construction methods are rarely publicly.",
      "title": "Extracting and Verifying Illicit Bitcoin Addresses from Underground Forum Discussions",
      "url": "https://arxiv.org/abs/2608.13930"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.13948v1 Announce Type: new Abstract: SQIsign is the sole isogeny-based digital signature scheme submitted to the NIST Post-Quantum Cryptography standardization process, distinguished by its foundation on the hardness of the endomorphism ring problem for supersingular.",
      "title": "Vectorized SQIsign Implementation Using AVX-512",
      "url": "https://arxiv.org/abs/2608.13948"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-08-17",
      "detection_surface": "Egress destination, payload metadata hash, and session-level intent drift",
      "failure_pattern": "Data exposure / exfiltration risk",
      "recommendation": "Restrict egress, monitor destination drift, and keep sensitive outputs behind review gates.",
      "relevant_awr": [
        "AWR-111",
        "AWR-006"
      ],
      "severity": "High",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.13981v1 Announce Type: new Abstract: Graph encryption schemes (GES) enable secure outsourcing of graph data while supporting efficient queries. This report provides a comprehensive analysis of structural leakage in GES for single-pair shortest path (SPSP) queries,.",
      "title": "Structural Leakage in Graph Encryption: Attacks and Defenses",
      "url": "https://arxiv.org/abs/2608.13981"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.14094v1 Announce Type: new Abstract: Cloud-local LLM inference systems have the potential to use the reasoning capability of large cloud models while protecting sensitive user data on personal devices. Cloud-bound requests must exclude personally identifiable.",
      "title": "P2Skill: Privacy Preserving Skill Distillation for Cloud-Local LLM Inference Systems",
      "url": "https://arxiv.org/abs/2608.14094"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.14126v1 Announce Type: new Abstract: To mitigate attention dilution in high-entropy TLS 1.3 flows, we propose BGA, a noise-immune neural distillation framework for encrypted threat intelligence.The methodology first employs Analysis of Variance (ANOVA) to decouple.",
      "title": "BGA: A noise-immune neural distillation framework for malicious signature extraction in high-entropy encrypted flows",
      "url": "https://arxiv.org/abs/2608.14126"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.14329v1 Announce Type: new Abstract: Principle-based regulation, with evaluative standards such as \"fair, clear, and not misleading\" or \"deliver good outcomes\", cannot be reduced to binary predicates, and LLM-as-judge is increasingly used as the substitute. Our.",
      "title": "A Four-Axis Trustworthiness Benchmark for LLM-as-Judge in Principle-Based Regulation",
      "url": "https://arxiv.org/abs/2608.14329"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.14418v1 Announce Type: new Abstract: Strategic Cyber Threat Intelligence (CTI) focuses on high-level insights, such as identifying targeted industries, attributing attacks to specific ransomware groups, and assessing the scale of data loss. Today, X (formerly.",
      "title": "STINER: Automated Extraction of Strategic Cyber Threat Intelligence from X",
      "url": "https://arxiv.org/abs/2608.14418"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-08-17",
      "detection_surface": "MCP graph edges, privilege expansion, and scope explosion",
      "failure_pattern": "Connector or tool-surface expansion",
      "recommendation": "Pre-register tools, review requested scopes, and alert on unexpected graph expansion.",
      "relevant_awr": [
        "AWR-112",
        "AWR-113"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.14501v1 Announce Type: new Abstract: In their seminal work, Goldreich, Goldwasser, and Micali [CRYPTO 1984] constructed a pseudorandom function (PRF) using a black-box access to a pseudorandom generator (PRG). When combined with Levin's domain extension technique,.",
      "title": "Lower Bounds on Black-Box Constructions of Pseudorandom Functions",
      "url": "https://arxiv.org/abs/2608.14501"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2603.24868v2 Announce Type: cross Abstract: We introduce Quantum Spectral Authentication (QSA), a symmetric-key entity-authentication and key-derivation protocol in which a remote endpoint proves it still holds a hidden planted state, an eigenstate of the challenge it can.",
      "title": "Quantum Spectral Authentication: Entity Authentication and Key Derivation from a Hidden Eigenstate of a Public Unitary Challenge",
      "url": "https://arxiv.org/abs/2603.24868"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-08-17",
      "detection_surface": "Egress destination, payload metadata hash, and session-level intent drift",
      "failure_pattern": "Data exposure / exfiltration risk",
      "recommendation": "Restrict egress, monitor destination drift, and keep sensitive outputs behind review gates.",
      "relevant_awr": [
        "AWR-111",
        "AWR-006"
      ],
      "severity": "High",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.13597v1 Announce Type: cross Abstract: Coverless image steganography (CIS) synthesizes a stego image rather than modifying an existing cover image, enabling authorized recipients to reconstruct the original secret image from the stego. Existing diffusion-based CIS.",
      "title": "Secret-Stego Dissimilarity as a Design Axis: Invertible Coverless Image Steganography with Diffusion Models",
      "url": "https://arxiv.org/abs/2608.13597"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.14149v1 Announce Type: cross Abstract: Recent training-free post-training quantization methods restore model accuracy through closed-form residual compensation. To constrain additional model storage overhead, several existing methods gate layer selection by.",
      "title": "QuaSAR: Quantization Compensation via Stable Activation-Aware Rank Truncation",
      "url": "https://arxiv.org/abs/2608.14149"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.14331v1 Announce Type: cross Abstract: The relationship between cryptography and learning theory has long been a central theme in the foundations of theoretical computer science: cryptographic primitives can imply hardness of learning, while hardness of learning can.",
      "title": "Equivalence Between Average-Case Hardness of Learning and Cryptography for Mixed Quantum States",
