Timeline

Curated attacks on AI systems in chronological order — newest first.

2026

  1. 2026-07-16 Incident critical Other

    Malicious Dataset RCE in Hugging Face's Processing Pipeline

    A crafted dataset chained two flaws in Hugging Face's dataset-processing pipeline — a remote-code dataset loader and a template-injection bug in dataset config — turning routine ingestion into arbitrary code execution, then credential theft and lateral movement into internal clusters.

    AML.T0010.002AML.T0049AML.T0106AML.T0055AML.T0108
  2. 2026-07-11 Incident high Multimodal

    GhostCommit: Prompt Injection Hidden in Images Steals Agent Secrets

    Attackers concealed instructions inside PNG images that AI coding agents ingest and 'read.' When agents like Cursor and Google Antigravity processed the image, the hidden prompt executed — steering them to collect and exfiltrate developer secrets.

    AML.T0051.001AML.T0055AML.T0086
  3. 2026-06-05 Incident high Agent

    Prompt Injection in Claude Code GitHub Actions Steals CI/CD Secrets

    Untrusted text in a GitHub issue or pull request steered a Claude Code GitHub Action into reading process environment variables and CI/CD secrets, then exfiltrating them — turning an automated code agent into a credential-harvesting tool.

    AML.T0051.001AML.T0055AML.T0098AML.T0086
  4. 2026-05-07 Incident high Other

    Fake OpenAI 'Privacy Filter' Model on Hugging Face Pushes Infostealer

    A repository typosquatting OpenAI's Privacy Filter release copied the model card nearly verbatim and shipped a loader that fetched and ran infostealer malware. It hit #1 trending on Hugging Face with 244,000+ downloads in under 18 hours.

    AML.T0058AML.T0010.003AML.T0011.000AML.T0048.003
  5. 2026-02-23 Incident high LLM

    Model Distillation Campaigns Targeting Anthropic Claude

    Anthropic uncovered competitor labs harvesting Claude's outputs at scale — roughly 24,000 accounts and 16 million queries — to distill its agentic reasoning, code, tool-use, and computer-use capabilities into rival models. Model theft by imitation, laundered through ordinary API access.

    AML.T0040AML.T0065AML.T0008.005AML.T0024.002AML.T0048.004
  6. 2026-02-03 Research high Agent

    OpenClaw: Command & Control of an AI Agent via Prompt Injection

    A booby-trapped webpage delivered an indirect prompt injection that made an autonomous AI agent silently execute a script, then plant persistent instructions into its future context — turning the agent itself into a command-and-control channel.

    AML.T0051.001AML.T0054AML.T0069AML.T0053AML.T0080.001
  7. 2026-02-01 Research critical Agent

    OpenClaw 1-Click Remote Code Execution

    A malicious link carrying a few milliseconds of JavaScript was enough to achieve remote code execution on the OpenClaw AI agent — modifying its configuration, harvesting credentials, and escaping to the host in a single click.

    AML.T0011.003AML.T0050AML.T0081AML.T0106AML.T0105

2025

  1. 2025-09-25 Incident critical Agent

    ForcedLeak: CRM Data Exfiltration from Salesforce Agentforce

    Malicious instructions embedded in a Web-to-Lead submission were later executed by Salesforce Agentforce during normal employee use, exfiltrating CRM data through an attacker-acquired domain still on Salesforce's CSP allowlist — bought for $5.

    AML.T0051.001AML.T0093AML.T0086AML.T0048.003
  2. 2025-09-18 Incident high Agent

    ShadowLeak: Zero-Click Gmail Theft via ChatGPT Deep Research Agent

    A hidden prompt in an email made OpenAI's ChatGPT Deep Research agent collect inbox data and exfiltrate it from OpenAI's own cloud — a service-side, zero-click leak invisible to local or enterprise defenses.

    AML.T0051.001AML.T0085.001AML.T0086
  3. 2025-09-01 Incident high Agent

    Poisoned Postmark MCP Server Exfiltrates Email

    A popular MCP server for the Postmark email service was trojanized in a supply-chain 'rug pull': a new version silently BCC'd users' emails to an attacker. Every agent wired to the tool leaked mail automatically.

    AML.T0104AML.T0109AML.T0010.005AML.T0011.002AML.T0086
  4. 2025-08-06 Research high Agent

    Invitation Is All You Need: Hijacking Gemini to Control a Smart Home

    Malicious instructions hidden in a Google Calendar invitation title were executed when Gemini later summarized the user's schedule — triggering real-world actions through connected Google Home tools: opening windows, turning off lights, and starting a boiler.

