Mapped to MITRE ATLAS v5.6.0

Attacks on AI systems, curated and mapped.

Prompt injection, jailbreaks, data poisoning, adversarial evasion, model theft, supply-chain compromise — real incidents and research, each mapped to the MITRE ATLAS framework so you can explore the adversarial landscape for AI the way you already navigate ATT&CK.

28

Curated attacks

45 / 101

Techniques covered

16

ATLAS tactics

v5.6.0

ATLAS version

> explore

> featured

view all →
Incident critical 2025-09-25

ForcedLeak: CRM Data Exfiltration from Salesforce Agentforce

Malicious instructions embedded in a Web-to-Lead submission were later executed by Salesforce Agentforce during normal employee use, exfiltrating CRM data through an attacker-acquired domain still on Salesforce's CSP allowlist — bought for $5.

AML.T0051.001AML.T0093AML.T0086AML.T0048.003
Incident critical 2025-06-11

EchoLeak: Zero-Click Data Exfiltration from Microsoft 365 Copilot

A single crafted email — no clicks required — planted hidden instructions that Microsoft 365 Copilot ingested from context, then abused trusted markdown image rendering to exfiltrate internal data to an attacker server. The first documented zero-click exploit of a production LLM assistant.

AML.T0051.001AML.T0093AML.T0067AML.T0025
Research high 2024-03-28

Slopsquatting: Weaponizing AI Package Hallucinations

Code-gen LLMs confidently invent non-existent package names — and repeat the same fake names reliably. Attackers register those hallucinated packages with malware, so developers who paste AI suggestions install the payload themselves.

AML.T0062AML.T0060AML.T0011.001
Research high 2024-03-05

Morris II: A Self-Replicating Worm for GenAI Ecosystems

An adversarial self-replicating prompt spreads between GenAI-powered email assistants: each infected assistant carries out malicious actions and poisons the RAG of the next, propagating agent-to-agent with zero clicks.

AML.T0051.001AML.T0070AML.T0052AML.T0086

> about

This is a curated intelligence layer on top of MITRE ATLAS — the Adversarial Threat Landscape for AI Systems. Every entry documents a real attack technique against an AI/ML system, mapped to the ATLAS tactics and techniques it exercises, and annotated with severity, detection signals, and mitigations.

Entries are curated from security research, disclosures, and proof-of-concepts, then reviewed before publishing. The goal is a fast, explorable map of how adversaries actually attack AI — for detection engineers, red teamers, and AI security teams.

Part of Threat Detection Labs