      "url": "https://arxiv.org/abs/2608.14331"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.14356v1 Announce Type: cross Abstract: The growing use of crypto-assets has generated disputes that sit uneasily within existing legal redress mechanisms. Their resolution is complicated by the technical features of blockchain transactions, the cross-border nature of.",
      "title": "Designing Inclusive Crypto-Asset Dispute Resolution A Hybrid AI and Smart Contract Online Dispute Resolution Framework for Vulnerable Users",
      "url": "https://arxiv.org/abs/2608.14356"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2511.19009v2 Announce Type: replace Abstract: Large language models (LLMs) demonstrate powerful capabilities across various natural language processing tasks,yet their inherent safety vulnerabilities undermine the reliable application of LLMs in real-world scenarios. To.",
      "title": "Understanding and Mitigating Over-refusal for Large Language Models via Representation Intervention",
      "url": "https://arxiv.org/abs/2511.19009"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2601.11629v2 Announce Type: replace Abstract: We demonstrate that while the current approaches for language model watermarking are effective for open-ended generation, they are inadequate at watermarking LM outputs for constrained generation tasks with low-entropy output.",
      "title": "Semantic Differentiation for Tackling Challenges in Watermarking Low-Entropy Constrained Generation Outputs",
      "url": "https://arxiv.org/abs/2601.11629"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2607.07075v2 Announce Type: replace Abstract: Entropy-based methods have long been used for network anomaly detection, but most existing approaches treat entropy as a scalar statistic on narrow observables rather than as part of a broader behavioral state-space for cyber.",
      "title": "Cyber Dynamics I: Finite Macrostates for Behavioral Anomaly Detection in Network Telemetry",
      "url": "https://arxiv.org/abs/2607.07075"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2608.09075v2 Announce Type: replace Abstract: Modern heterogeneous System-on-Chip designs integrate CPU cores and a GPU that share a last-level cache (LLC) or system-level cache (SLC). This sharing exposes a new cross-domain attack surface, and existing attacks on.",
      "title": "SLAC: Access-Driven CPU-to-GPU Side-channel Attacks via System-Level Cache on Apple Silicon",
      "url": "https://arxiv.org/abs/2608.09075"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2603.11799v2 Announce Type: replace-cross Abstract: Membership inference attacks (MIAs) are becoming standard tools for auditing the privacy of machine learning models. The leading attacks -- LiRA (Carlini et al., 2022) and RMIA (Zarifzadeh et al., 2024) -- appear to use.",
      "title": "Exponential-Family Membership Inference: From LiRA and RMIA to BaVarIA",
      "url": "https://arxiv.org/abs/2603.11799"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2606.17035v2 Announce Type: replace-cross Abstract: Prior research suggests that differential privacy (DP) inherently enhances the robustness of federated learning (FL) against backdoor attacks. In this paper, we challenge this assumption. Through an empirical analysis of.",
      "title": "Your Privacy My Cloak: Backdoor Attacks on Differentially Private Federated Learning",
      "url": "https://arxiv.org/abs/2606.17035"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-08-17",
      "detection_surface": "ABOM, model hash, dependency signal, and integrity receipt",
      "failure_pattern": "Supply-chain or model-integrity risk",
      "recommendation": "Validate dependencies, track model identity, and require signed manifests for runtime changes.",
      "relevant_awr": [
        "AWR-113",
        "AWR-115"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2607.22140v2 Announce Type: replace-cross Abstract: Software Bills of Materials (SBOMs) are consumed not only as component inventories but as dependency graphs: vulnerability triage, reachability filtering, and impact analysis all traverse the edges an SBOM declares. We.",
      "title": "No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild",
      "url": "https://arxiv.org/abs/2607.22140"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "arxiv.org",
      "source_type": "Research",
      "summary": "arXiv:2607.23952v2 Announce Type: replace-cross Abstract: We study the impact that two miners equipped with quantum computers purpose-built for quantum Bitcoin mining will have on the 51% attack threshold of the Bitcoin network, given that the miners are playing a competitive.",
      "title": "Strategies for quantum-enabled Bitcoin miners",
      "url": "https://arxiv.org/abs/2607.23952"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-08-06",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Tech Times",
      "source_type": "Public reporting",
      "summary": "OWASP LLM Top 10 2026 Incident Data Overrules Experts on Misinformation Risk Tech Times",
      "title": "OWASP LLM Top 10 2026 Incident Data Overrules Experts on Misinformation Risk - Tech Times",
      "url": "https://news.google.com/rss/articles/CBMixwFBVV95cUxPWWtyRVFJT3ZUTkxLdjRmeDNyWVpxdjQ0dDNUUEVvSWpjMTF1d2tNMXdLc2w3ZG9mUXlncVVOT2pXX3gwMnNfU25kdFI2aEZ3SDViSnlGcXNBc0dwdUwtNl9ZYVdHaFNEQzJhS3MtQjYxVHB1dGh5MDZSUlRTdWRsTnppQ3ZNWW0zWG14LVpzczhCSkJjcjZoUXRNcDZxR3ZzWWVvZmRVaVlGRWktQmpucTJSRHVpU2Z4c0VENnRpSW9ER0FJZ0FJ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-07-27",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Tech Times",
      "source_type": "Public reporting",
      "summary": "AI Safety Evaluations Are Not Safety Certificates: Formal Analysis Today Tech Times",
      "title": "AI Safety Evaluations Are Not Safety Certificates: Formal Analysis Today - Tech Times",
      "url": "https://news.google.com/rss/articles/CBMixAFBVV95cUxPeERQS0ZSYnFobFJJYVV6d1dhR1VlR3dSSEoyVEIwRWdKSXQ3dHgtelN1SWJVMHpLalNZLWxMVnBySDAwQTVmZGxzVU0zNkJNUGZkbGpXbHp6aXcxMUpTYUdNcDZFZzNIeDRTT0pZbWZrUXJWVGF4NVo0cl9tME81QVd6S2hhZmNCY1NHNloxYW1GTmZsaTV5MkMwcHFzelExX2trNWw0MGZBb3ZWbXA2NWlDa2ZBX3JjaXEwaFd4SUJHYUxE?oc=5"
    },
    {
      "also_reported_by": [
        {
          "source": "Yahoo Tech",
          "url": "https://news.google.com/rss/articles/CBMi3AFBVV95cUxOV1V0Um8xVmhlVmpFN3RHN25xbHZOUFFQcm4wN2YzYlA4SHVyT3FJWmQ4YjJOMmdHVFZYVU5HQ2l6NDRBY2JzQVluNFZYbEZkdEV2Y2tuZ3dIc2ZEd1NTQk5DV3A4dnMzX3hWc2xsUmZRcjVwZjNwcTJ3WnVlcUdQQ1I3VVVqZFRGQ3F4bGZYVFoya0g3dmZlcWpfT2lia0dUdFFiN2lITkRHek1UazRVS0JpSlVNRTdXSXNiUEFlclV2NHhyY2JackFmcFprZ2pZTGxfc2NWSzhfVW51?oc=5"
        },
        {
          "source": "Hindustan Times",