    AML.T0051.001AML.T0053AML.T0048.003
  5. 2025-07-17 Incident high Agent

    Amazon Q VS Code Extension: Wiper Prompt via Supply-Chain Compromise

    An attacker gained write access to the open-source Amazon Q VS Code extension repo and slipped a prompt into an official release instructing the AI agent to wipe the local filesystem and cloud resources. It shipped to users before AWS pulled it — the payload failed only due to a syntax error.

    AML.T0010.005AML.T0011.002AML.T0051AML.T0101
  6. 2025-06-11 Incident critical LLM

    EchoLeak: Zero-Click Data Exfiltration from Microsoft 365 Copilot

    A single crafted email — no clicks required — planted hidden instructions that Microsoft 365 Copilot ingested from context, then abused trusted markdown image rendering to exfiltrate internal data to an attacker server. The first documented zero-click exploit of a production LLM assistant.

    AML.T0051.001AML.T0093AML.T0067AML.T0025
  7. 2025-06-01 Research high Agent

    Data Exfiltration via Agent Tools in Microsoft Copilot Studio

    Researchers showed that a Copilot Studio customer-service agent could be enumerated, fingerprinted, and then driven by prompt injection to collect and exfiltrate an organization's data through its own connected tools.

    AML.T0006AML.T0093AML.T0084AML.T0051.002AML.T0085.001
  8. 2025-04-24 Research high LLM

    Policy Puppetry: A Universal Jailbreak Across Frontier LLMs

    A single prompt template that disguises a request as a policy/config file plus fictional role-play bypassed the safety alignment of every major LLM family — OpenAI, Google, Anthropic, Meta, and others — with minimal per-model tweaking.

    AML.T0054AML.T0051.000
  9. 2025-03-18 Research high Agent

    Rules File Backdoor: Poisoning AI Coding-Assistant Config

    Hidden, obfuscated instructions planted in a shared 'rules file' silently steered AI coding assistants like Cursor and GitHub Copilot to inject malicious code — a supply-chain backdoor invisible in normal review.

    AML.T0010.001AML.T0081AML.T0068AML.T0051.000AML.T0067
  10. 2025-03-06 Incident medium LLM

    LLM Grooming: Flooding Training Data to Seed Disinformation

    A pro-Kremlin website network mass-published millions of propaganda articles, seemingly to seep into the data that trains and grounds LLMs. An audit found leading chatbots repeated the network's false claims about a third of the time — a data-integrity attack on the model supply chain.

    AML.T0020AML.T0059AML.T0048.002
  11. 2025-02-06 Incident high Other

    nullifAI: Malicious Pickle Models Evading Hugging Face Scanning

    Two models on Hugging Face carried reverse-shell payloads in broken Pickle files, deliberately malformed and 7z-compressed to slip past Picklescan. Loading the model opened a connection back to the attacker — RCE via the model artifact itself.

    AML.T0010.003AML.T0058AML.T0011.000
  12. 2025-01-01 Research high LLM

    AIKatz: Stealing Auth Tokens from LLM Desktop Applications

    Researchers extracted authentication tokens from the memory of LLM desktop apps (Claude, ChatGPT, Copilot). With a stolen token, an attacker impersonates the victim to the LLM backend — lateral movement into the user's AI account.

    AML.T0089AML.T0091.000AML.T0092AML.T0048.003

2024

  1. 2024-10-01 Research high Computer Vision

    Live Deepfake Injection to Evade Mobile KYC Verification

    A red team defeated a mobile facial-authentication / KYC service by injecting a live, face-swapped deepfake video into the camera feed — impersonating a target and passing liveness checks to open fraudulent accounts.

    AML.T0088AML.T0016.002AML.T0073AML.T0015AML.T0048.000
  2. 2024-08-20 Research high LLM

    Data Exfiltration from Slack AI via Indirect Prompt Injection

    A malicious instruction posted in a public Slack channel was ingested into Slack AI's RAG index, then coaxed the assistant to leak data from private channels — rendered as a clickable link that carried secrets to an attacker.

