Attacks on AI systems, curated and mapped.
Prompt injection, jailbreaks, data poisoning, adversarial evasion, model theft, supply-chain compromise — real incidents and research, each mapped to the MITRE ATLAS framework so you can explore the adversarial landscape for AI the way you already navigate ATT&CK.
28
Curated attacks
45 / 101
Techniques covered
16
ATLAS tactics
v5.6.0
ATLAS version
> explore
ATLAS Matrix
The full tactic × technique grid. Cells shade by how many curated attacks map there — click any technique to drill in.
Catalog
Every curated attack, filterable by type, severity, tactic, and target model. The fastest way to find a specific technique in the wild.
Timeline
Attacks in chronological order — watch how adversarial pressure on AI systems has evolved over time.
> featured
view all →ForcedLeak: CRM Data Exfiltration from Salesforce Agentforce
Malicious instructions embedded in a Web-to-Lead submission were later executed by Salesforce Agentforce during normal employee use, exfiltrating CRM data through an attacker-acquired domain still on Salesforce's CSP allowlist — bought for $5.
EchoLeak: Zero-Click Data Exfiltration from Microsoft 365 Copilot
A single crafted email — no clicks required — planted hidden instructions that Microsoft 365 Copilot ingested from context, then abused trusted markdown image rendering to exfiltrate internal data to an attacker server. The first documented zero-click exploit of a production LLM assistant.
Slopsquatting: Weaponizing AI Package Hallucinations
Code-gen LLMs confidently invent non-existent package names — and repeat the same fake names reliably. Attackers register those hallucinated packages with malware, so developers who paste AI suggestions install the payload themselves.
Morris II: A Self-Replicating Worm for GenAI Ecosystems
An adversarial self-replicating prompt spreads between GenAI-powered email assistants: each infected assistant carries out malicious actions and poisons the RAG of the next, propagating agent-to-agent with zero clicks.
> about
This is a curated intelligence layer on top of MITRE ATLAS — the Adversarial Threat Landscape for AI Systems. Every entry documents a real attack technique against an AI/ML system, mapped to the ATLAS tactics and techniques it exercises, and annotated with severity, detection signals, and mitigations.
Entries are curated from security research, disclosures, and proof-of-concepts, then reviewed before publishing. The goal is a fast, explorable map of how adversaries actually attack AI — for detection engineers, red teamers, and AI security teams.
Part of Threat Detection Labs