          "url": "https://news.google.com/rss/articles/CBMi9AFBVV95cUxNM2J1SHlmOUZTVWx1QlVPbWJuVXA3Ym40aHVyWGE1cXg0SU9HM09XTUs2OWdlcV9JOHE1Vmd2WjlUSEZYZDNtOTNNdExtUkZhZWFQZEo1RV9Hckppb1BPY3ZiSkdweVBfLS1MWnpMeDVmdnVMaEgtV0FkbXJ3T3NwRi0zMTdsOUx1UzZTWkR0WE9QQThVZGFTZVpzb3d4N2FwbWU4S25RVlZKcWlOV2U0cnJuV05PVHlSbEc1Yzd2TVV0ZWN5dnZNWEdkb0g0U0hfaFFpSDB2QnRscXNaSVBIU2t3UUItUW84Z0I4NnlQbEMybnNT0gH6AUFVX3lxTFBXaWFGM0UzamphNElZWGVYWElUT3RQLUo5WWNWazJfVW5Lak5lazN3dDZfeEd2YVhCSHVPQVJuVktsM1Y1Z1NNRU83cDdqbmRlUS1OZXFWRUJhOFQxUHNJTThtdVZlSFdVNllSUjNIY3NCTUtMVnphblBpbzJHYk9DbVNEWGJqYzBGTVZRVnFyOTFpVWZTajR1WW4tVnp1dkpucjd4aklDQkF5Z2lHSjYtREZKbTRYLWxMNWdXYkd4cFZIX3ZuTDN6WmtVdW1ySDNoQkl1OExQTElPQ0t3LWdETDJqOVdRT0NGSEdGb0hGcWZQN201Qy1XU2c?oc=5"
        },
        {
          "source": "Vorys",
          "url": "https://news.google.com/rss/articles/CBMiY0FVX3lxTE1jME9OM3lBdUxHLUxVNEhnQ2pvNThDNDJ3R3BvSURHMjF3bXhVbWZBZXBpdHlERTZ1bjl4cVdQN0Zsb1B5WS0zQ0h1a3Y4cG1BdTQ0ZDVJWTRNUjdPWDJlYnp2bw?oc=5"
        },
        {
          "source": "Chosunbiz",
          "url": "https://news.google.com/rss/articles/CBMiekFVX3lxTE9PaTg2UGVnX09EVnJFVjJBUGFNRXRDU095eXlNX0FHTDZXaWJWLWNxQVhfcFpxT3Z5ZHpzR2EySU8wNVpoRHhCZDJ6MGpkUDUwVlJ5SGNvbHpMRGJOM1dqNXA5S0pyTGJaY01ZZFpZbDFicG9KbXRXaWxB0gGOAUFVX3lxTE1ONUxnaHMyUDE1SldLc0hmZHhOZ24zX2s5M2NoWmg0WkJpLVFWZVFlcHdoeW5fLTFTbno4LTlDX2NPVi1GalF2b3A5a19WeEpCWGN0SlVGbW9QZEhWSTNrakd6THQ5eldCM0ZUMXBXRWtMTjNsSG5MemZJSUxlUWVWNm8tNjNIUXJGUEhpNGc?oc=5"
        },
        {
          "source": "Yellow.com",
          "url": "https://news.google.com/rss/articles/CBMifEFVX3lxTE9fZktjc1BUQTM5TG1Ea1pLejBlNkZKSzRVSzlxQkNkS1VGcDR3bGYxdkNJWnZnWWcxaTRNeVFsLTl2Y1E3elhjZ3BnaU9pVHBGRW9TZjlwN0t2VEdCTUNFUEhXVjF1MFBtUlJwTU1qMk1QLUtOMHc3YkhqWjY?oc=5"
        },
        {
          "source": "CBC",
          "url": "https://news.google.com/rss/articles/CBMifEFVX3lxTFBZVmZrbmZEckpMNHB1bS1PQlV5dWVxMHlYcVdLUGdFUFgtcFRfT2FYVnZWSmFCZlpDVHd4TzV6MURmMDdfUEdrU0hFZERjQi1VM1VrOEZ0UEpsN1lLdWFiMURQT3g4VHNVZjJEckd1bi1BT2V2VFhPNnpJZVI?oc=5"
        },
        {
          "source": "The New York Times",
          "url": "https://news.google.com/rss/articles/CBMigwFBVV95cUxNRFFIX1hiUENTX3h0a3o0Vk5pYk9SU0VwWXNFQThrWS1paUE5RGpoUVdDRjV6QlBzOE1COU0zbW5qaVNfQnhzNXRJZzZCdDhiRkhZYzJhOGc2TXd3ZWhBeGlKTjN1VGRBaXVaMUUzbzBXWlNBczRiTUJlWlk5UnZSTXNZVQ?oc=5"
        },
        {
          "source": "AOL.co.uk",
          "url": "https://news.google.com/rss/articles/CBMiigFBVV95cUxPdUtpeGtwTjNXdndhYW5QcjdOTVctc0wyREZmZzZOOE1Bd1pWN0x1UjBuS3piMjRJck5ld1Utc1JIbFJfT1JjWXJFS3dIbHhlN29SZnEtV2tMNElLZUhKdzFSaVhQMGw2U2V6OF9JZzNQMWVMRF96VVRoM3RJbkxpVEpBT0swLWdVN0E?oc=5"
        },
        {
          "source": "Yellow.com",
          "url": "https://news.google.com/rss/articles/CBMiiwFBVV95cUxQMTJubi1jNzRHSGVjRHRyVUpFVnRoXy1lamltMGl6U2FXOHVRb2xpSlhROV9COEp5eHNkVWZ0YWY4NnVtbDFWa1FkTUhTa1RPYTNPWTBBZjM2OUk2Q0NwZURSSEZxdkd4T1NpRmtMcEltTzVJYWVVQ0ROSVozakhQYnJNYUF1Vl91Qy1r?oc=5"
        },
        {
          "source": "Fortune",
          "url": "https://news.google.com/rss/articles/CBMikwFBVV95cUxONTZ5aUtUdEc3d29jZUhnb3dUMXFiRFV3M2FJMzlGWkZGdkhMWE93N0NIcmJQX3ZkcExKeFBfalc3NHRvOTRRdjZvUHVKSEU1ZDYyYUZjSzZiTmVBc2M4bVZ3R05GUW4zUmFWMzM4b3hndHNVRFBBY1BkMEFkelYta3RudWpQU05heVNQZGVYb0V6T1k?oc=5"
        },
        {
          "source": "Politico",
          "url": "https://news.google.com/rss/articles/CBMikwFBVV95cUxOaElSVC1WQ2JsMi1JTEZTNGg1dGZ4cDhMZldRajFrTzN5SW5QRXZyNTdCZkxxZklxUXJBOXNOblZQbmZXMkJvZ0VNaE5SR255T0FzbTdBbFNiWjZWMm51cUJPbERTenhWYXNqOVhUYmRidnJaVzZYUmxCeGZ6cVdwUTBCQnhja0JqU2tWbkVCLUx1dnM?oc=5"
        },
        {
          "source": "it-online.co.za",
          "url": "https://news.google.com/rss/articles/CBMilgFBVV95cUxNUk5ITk5KYTRTLXBhNWRDZEs0b25tWHNOTTlQenhYUGg2cWE3UXViMG5tdDhZZDEtaVpZb1J1ZkdSaTJUeGZQU3Z1Z05iWWpLMC1pZUdMMDVkSDRUTzl4c1g0UVZHSEVwM2VUNXd5MWh3U2h2R3Fva0JRZzZTV0xUTmhHdXJtTjRSVXROUGEybWRtQzY5Znc?oc=5"
        },
        {
          "source": "Daily Mail",
          "url": "https://news.google.com/rss/articles/CBMinwFBVV95cUxPM01lWWFpSnFyUmFrQ0VaNXUxZnZ1N2J4Rlh3N1U4cWZvMHNyZzRWSlZwWDlRRzRKNTFxUGZLbE1uLXhjdTFpR0JUMlR5UlJJa0JWdmIxY1FOZVpadEpPUUg4YV9Fa1B4WjJrSjcxQkVQZjltMy1UTm1aZGQtQjZ3Z2tKVE80bEJOT21xeUFfdlo2VGtGWUNkeDc4bEVzRkXSAaQBQVVfeXFMTnN6dlFJSEllZnVCWlFuRmd3SnN4QlFueEJHWC1EbTZTelZYNGxXWE94ZkRTVlBrMTRoa2RhaVpISkhBN19XVjFUOUVUaHB5YkhOalBBUVVzdmVFOGdaSEhoR244VThrNnRocWpGYjA0aHVqOGR1OWFYbG1pVi10Vm1yOHgwWVBUUGd2aEItOXFzZWI3ZHFyZHVDeXRTUTduS2E2MTk?oc=5"
        },
        {
          "source": "arise.tv",
          "url": "https://news.google.com/rss/articles/CBMiogFBVV95cUxPUU92WWUyaFozRGJ6S1htTzZ3QUZJUTlUcHpVZE1yd1JYN1FKZ0E5Mk80S3B2eFRnSGQ3VC1kN0dkT1RZSHBJZjNRVWpQdkhkMjMxblc2c3JKSzdfUTV3bmM0RkNLZC1YWHF1NHhhLVl6T3c3T2tBQnJBa0xIWUM5czM0UVdpMWZaZGE0a0I2MHhYaTZWd05xMUo1dC16VU5pN2c?oc=5"
        },
        {
          "source": "Ars Technica",
          "url": "https://news.google.com/rss/articles/CBMiowFBVV95cUxOT28zdWJkS0hQT254NEdPWG5rQWVDdExGMG13SnNUdDAyWWFhdlRGYlBiTGlBYmhJb29LbDJDUUlqWEpIZVRDekxPQVZDWmRVd1cwNWJKWmFYclplSVk3cm5FYlJwNTRrR1A5WHpLOE5ubjdqZFA2ZmExWm9YS284Zzl1ZGllYnBON2pvWlJqVmdHLWY5RnhtMk9wTUNvTURJdElZ?oc=5"
        },
        {
          "source": "Tempo.co English",
          "url": "https://news.google.com/rss/articles/CBMipgFBVV95cUxNdW9NUXd0RkRkUHFta3VseTdQMHR1VjY3MzlnbWlEYUtIOHRWM2V5M0t4VVdTc1lmTldWZ0JSMEE3alhwbUJkaW9uVk5SU0o2UVNROUZDYUFwdU8xZjZWcm45c3cxUnVBNVRyOTBCNlFFbzBtd2FNWkw5eF83dElhb3cxUVJCUWFNR1FfQmlFTzBkRGlDMXNZSlRFNEpuVmtsSFB3QldB?oc=5"
        },
        {
          "source": "CNBC",
          "url": "https://news.google.com/rss/articles/CBMipgFBVV95cUxQMU95TFhjeUdscnZoOElsdnRhRmV5eTNEZ0dpa3VRTmFCdEVmSTRNOGIyWjJOcTl1aFo3OENPNC1DTFJoWGk5YTJjSVhEQjd1ZzhFQVFteEI1R3dwb0ctbkNuREx2MkpMbHVMVnBfczV5eG1NQlZ2anZ6MXlDdnplS2ljSWVoVlBQaWhZS0JfdUQxNGZEY3VqLUZBTWY5MENKRUpKTnpn0gGrAUFVX3lxTE1uTHVPT3VwRk16aWFGZFFmdEI2akJOaXhmVmpjNkhzVDRkdUpoRDcyZS1HQ2NzZzAyRTJzcjJGTDIyNG5CYTMxY2NxNC1NS2hZQ2VRdUNZUVgweWNPZnBoQjJpd3BudHN5WFJFU2RrcU1EbU5OMEprNGlHQVJzRk1UbndLeUNOSjd0S0FiNjhUbjBkVXdaN2lkdlBTRWt1MjZ3WVh1SmtyNVdXcw?oc=5"
        },
        {
          "source": "Cybersecurity Insiders",
          "url": "https://news.google.com/rss/articles/CBMiqwFBVV95cUxPWlNOWi05UllpcC11djJZZFBzcjh6TnF5RDQzaVdSY0FiclplYTlQQldwTy1xaE5TSUdYbFgtaEJ6QzJFS2ptOXlkTHZsY3hkMzBxd2s3djdIQzFuUnJtdU0tRDJralZDaUVaX0RacUNhTmIyak51Snp2MUdpY0pwRVhWNXhTelk4UnlLQmRQSEZQcHFYLXlsNG1HaEJ1YWdWaEk5YnRIWTBXYnM?oc=5"
        },
        {
          "source": "Anadolu Ajans\u0131",
          "url": "https://news.google.com/rss/articles/CBMirAFBVV95cUxNdU5BSE5Hb1BVc3Z5ODNmRlRRc0lXTHZXejA1WDdpTEhBQkNNMmRNUUthekh0TFdIVEk5d1JwWEgtekhSc01Wd21jclcyWnVYdHA0Y19lN0VOTWpHZm1PN1JpV1JBenFNUFBCMWxkcTY2LW4xbmdXbUtlWDhTRmhfRTQ2ZUdCUDAwSHdONFZxcS03MDk5MkMzQVRqMUI1RF9VelBKaFBlc2xuWTZ1?oc=5"