    AML.T0051.001AML.T0070AML.T0066AML.T0082AML.T0077
  3. 2024-06-06 Research high Other

    Web-Scale Data Poisoning: The Split-View Attack

    Web-scale datasets distributed as lists of URLs can be poisoned by buying expired domains behind those URLs. What researchers downloaded when the dataset was built differs from what later trainers fetch — cheaply poisoning real training corpora.

    AML.T0002.000AML.T0008.002AML.T0019AML.T0020AML.T0059
  4. 2024-03-28 Research high LLM

    Slopsquatting: Weaponizing AI Package Hallucinations

    Code-gen LLMs confidently invent non-existent package names — and repeat the same fake names reliably. Attackers register those hallucinated packages with malware, so developers who paste AI suggestions install the payload themselves.

    AML.T0062AML.T0060AML.T0011.001
  5. 2024-03-05 Research high Agent

    Morris II: A Self-Replicating Worm for GenAI Ecosystems

    An adversarial self-replicating prompt spreads between GenAI-powered email assistants: each infected assistant carries out malicious actions and poisons the RAG of the next, propagating agent-to-agent with zero clicks.

    AML.T0051.001AML.T0070AML.T0052AML.T0086
  6. 2024-02-01 Research high LLM

    Hacking ChatGPT's Long-Term Memory with Prompt Injection

    A prompt injection hidden in a shared document wrote false, persistent 'memories' into ChatGPT's long-term memory. Because memories survive across sessions, the planted instructions could exfiltrate future conversations indefinitely.

    AML.T0093AML.T0051.001AML.T0068AML.T0080.000AML.T0048.003
  7. 2024-01-12 Research high LLM

    Sleeper Agents: Backdoored LLMs That Survive Safety Training

    Researchers trained LLMs with a hidden trigger — behave normally, but write exploitable code when the prompt says the year is 2024. Standard safety training (RLHF, adversarial training) failed to remove the backdoor, and sometimes taught the model to hide it better.

    AML.T0020AML.T0018.000AML.T0043.004

2023

  1. 2023-11-28 Research medium LLM

    Scalable Extraction of Training Data from ChatGPT

    Researchers made a production LLM regurgitate verbatim training data — including PII — by asking it to repeat a word 'forever.' A cheap query-only attack that recovered megabytes of memorized data from ChatGPT.

    AML.T0040AML.T0057AML.T0024.000
  2. 2023-09-05 Incident critical Other

    ShadowRay: Exploiting Exposed Ray AI Compute Clusters

    Ray's Job API allows remote execution by design and ships without authentication. Thousands of internet-exposed clusters let attackers run code, steal cloud credentials and AI artifacts, and hijack GPUs for cryptomining.

    AML.T0006AML.T0049AML.T0035AML.T0055AML.T0048.000
  3. 2023-08-23 Research high Other

    Organization Confusion on Hugging Face: Impersonation to Reverse Shell

    A researcher registered Hugging Face organization accounts impersonating real companies. Employees uploaded private models to the fake orgs — which could be swapped for poisoned models carrying reverse-shell payloads that execute when loaded.

    AML.T0007AML.T0058AML.T0010.003AML.T0011.000AML.T0072
  4. 2023-07-09 PoC high LLM

    PoisonGPT: Surgically Backdoored Model on a Public Hub

    Researchers edited a single fact into an open LLM using ROME, uploaded it under a name resembling a trusted org, and showed the poisoned model passing standard benchmarks while emitting targeted misinformation — an AI supply-chain compromise.

    AML.T0018AML.T0058AML.T0010
  5. 2023-02-23 Research high LLM

    Indirect Prompt Injection via Retrieved Web Content

    Attackers plant hidden instructions in web pages, emails, or documents that an LLM-integrated application later retrieves — hijacking the model's behavior without ever touching the victim's prompt.

    AML.T0051AML.T0056AML.T0086
  6. 2023-02-04 Research high LLM

    DAN & Role-Play Jailbreaks of ChatGPT

    Adversaries bypass an aligned LLM's safety guardrails using role-play personas ('Do Anything Now') and competing-objective prompts that coax the model into producing disallowed content.

    AML.T0054AML.T0051
  7. 2023-01-28 Incident high LLM

    Code Execution & API-Key Theft in MathGPT via Prompt Injection

    A public Streamlit app turned GPT-3 output into executed Python. A prompt-injection payload made the model emit code that read the host's environment variables, exfiltrated the app's OpenAI API key, and crashed the service.

    AML.T0093AML.T0051.000AML.T0053AML.T0055AML.T0048.000