        },
        {
          "source": "streamlinefeed.co.ke",
          "url": "https://news.google.com/rss/articles/CBMisAFBVV95cUxPbWNqYW9vWmoteWJIRzZ0XzlpVjJaTTNMRnBDRXB4ZGxhdDNxVDZPSnR0WkhOUGFCR1ZhYmtVeDRDa1piS1NmYnRHdS0zbkszR1dmd3d3bDd4X0gxOWI4eTJ1R0lPRS12QjdOWHZ5Q0R2dWl0Um83alMxVjZuSGVjLWdXVlRWNk1CSU5zbkpYcm1rTnNQdUhNMVdsVkdkb3k5RGF1cUg4N2hXRy1kRHpIUg?oc=5"
        },
        {
          "source": "oodaloop.com",
          "url": "https://news.google.com/rss/articles/CBMisAFBVV95cUxQb0xZM281QXJ2UjBsLUtteHZ1ZEg4STVKYjA2WXJqS0R1Njc4R2lxSHFZb3ZxTFVqVDVsaWZJNVY1WW1uQzl6Z2dBNDZnVDFKM0JMcWJyRERzdERhUVduT1lGVVNNRkJQc3FxZXhITWNtZnZwSTJOY3A2dDNsMUMwSUtOVkV3ZjQ3Z0Z5UmpqQ0xNclp5Y0x1X2JyNDZmbEg3RDJjU0V2YlVIQUNuOGVjbA?oc=5"
        },
        {
          "source": "AFR",
          "url": "https://news.google.com/rss/articles/CBMitwFBVV95cUxOMEdqUmdHQ3Jyc2xnMHZxZG1NOGlQaEp1Ry1rTlRNdllGZmlDYkM1dVp0aXowT1ZYNVhaWno1N24tWVJxbWVBZmZ1V1hvNHp2WlNPU0kyZ1N1TUcwNEdaMWIwd0p3MWpQQlJGWTNrdk03aWs2TEJpamJJVzZXZllrY1lsRnZGYzdfOENuRDBWVDVfM3l5MWVwY0lhLVVjTHphaFhkdkhYbVF6a2NyWW5xdzhTUXpkaHM?oc=5"
        },
        {
          "source": "Invezz",
          "url": "https://news.google.com/rss/articles/CBMiugFBVV95cUxOcVk4RV82bVlic1BsV0FWcDZWT2Jxbk5FakUzZ2hJNWdTVW5ybFlyTXNicThZZGNnU0duSnZ1NmQ0RC1VVVZsSnF5M2xVZFNtTjdNTXdXRmd2V3lkUU12QVlPd0VkZ01veGo0RzdOa3lXWm11REZFTWtWZHA3d0d0TkhzNUl1dXBncXZHOEh0OEVsWGlyeFJud2p1UmVFWUdOelB0VjVTdjkyb2ZBN19ZaWFZQjlGNUhyWlE?oc=5"
        },
        {
          "source": "Reuters",
          "url": "https://news.google.com/rss/articles/CBMiuwFBVV95cUxOc1VqeGo0bjJGSmZQNEpqOWkyMjdCd0F0ZDlnZFZab2xwX2hwM1lCc3RoLWpTRF96ZlI3SHNnMVNoTWFzY05Sb2FrbG9hQmNhNlJCUS10VjJHYUtUSkt6NHJ3d0hSNGREMlVPUUR5WkUyRjRFU014eU5uM1dpbHgwUFZTUTFwV2Z1dFl4SzItQUFxWkRJdHN3TWRxNTRuUGhtb1liMXFvbFotdDRJTHU3T2hhTHlvQjBNcTE0?oc=5"
        },
        {
          "source": "breitbart.com",
          "url": "https://news.google.com/rss/articles/CBMivgFBVV95cUxQQkNNVVRsdjAzWHZ1YzE2WWJGaHIxUEZkMWdXWjViNDVCNWJ4U2RpN3FtM3pNeVBnUTNsWkp0dXNTM0g5UGZXcnRmd1pGYjdxWFZtS19Sb00tMi1Kc25FSFlBLVExdElfTTlQNlZuZmxiMzFyT0VNcExURWs2RkRsN1h0bGh3b215T2VvQ1RpOHZtcXh0c2JzTllHR08tOW8tYXhZbnNaeGh6cmhBUlJ0LVVfSmo4T082RXIzOERR0gHDAUFVX3lxTE84UUxqLXRoTnNTSUI2N1J0S0FHcDQ2ZnpuSTRteld0RUxFTDZocmdUVG9CYmJBMGxhZ0RKb2RYd3cxU0lub2ktZlUwVXN0ZjFGVmZqUlhMSVVGMzgwdThtUnYySFBTeURfU1dvYzh6MTFzNGl6eWR0bUVZcUdCWFNxaFh5VTdsME5OdmlzT1IxN2ZvRzBZVGlQcmJqSUwwemdQRVZheTV3ME5mSkRMd0JFbmUtTDNFdlBkVW1NaUhnbG1ONA?oc=5"
        },
        {
          "source": "Security Boulevard",
          "url": "https://news.google.com/rss/articles/CBMivwFBVV95cUxNMEV3ZnpIS1Q2QjVoSFFhVllCOWRuTzBsZ1FNeF9Fa0JLMFdfZHN4X3N1OFlxbVI0c1ZITERkU0lUM1FkekxHRTZvaVZoMDR1bU5Pb3JiU0ZRV3lQM0lOZ1FaTTFHODRDQjN1a29nd3VUTVY2UnpnU2ZNbWhESjBSS2lFTmpKSmFteWFFTElTMWtjTU5KTjliQ0d5X05wcEVYcTE2Z2ZzREg5b3E2bTZtd3lXSFVLUGZnQmJoanBuMA?oc=5"
        },
        {
          "source": "gHacks",
          "url": "https://news.google.com/rss/articles/CBMivwFBVV95cUxQY053X3FJT01OQmpZQkFWcVgyY2tvcFE1bXVRcFpvU3pLTzFlUlhxNE9KZkVDc3JESzlDRmxfWUZRNVlJa0pNa2xidmtORG4wWWNxY1pRcUdBQlBrdzJOUGk4QnFuOEJNR25zY0pwUGlPTGNINkwwY1AxakFRWjZtRTF5MGwwbDY3SnpydE03akZiUTljNVBSSzNubmtEZDJSakI5X0MxbjkxTW9NY2k5Y0l6cUhRS3BzTmU1clB1bw?oc=5"
        },
        {
          "source": "Security Affairs",
          "url": "https://news.google.com/rss/articles/CBMiwgFBVV95cUxOZlFlRllDTW5jRVlMa0JOejRERk5XeXh6Z1lXeHI4RWJWanFMQzNZdTl1ZHVHUFJVaDJ5WGtiLWdMb0YyMTJiR1JNd3JmUXgwVUpMVEJqVmpCV3dxUkVDMXJiZWJUVzRjVm8taHVHRE5RQl9Zbm1OSVVwS24xQllQNU9pVE5kZHBPSWxHaVJTWTZaMVoyUlhGU0ROWXpYVlBvVFJ6bG1XR3RqQjEyZHQ3YWl3Rmw1OTBjVFE3eVg0aUY4QdIBxwFBVV95cUxOazVtcFFuS1c2a285Ry1qNUxkZzItRWFMM0ZGdWpJcFFZTDU1bll3Y2VKMGtoenBSQ1NncTVwQnlvQVE3OFdJVThkZVhHOW9HYlU2Y0sxYm5EYURGTHNuNDlJR05Lc2c2U09PUHM4YXZFRTU0YVptdFZhTnFzbjhmVFpLcC11YlFFZk12LVhFaXItR2FKNjEwZzdKODlXMUtuM0h1LW4wR1JiTTdTRFJBemxqdi1sRmpSd0FpdUJZOVRwSktCcXE0?oc=5"
        },
        {
          "source": "SW Newsmagazine",
          "url": "https://news.google.com/rss/articles/CBMiwwFBVV95cUxOaEphZWFMYk9fbU5wd09mc2ljVUZmTDMyYVYwUS1LR2VWYnNKNWdlT0pscVE5YmlKRF9GMjBWVm1KUWdnOXVCdkIyWlRLRWdLVzl4MEs5Vlg3M3d6S1VQVndvUzFOOV94N1FuVjladHFERnBydmFNUHR1QlNXUHkxSmhZd2pwSG5QeTdXNkFMMl93WkxlTkFsWlU0V2N2cWQ1b3RKaTJXMWg3UEFsa2ZoZnpZRXVFd0dNeTJjbVpmdWllZUk?oc=5"
        },
        {
          "source": "Next Big Future",
          "url": "https://news.google.com/rss/articles/CBMiwwFBVV95cUxQS3lwQ19xMXJ2NnRaemJMTmJuRnBQaEtVZU8yZzlTYzF6d05GMnFFdlY4X1Ewc1dzVU5JOS1XT3haQVZmNTRuNHJoM1hIZGt0ckF5RWU0VXRJNWFvNnpUUW9qT183bmw1c0dGVy1oU2tKcllnMl9nc29vX1RXY2w2emJLVUlJSUVJUnNCX2dGUWVmd054Z3JNYTI1cGVKTXZ3TUxrTDZ6blNpMzhKbTVuZkY3WFo3V3JyYlMwWG91NF9jUUU?oc=5"
        },
        {
          "source": "The Guardian",
          "url": "https://news.google.com/rss/articles/CBMiyAFBVV95cUxOSnlKVXR0aTVRX0FzM2J3UHBCRUlKbGxfU0JDSFVlMEtzQzFEMndhQ19CUjdhVEtNY1l6b2J2RUpibkZvT0FTNGhQRUZ2V0JVNzU3cUtWMlZHdlFDMTFlUlN4cEFldXhFeXRIUW9oMTJuUjVLTENHVnRWbWFwOXlsTVA3UkpZQVpka3ZQOG9HWld1VGZDWWQ0TDdTeTM1anNHcWNEUWNtMkI0cUkyYUc2ZWczQWVXWG00eG15WnNqbUhWTW5XOEJRbA?oc=5"
        }
      ],
      "confidence": "Research / Hypothetical",
      "date": "2026-07-21",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Tech Times",
      "source_type": "Public reporting",
      "summary": "",
      "title": "OpenAI Says Its A.I. Models Went Rogue and Attacked a Digital Library - The New York Times",
      "url": "https://news.google.com/rss/articles/CBMi1wFBVV95cUxPSmh1T25kUjBUc3owd251Y3p1TjRpQjgya29mQmJ6VVFCNjAxMDJFYTJ4OFJ3azkyN09kTnpERDlwcTFRUnJYS2pJcXRmSks3bVhMSEZuZUxaLWprNjFHbzNvSm5la2VsOEF3WmN5V1hwaWRJN19ZR292RzFxTGVyQ3FBQ0ZGTWVaQ0RHcmJDQzhlWC1KNWpGLW5kRWdQQVJqTEZ1WnhHb2lvZEFTaDBGemhOOE10MllLUjVJR3hjTmtEOHRsSkJVVllBclU1LXREWTgtVVdMdw?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-04-03",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Unit 42",
      "source_type": "Public reporting",
      "summary": "When an Attacker Meets a Group of Agents: Navigating Amazon Bedrock's Multi-Agent Applications Unit 42",
      "title": "When an Attacker Meets a Group of Agents: Navigating Amazon Bedrock's Multi-Agent Applications - Unit 42",
      "url": "https://news.google.com/rss/articles/CBMigAFBVV95cUxQWkw4dVVoTUFiTUYyNlZjbVprZjBienpIaUhEYlRnYWRJS0tuQ3JqdHJsOGJWRHZPUmlkZlVzbDRzMXpFTWpHQ0NyU2tjRzBCaENFRnZMbVhJR1lnTDVlRlBqQjJjVTZjS1d1UkJySUNlOHJxRXVHc1NsU0xEQTd2ZA?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-06-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "FinSMEs",
      "source_type": "Public reporting",
      "summary": "Tenet Security, Interview With CEO Barak Sternberg FinSMEs",
      "title": "Tenet Security, Interview With CEO Barak Sternberg - FinSMEs",
      "url": "https://news.google.com/rss/articles/CBMijwFBVV95cUxQckJtNE9rZzloUWhUWXVVeTVzTzFVSWkzSEdYV1NFQWZRbGFybE1pM3NkVGZ5MjZtN3NpWndqVHlyVjdiQndPazc0aUlIVE5yb1BfeHgwcnJRanV2dEhrVnJkNlRLRmJ4Q3dFQi1jclBaRXZvSHpLZW1KQXhsWjlKWk01RVFJckcwYkdhUHBUbw?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-06-05",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "MIT Technology Review",
      "source_type": "Public reporting",
      "summary": "The Meta hack shows there\u2019s more to AI security than Mythos MIT Technology Review",
      "title": "The Meta hack shows there\u2019s more to AI security than Mythos - MIT Technology Review",
      "url": "https://news.google.com/rss/articles/CBMisAFBVV95cUxNVlhzV1EwTzVfYjU2U2REZ3V6UnZCcVYwek12UUIySjBaRzRaVl9pMlJCclFHRVg2bUtZa3ZxdjNHY3E1TnoxVVE4S0pYV2VQQ0UxNnEtVGRRSEd1ckZRV0lhdGwyazF0ZkZiaEZaSkEwcXJFUEFnMVc2Q0kxaXI0alV1Tnlrb2U0Yy00NUhsTkxLcmhPanFZSE00MGcwWWhFTnVlUFVZa1BGQTRBU19OQdIBtgFBVV95cUxQQjJSVzEtLTFQSm13Q2FCd2FVUFlFMXRzUGRyRnRZWktLS3UwZGlkZ0JTM2p3Tlh0aURqRHpscFZ1ZzNkVTBWN3hQcW1OZEUwZmFFclZ4STd0elpzLWItSTRNR0JVUU92WWEtZXBYOEtCaS0xU2pnMHl3SWViM2drNHh0ZmlfcEItbEZ3bzM2WXh5eS1NVHM1Y1paN3l2VzVjV20yVG10R0dhTWtrY2t5U19jYjFBUQ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2025-09-11",
      "detection_surface": "MCP graph edges, privilege expansion, and scope explosion",
      "failure_pattern": "Connector or tool-surface expansion",
      "recommendation": "Pre-register tools, review requested scopes, and alert on unexpected graph expansion.",
      "relevant_awr": [
        "AWR-112",
        "AWR-113"
      ],
      "severity": "Medium",
      "source": "Medium",
      "source_type": "Public reporting",
      "summary": "Model Context Protocol (MCP) Attacks: Threats, Taxonomy, and Defenses for Tool-Using LLMs Medium",
      "title": "Model Context Protocol (MCP) Attacks: Threats, Taxonomy, and Defenses for Tool-Using LLMs - Medium",
      "url": "https://news.google.com/rss/articles/CBMiyAFBVV95cUxQdURyZ1NMcHN6VGtjQ0o3VWQ5Y0wxVjh1TWhXd0MzZGo4OEVQc0hDemh1X1lUYXpuT0ZpZTQ2RHRhZGtmTHl6Qi1vc0lJRjlUY1gtS253VUVwLUN5SFJYdUltczE0ZG5vYVlvVnFHejNzbWpCQlFOY1JfU3B6YjRXeDRnVGhRX0RPcUdMdWIwZ0xTeFJ3SmV0anlkMkE5RWdtaFFKd2RjRkY2akVERnZqTURwVTc1RURGblNXdlZGbGUyWThlRXJfZg?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2025-08-09",
      "detection_surface": "Egress destination, payload metadata hash, and session-level intent drift",
      "failure_pattern": "Data exposure / exfiltration risk",
      "recommendation": "Restrict egress, monitor destination drift, and keep sensitive outputs behind review gates.",
      "relevant_awr": [
        "AWR-111",
        "AWR-006"
      ],
      "severity": "High",
      "source": "Medium",
      "source_type": "Public reporting",
      "summary": "Use-Case Rabbits, Data Leaks, and Shadow AI \u2014 The Top Perils of Enterprise GenAI and the Hard-Won\u2026 Medium",
      "title": "Use-Case Rabbits, Data Leaks, and Shadow AI \u2014 The Top Perils of Enterprise GenAI and the Hard-Won\u2026 - Medium",
      "url": "https://news.google.com/rss/articles/CBMi1AFBVV95cUxOMzFENHJjMm9hai1XUW5hZ1FPeC1ZbWtsNFpFWHFXdzF6VUJURldfYzFGQlU4SlVoOFh3dExXZmxCdVBwMDM3VzU4d0JWNlZ4RjhxT3QzTkhWN09pNW9jM2FsV09PM2htNDFkb3BOQ1NVNnhyVEFmTUZvMldHSEdhU2RWYUt2MjcyZERDNXJqQmZlWEFxd01NV1V6a2RCdlFGbnphSzd4M3FDZG5kR19BY3p4RkJpeFRaOGVha0tEdS1nREUyZnM5R0I2Wk5HWkFqTzVSVQ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-02-12",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Microsoft",
      "source_type": "Public reporting",
      "summary": "Detecting and mitigating common agent misconfigurations Microsoft",
      "title": "Detecting and mitigating common agent misconfigurations - Microsoft",
      "url": "https://news.google.com/rss/articles/CBMitgFBVV95cUxPQk9pdU1jNGhzVWxNOGVIc3VtblE2bjJKQWdmMDdyY09qdC1HV2N3RDJiam1oV3RoMFRuQkpjTXVNQUNrVmJsQ1JHTmxpV0lXVE5QZHl2LW85RWpoWTVSTnpXOG0teHhSZGkwbzFyZXJCSEpVOWVUd2V5cExfSkVJSDJoMzJTeWhRZFdVN21MQzR6Z3FFS3JoQld0aHpMU3E1NkRDT2huSFhNTjlHN3hHUGlGdkJ2dw?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-11-14",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "wiz.io",
      "source_type": "Public reporting",
      "summary": "AI Cyberattacks: How attackers target AI, and use AI against you wiz.io",
      "title": "AI Cyberattacks: How attackers target AI, and use AI against you - wiz.io",
      "url": "https://news.google.com/rss/articles/CBMiZEFVX3lxTE5EaEVMaHptUmVuZ21DMUJ0dWsxY1FUQUJYZ0p2ZHN1bE5GVEs5bFA2UmJyX1pPdmdYc184T1psUnVWTWotbnlVVkQwc0Y3cmluQ2x0bGJKV1N6MFhfUUJRczA3SUo?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2025-09-18",
      "detection_surface": "Egress destination, payload metadata hash, and session-level intent drift",
      "failure_pattern": "Data exposure / exfiltration risk",
      "recommendation": "Restrict egress, monitor destination drift, and keep sensitive outputs behind review gates.",
      "relevant_awr": [
        "AWR-111",
        "AWR-006"
      ],
      "severity": "High",
      "source": "The Record from Recorded Future News",
      "source_type": "Public reporting",
      "summary": "OpenAI fixes zero-click ShadowLeak vulnerability affecting ChatGPT Deep Research agent The Record from Recorded Future News",
      "title": "OpenAI fixes zero-click ShadowLeak vulnerability affecting ChatGPT Deep Research agent - The Record from Recorded Future News",
      "url": "https://news.google.com/rss/articles/CBMifEFVX3lxTE0yRXlOdjZ1M09LbW9td2F6ejIxd2VlOHZidE1qR2dqWndKVWMzd2UzTmE1QmpaOWxBWm9mc2lncUJOV2JnTDhvUF9yR295SGFNVS1UaUFsaVVURlBNUUlVdGJZWHFTRnZlX3VJOXhxbG16M21mYTk5dnVRaWw?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-04-16",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Help Net Security",
      "source_type": "Public reporting",
      "summary": "Command integrity breaks in the LLM routing layer Help Net Security",
      "title": "Command integrity breaks in the LLM routing layer - Help Net Security",
      "url": "https://news.google.com/rss/articles/CBMiiwFBVV95cUxPSjM2Y0w1YW1hRWYtU2ZfdVdSU0FOcWJjZnZaTXJ5cmRUYjJJUG1XU19oMmpyUXNWWkJwbk9sRUN0S0ZnczJHQmczZlNEVHVhc1BJSHB0YkVwN2E2WTBzSzhsNE04Sl9mQkZyQUd2UjJjVVNhNjVRS0pwNEZKNHNrWmZUa2JLTGVqMXZF?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-03-28",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Blockchain Council",
      "source_type": "Public reporting",
      "summary": "NemoClaw Explained for Web3 Security Blockchain Council",
      "title": "NemoClaw Explained for Web3 Security - Blockchain Council",
      "url": "https://news.google.com/rss/articles/CBMihgFBVV95cUxQYV9PY3l6U3RVOVJKOXgxOHJSbVgxaFRlNUVXUm9XbEg2bzZsZzF0dWFPM2Q3N3l3dHE0Y0pJLUdXc1ZTZE04aEJIWmNzYUJBdldfU1huR0lqQmZXYkNzNzlsR3g2c2FCM0dtN0YxdnhmUU9LTXJmelozRmhFZnpRWTE5NWJEdw?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-03-20",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "wiz.io",
      "source_type": "Public reporting",
      "summary": "AI Application Security: Risks, Tools & Best Practices wiz.io",
      "title": "AI Application Security: Risks, Tools & Best Practices - wiz.io",
      "url": "https://news.google.com/rss/articles/CBMib0FVX3lxTE4wblpNM080ZnlsdG1IM21ydWF1M1VseVc0X3p3MEhqTVN4S1NSSWdKMHBZMkFWaFR0cTQ0bm1mZmViRE9tZFlLUkt1WDJkRGNXOEpKU3E0Q3UyOEdGZTZuVUpjZlJqV3ZHUnIzODZETQ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-03-09",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Help Net Security",
      "source_type": "Public reporting",
      "summary": "OpenAI to acquire AI security platform Promptfoo Help Net Security",
      "title": "OpenAI to acquire AI security platform Promptfoo - Help Net Security",
      "url": "https://news.google.com/rss/articles/CBMilwFBVV95cUxQOVp2NkdmMFJVSHB4YXNQQl9OUmVycXkzWV85eDY2NUZsMnFPZW8ycWg5THpqeHNoTldrcFdMcHRfU19GelpiZjNoWTVNT01BMHkzck1mbmlBTExwRWR3Y0JvTlVWNkQzVGxUUG1IWm13WHhlb01JcmdDTU95bHRQTHNLSXZlMDBraEN1ekZ3XzZnSDZ5LTk0?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2025-06-25",
      "detection_surface": "MCP graph edges, privilege expansion, and scope explosion",
      "failure_pattern": "Connector or tool-surface expansion",
      "recommendation": "Pre-register tools, review requested scopes, and alert on unexpected graph expansion.",
      "relevant_awr": [
        "AWR-112",
        "AWR-113"
      ],
      "severity": "Medium",
      "source": "The Register",
      "source_type": "Public reporting",
      "summary": "Anthropic won't fix a bug in its SQLite MCP server The Register",
      "title": "Anthropic won't fix a bug in its SQLite MCP server - The Register",
      "url": "https://news.google.com/rss/articles/CBMiqAFBVV95cUxNcl9BYmlxTDJrVnRDdEY5cnpNQlYwYXY3U1hmMkIxcjhUUEJfVk5DdEtlM3prcGZxWFlSMHUyT2lNcFZnTmlyOFRvTmJDZVlQRWRyZWJZM2hNOW9jZk11dzhadkNxeHNlNVRoUUtZRHZTVUxGcWtrS2xLVFpaeVMyVzlITFBsOVhmWGk5RWdIeXJ0clQ0b3ZIX0hrV1dzNkE1YVRHOUpsaDM?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-04-08",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "36Kr",
      "source_type": "Public reporting",
      "summary": "Claude Mythos Sounds Alarm for World End: Superintelligence Nears, Hassabis Deeply Terrified 36Kr",
      "title": "Claude Mythos Sounds Alarm for World End: Superintelligence Nears, Hassabis Deeply Terrified - 36Kr",
      "url": "https://news.google.com/rss/articles/CBMiU0FVX3lxTE9yUHozMTdEUlRUQjltc2tab3ZJUElpbzhwQlEyelBCblVTbUx3dEZVV0VmU3FYbmxfU2lGZ2NoZno1UkljS3p4bzRIZUFMVjNyUWZB?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-04-03",
      "detection_surface": "Egress destination, payload metadata hash, and session-level intent drift",
      "failure_pattern": "Data exposure / exfiltration risk",
      "recommendation": "Restrict egress, monitor destination drift, and keep sensitive outputs behind review gates.",
      "relevant_awr": [
        "AWR-111",
        "AWR-006"
      ],
      "severity": "High",
      "source": "Futurism",
      "source_type": "Public reporting",
      "summary": "Anthropic Suddenly Cares Intensely About Intellectual Property After Realizing With Horror That It Accidentally Leaked Claude's Source Code Futurism",
      "title": "Anthropic Suddenly Cares Intensely About Intellectual Property After Realizing With Horror That It Accidentally Leaked Claude's Source Code - Futurism",
      "url": "https://news.google.com/rss/articles/CBMirgFBVV95cUxOVGpLYXJ5YUtBM3RwSzRXbE9uZi13Q1U5c2xsalVZY1h2WF9NdkVaRzlCaDVOdDNtS3hEZmZKNlBVc1lXUzlXMnhxaHdtRjhXbnROZktPLXlzTnR5c1pMTlZVTUVhMDVCSHpBbVJ0SGpyMndYc0k2Wk5FNExXSkkwT05tdEhLamxFaXdVU3hteGJfNUktRXlTWk1ieXZmUk5ydFNqcUZ4UW9xRlQzQkE?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-04-02",
      "detection_surface": "Egress destination, payload metadata hash, and session-level intent drift",
      "failure_pattern": "Data exposure / exfiltration risk",
      "recommendation": "Restrict egress, monitor destination drift, and keep sensitive outputs behind review gates.",
      "relevant_awr": [
        "AWR-111",
        "AWR-006"
      ],
      "severity": "High",
      "source": "BleepingComputer",
      "source_type": "Public reporting",
      "summary": "Claude Code leak used to push infostealer malware on GitHub BleepingComputer",
      "title": "Claude Code leak used to push infostealer malware on GitHub - BleepingComputer",
      "url": "https://news.google.com/rss/articles/CBMiqwFBVV95cUxQRU45d2lrdGk3NlN3SXZtWUJBcTh3OXY3UWExRlFEazl5Q0QwaWlFN1pIYlVrQVQxdFFCeENQeV9sMGdyMU9DbDJlTzczT2RCeGFGUDdxd0MtRDhiQ01UeUc4ZW43NXQ4Z1RCdldQYWFMVE1wR0tRdzczSHFKNW5zZ1VnTjJXQ18xaXBjb1VELVM5NXpJTnZZVS1FSG5RejNSdDBTWmtHd01WMlHSAbABQVVfeXFMT2ZfQXJCWm5QRTFWVVE5eWRDSUw4QkhiUnA5ZDlENFR6UUFwY0FOMmRVNXlZWTYtYk4tanZIeDRfSU5BRkpYa2htWTJGVnFweFBTd3FTUzNPVVYwT2gxYmtzVDRLenE0cnRfUFNBZVVHYzZHbnpQZE9hVThTTmMxUFFIR0xuSHEwY0IxbHd5RjdQdjdKNlduR3RDNjJvRkpTcXE0LTUzbkZ3QmVvclJOVGM?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2026-04-01",
      "detection_surface": "Egress destination, payload metadata hash, and session-level intent drift",
      "failure_pattern": "Data exposure / exfiltration risk",
      "recommendation": "Restrict egress, monitor destination drift, and keep sensitive outputs behind review gates.",
      "relevant_awr": [
        "AWR-111",
        "AWR-006"
      ],
      "severity": "High",
      "source": "WinBuzzer",
      "source_type": "Public reporting",
      "summary": "Claude Code Source Leak Exposes Anti-Distillation Traps WinBuzzer",
      "title": "Claude Code Source Leak Exposes Anti-Distillation Traps - WinBuzzer",
      "url": "https://news.google.com/rss/articles/CBMipwFBVV95cUxPVWg3cG14Qk1mRVhQVzZqcDlSWVRFbGZjdUFwRE03NEYwekNvaVlyRHZtdkdhVmNtRi1COHhwZmFYbUVxMkZGTGpOX2FlZW8xdkp2dEhrMzJFMjc4WVlwQ3l4TTRvYjczMUJfY1hBWXBKRkRWYXZpUmt0Q3JqVnhmVEROa0RFMzUyS2xXaXAwaUJmaC1xSkdGLW1QNEY4dHhwaTA5enRJRQ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-03-11",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "The Futurum Group",
      "source_type": "Public reporting",
      "summary": "OpenAI Acquires Promptfoo, Gaining 25% Foothold in Fortune 500 Enterprises The Futurum Group",
      "title": "OpenAI Acquires Promptfoo, Gaining 25% Foothold in Fortune 500 Enterprises - The Futurum Group",
      "url": "https://news.google.com/rss/articles/CBMiqwFBVV95cUxQbTAyYzgtek1jTVFYWUdQLVdwMWFrY0tyVllnSlBLUmlYM2kzMUtYTXlscEhCMkdVdkNoaDJwMWhwbkVrcnlqY2RlM0ZKVUtIYXpfUXdmcmF1a3huelVGeEhxMXQ2bFdod1Y1S2Y5aXNONE8wbkpLRjdRMEtCcGllRU9XTDhQbTlVamg2RnhDREd2bm1ObHVwZHdxUkF4dHhwdkFSR19wQW9pNjQ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-02-07",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "AIMultiple",
      "source_type": "Public reporting",
      "summary": "OpenClaw (Moltbot/Clawdbot) Use Cases and Security 2026 AIMultiple",
      "title": "OpenClaw (Moltbot/Clawdbot) Use Cases and Security 2026 - AIMultiple",
      "url": "https://news.google.com/rss/articles/CBMiREFVX3lxTFBJX1FvZk1peHRfTWNUUGhUdE9EMXBpNXpfSkhEdDNkZWpycllGWC13bFdEU1dRSTQ1aDVPXy01N25PczZV?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-02-06",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Resecurity",
      "source_type": "Public reporting",
      "summary": "Clawdbot / Moltbot: The Autonomous AI Butler That Could Expose Your Entire Digital Life Resecurity",
      "title": "Clawdbot / Moltbot: The Autonomous AI Butler That Could Expose Your Entire Digital Life - Resecurity",
      "url": "https://news.google.com/rss/articles/CBMiwgFBVV95cUxQc2tqT2VEVGpqenFYMUhzSjBkR2hDZTZIQmxxX25sMEJOb2lCVUllNHZGM0JpUHNsUmpCNU9aeFRrUTNleHpNV0U3TDBzNW51OW1vY3VzR19ZR2VfU3VlZlBLazRVbk1DYkJ2eFNrN2FzMEFZUTJzX0c5bmM5VEZvU1A3cHlaUHZ5U2NxVE9kQnlxVVFzb1ExeWhwNjdLTjd3UFZSWTNLRHJQNk5VY1NkbUFrWDhlUi1DY1dDd09kT2JlQQ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-01-27",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Gradient Flow | Ben Lorica",
      "source_type": "Public reporting",
      "summary": "The 6 security shifts AI teams can't ignore in 2026 Gradient Flow | Ben Lorica",
      "title": "The 6 security shifts AI teams can't ignore in 2026 - Gradient Flow | Ben Lorica",
      "url": "https://news.google.com/rss/articles/CBMid0FVX3lxTFBJX1QyQjdrcXFhQXZyQmxJOFEzSnh2VjYtRGZNSW5QcjI0MXFKS0VsYURBX1J5Q2l0aXdoMWR5bTllbWM0aVhBZ1ZXVDF1eTREY1pkdEVPeUhxWjVHZ0FFQmNsTzdhTUY3VnFDelZQdDAxcjdsSF9v?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-01-21",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "SiliconANGLE",
      "source_type": "Public reporting",
      "summary": "Nightfall expands data protection with AI Browser Security for browsers, endpoints and SaaS SiliconANGLE",
      "title": "Nightfall expands data protection with AI Browser Security for browsers, endpoints and SaaS - SiliconANGLE",
      "url": "https://news.google.com/rss/articles/CBMitAFBVV95cUxPb21rdFVJdFJ1ZzROWXVJdUM4VHdvMVpRYlBibVRkTUlxdTRxcDBaVUt1dHRaRmFDb0dQSjZVRlRURE50OGhVQVVlbFMySEtEZFdjbFNVNXJKcVpIVE9HRHBVeDVfeW4wM0l3R2N4ZHVaRTZ5dWhtNHh1eC1CdVB5OWFFcUVyQ3VRaGRiTDlJcHVLcjFNVDQ4VklFTzJYaGZLUW11aFVLa3d3Qjk5QmxvX1k2Yno?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-12-19",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Harvard Business Review",
      "source_type": "Public reporting",
      "summary": "6 Cybersecurity Predictions for the AI Economy in 2026 - SPONSOR CONTENT FROM PALO ALTO NETWORKS Harvard Business Review",
      "title": "6 Cybersecurity Predictions for the AI Economy in 2026 - SPONSOR CONTENT FROM PALO ALTO NETWORKS - Harvard Business Review",
      "url": "https://news.google.com/rss/articles/CBMikgFBVV95cUxQcVZaNlZYNVlTNXUtSndRTmk4N0t2dGhUcjA4TzJJcDMzWFdFSHl1S2dTTlQtYUYwSVJ2Ti1QanNfQmtKTmtFcGJqS0ZHei10WEhSVXdfd2k2bFM1Z0VvSk1rcTJjcllZR3dhYW9OQnlzbXU2SnQwMDhxQVZzbFNreEgxUmttT19qMWlfWnQwQXRQUQ?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-10-29",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Help Net Security",
      "source_type": "Public reporting",
      "summary": "Palo Alto Networks launches Prisma AIRS 2.0 to deliver end-to-end security across the AI lifecycle Help Net Security",
      "title": "Palo Alto Networks launches Prisma AIRS 2.0 to deliver end-to-end security across the AI lifecycle - Help Net Security",
      "url": "https://news.google.com/rss/articles/CBMi2gFBVV95cUxQYTRESHZBYlZzLWJ0OVR1d29odTI2dklOamo1SXdmZ0VHR2tUMmcwQXRhMENELWE2V3pvd2xVUjJTUGE4VWxrb3YtazdqSVJBSGdseHgzU1pxcWlvSElITTdjeVdGNU8tZGNMUUp3NFdEMjR0YURfeW11QkxFbUJnamlMa0FZdzBNWDBpWWsyWFFWWlI1QXh2Qml4b1ZqclJRaU1kQmttbE95ZHd2VUdJNW5rRm9NMjdPcVBfdURxUlBTajNIblk0TVFmMGlod1JZOEZSaE80Tk1Hdw?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2025-09-19",
      "detection_surface": "Egress destination, payload metadata hash, and session-level intent drift",
      "failure_pattern": "Data exposure / exfiltration risk",
      "recommendation": "Restrict egress, monitor destination drift, and keep sensitive outputs behind review gates.",
      "relevant_awr": [
        "AWR-111",
        "AWR-006"
      ],
      "severity": "High",
      "source": "SecurityBrief Australia",
      "source_type": "Public reporting",
      "summary": "ShadowLeak exploit exposes ChatGPT users to silent AI data theft SecurityBrief Australia",
      "title": "ShadowLeak exploit exposes ChatGPT users to silent AI data theft - SecurityBrief Australia",
      "url": "https://news.google.com/rss/articles/CBMioAFBVV95cUxNc3NnbEVpZnZJTS1zSlpGQXEzcm5xZ1VfSjg1bTAzdlV0ZVFTQ1h1WDNFSHpQTDNtcHF5TU45QkdHUHZld0xrUTVZWFkxd29Ra2FEOXBrNjVDZlpneE9jWEFNdEdIdmhLbDJxVFBtMWpJQkJCQUh3Yk5WTi1qd2JKSmNNc1NqdWxHWjBEQno5ZjZ1a2tVZmI1ZVhNR25hYmNp?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-08-20",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Help Net Security",
      "source_type": "Public reporting",
      "summary": "The AI security crisis no one is preparing for Help Net Security",
      "title": "The AI security crisis no one is preparing for - Help Net Security",
      "url": "https://news.google.com/rss/articles/CBMiiAFBVV95cUxNQ3JrblhabWpyMVBzWmh2VklteDRDeXR2QXBWVDhsQTU2OEozUUtEWk94N29PdnNOdlVWdTBEYV84RmUwZDRKMXNjMDdMeVFIRENhQUVhdDA1UlN2aGdWbXJFV2xta3hNdnNvSjVra0REQ3JVUTJzeEZpWHIxS2VGTEJWMkZISUl1?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-02-18",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "cyberpress.org",
      "source_type": "Public reporting",
      "summary": "Critical Log Poisoning Vulnerability in OpenClaw AI Allows Content Manipulation cyberpress.org",
      "title": "Critical Log Poisoning Vulnerability in OpenClaw AI Allows Content Manipulation - cyberpress.org",
      "url": "https://news.google.com/rss/articles/CBMiYEFVX3lxTFBwUC12YnBvS1YzOUdEWVJaWkpGdHRsSWZuWU9DNnlHVEdMQUU1NnBvVkxoMVhNMVg0QnNIaG5hMjRvczMzNWdHSEUzLXlRTWE0S2xnTVV4WlRCeVIyaHFRZNIBYEFVX3lxTFBwUC12YnBvS1YzOUdEWVJaWkpGdHRsSWZuWU9DNnlHVEdMQUU1NnBvVkxoMVhNMVg0QnNIaG5hMjRvczMzNWdHSEUzLXlRTWE0S2xnTVV4WlRCeVIyaHFRZA?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-02-12",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "The Hacker News",
      "source_type": "Public reporting",
      "summary": "ThreatsDay Bulletin: AI Prompt RCE, Claude 0-Click, RenEngine Loader, Auto 0-Days & 25+ Stories The Hacker News",
      "title": "ThreatsDay Bulletin: AI Prompt RCE, Claude 0-Click, RenEngine Loader, Auto 0-Days & 25+ Stories - The Hacker News",
      "url": "https://news.google.com/rss/articles/CBMifEFVX3lxTE9TeWx6ZVVjeEJsbTBHNnpESFRFTE1KOUtIU2ZrcmhpT3BWVlA3RHpXejZFTHM5MWVUX3ZwMzYxQ291bjBuRU1EQTVpZXFPNkMtaUwxei1ndk1UamZvUW83ckhnSkFOaERNc1cwVE9nR29qckdfQmQxVHdDV1M?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2026-02-05",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "AI Magazine",
      "source_type": "Public reporting",
      "summary": "How Anthropic Disrupted a World-First AI Cyber Espionage AI Magazine",
      "title": "How Anthropic Disrupted a World-First AI Cyber Espionage - AI Magazine",
      "url": "https://news.google.com/rss/articles/CBMiekFVX3lxTE1FRmpkZ1hkbXYtcHB0YmVmWjNBTERKVlBHaDFqN2V2SDRDa1dPS29JRmp2ZTRqRnRzSzYwd2ozVHdXMmJjNk5lQzExQzg0TW9pOEljMXZRZUpwOExxWUFJZjBIc2tFNXZMVTd3Q2FqZkV4YUMyZ1RobzdB?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-12-31",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "wiz.io",
      "source_type": "Public reporting",
      "summary": "What are LLM guardrails? Securing AI applications in production wiz.io",
      "title": "What are LLM guardrails? Securing AI applications in production - wiz.io",
      "url": "https://news.google.com/rss/articles/CBMiY0FVX3lxTE9NbG01ZXQxRTV5TFVZRWRmdGhLMEJJekhWWXRBc1hIZ2VKVm85SlhCbTQycW5qX1g3ZEtzbElLcTQ0OTlSUW50ckFiVE8yYk4xem12Uk1NOEN6NjhPbzY4N053MA?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-12-15",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Medium",
      "source_type": "Public reporting",
      "summary": "Inside the Dark LLM Economy Powering Modern Scams Medium",
      "title": "Inside the Dark LLM Economy Powering Modern Scams - Medium",
      "url": "https://news.google.com/rss/articles/CBMimgFBVV95cUxPUDEwUEdFYUI2RUlnNmJzaEthSWw5UkI2Z3dBS0dJbkt6RlpCVWtoaHNreHZjdzJxRGJEMHBaTDdGZEdodF9VWXZRZWV6ZmlNZFNxR3B3QTBTRGRtMmZGWWZqNFgzNndvbUp2Z2otdTVoWWhHSGxHbDBzTHFrQWRGTkNRTFRmWkN4MTNISWFCM1Q1LTNycjVpc2VB?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Likely Mapping",
      "date": "2025-11-05",
      "detection_surface": "Egress destination, payload metadata hash, and session-level intent drift",
      "failure_pattern": "Data exposure / exfiltration risk",
      "recommendation": "Restrict egress, monitor destination drift, and keep sensitive outputs behind review gates.",
      "relevant_awr": [
        "AWR-111",
        "AWR-006"
      ],
      "severity": "High",
      "source": "The Hacker News",
      "source_type": "Public reporting",
      "summary": "Researchers Find ChatGPT Vulnerabilities That Let Attackers Trick AI Into Leaking Data The Hacker News",
      "title": "Researchers Find ChatGPT Vulnerabilities That Let Attackers Trick AI Into Leaking Data - The Hacker News",
      "url": "https://news.google.com/rss/articles/CBMicEFVX3lxTFBWNGtxVTJrbHpFSDVxM2d4N1VqVW1ES2I3TFdNekFpNDcwOW1vY25SRURXQVRFUk1raU5BSTJRRGE1M3RFdXVPWEFDXzczTThEUmJwY1lYc3d0dFJLRE5JaXFwcHlVcUhKeWlia0l5a3M?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-10-29",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "XDA",
      "source_type": "Public reporting",
      "summary": "Please stop using AI browsers XDA",
      "title": "Please stop using AI browsers - XDA",
      "url": "https://news.google.com/rss/articles/CBMibkFVX3lxTFBPSEc3RkJIRm43ZjlyNW94SmR2TnR3bi04VWtHRm9wandyTkNabGgxNnNoM3NBVzJZUmNZdWZFdnJmMmVPWWVtX3p1Q0JfTjJnMXllbmpZcl9Qd0Z1SS1FTUZlaFlKUThEeW94R3hB?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-10-28",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Palo Alto Networks",
      "source_type": "Public reporting",
      "summary": "Prisma AIRS 2.0 Is Powering the Next Wave of Secure AI Innovation Palo Alto Networks",
      "title": "Prisma AIRS 2.0 Is Powering the Next Wave of Secure AI Innovation - Palo Alto Networks",
      "url": "https://news.google.com/rss/articles/CBMilwFBVV95cUxOMkFWZTYtZl8wWDlieThOYkt2Tk1HbGU4OGpZTFp6dDVNNE83UmlYWXdubmc5T2NPc0xNZ0FKeW1GN1B0ZDh2bnZNaXc0bXFRemw3UWlqSExmTVlOZ3k3TllqMWFHTWUzVF9YTVUwTVJPNl9qdTFKY1I5ZzRTeGVCbEtfa1EtWkQyckdSZU5TVFJNV2tOdTNR?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-10-24",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Medium",
      "source_type": "Public reporting",
      "summary": "Benchmarking the Investigator: Why ExCyTIn\u2011Bench Is the New Gate for AI in the SOC Medium",
      "title": "Benchmarking the Investigator: Why ExCyTIn\u2011Bench Is the New Gate for AI in the SOC - Medium",
      "url": "https://news.google.com/rss/articles/CBMixAFBVV95cUxQcXMzRnNwekJoWENYb3FIdXF6T1pWc0hmVWZtaG1ORENaQXVzTkxrX2owenZwSnJoQVI2OXdPQkNicHhNT2E0eTJpcDdDUXZxT0gxSTAzMGViZTdTVURYeG1QRWhwUzJxX2FrNGd6ZkFpc0dxWU4zRlI1T3prSlMzZW5BemhGOHZabzJxWHdaQzdlR2NjcGFQLXFYY1R2UGdVdElSRGhGTDNNQjlGRnU5RnRtLVA1YmxzWko1dlVaZHJpT0g4?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-09-19",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Malwarebytes",
      "source_type": "Public reporting",
      "summary": "ChatGPT Deep Research zero-click vulnerability fixed by OpenAI Malwarebytes",
      "title": "ChatGPT Deep Research zero-click vulnerability fixed by OpenAI - Malwarebytes",
      "url": "https://news.google.com/rss/articles/CBMirgFBVV95cUxQcWFYSVhBVnVBVDlGZ25pMXhxR3dNOE52RWlnYnZWUTFUMTFLRDJGU3hBSnZXMGxRMlNQX2owbk9yM0x1c2V1d0o3NTFhN284YkphY0IweXN5VWR2RWdqeDdtUW9xMzJUMVdaYTZ0b2NxOTE2eXpHazFvMkV4Y0pxbEhxRjRMUm5TXzR5cTlYUjMxTHAxM0FNbzhDbjRpM29Nb0JPeExRMmlFbWRLWlE?oc=5"
    },
    {
      "also_reported_by": [],
      "confidence": "Research / Hypothetical",
      "date": "2025-09-17",
      "detection_surface": "Session trace, event cadence, and rule evaluation",
      "failure_pattern": "Agent security research / operational risk",
      "recommendation": "Review the agent workflow, limit tool scope, and monitor behavioral drift.",
      "relevant_awr": [
        "AWR-100"
      ],
      "severity": "Medium",
      "source": "Palo Alto Networks",
      "source_type": "Public reporting",
      "summary": "Securing the Future of AI Palo Alto Networks",
      "title": "Securing the Future of AI - Palo Alto Networks",
      "url": "https://news.google.com/rss/articles/CBMifEFVX3lxTE1IaXI2WTlkYmlnQ2ZpdHdSMFl3b2E2QW9PRGlnSGd6NmxfWmdkZGZZYTdmU2RJYTJ0bzQxU0ZmYnhfeHpJeWlQLVduVFg4dTB3TV9kRm1kQkNpUUxiQjlfclFlQ3FEWDNrV0QybzkwUklHVXcySFMzTkVPZl8?oc=5"
    }
  ]
}
