{
 "schema_version": "redlens.agents/2",
 "generated_at": "2026-10-05T16:21:15Z",
 "note": "Every hand correction to the incident register in the last 30 days, oldest first: a merge (two IDs were one event; the old ID resolves to into_id), a move (one document was in the wrong incident; to_incident 'none' means assessed, not an incident) or a relabel. Model assignments are not listed; these are what a person changed, and why.",
 "count": 52,
 "corrections": [
  {
   "at": "2026-10-04T06:18:23Z",
   "action": "move",
   "document_id": "RL-D-7597413b544d",
   "document_title": "OpenAI agents reportedly targeted RubyGems prior to the Hugging Face cybersecurity incident",
   "document_url": "https://ciso.economictimes.indiatimes.com/news/cybercrime-fraud/openai-agents-reportedly-targeted-rubygems-prior-to-the-hugging-face-cybersecurity-incident/134230725",
   "from_incident": "RL-I-2026-0085",
   "to_incident": "RL-I-2026-0153",
   "reason": "About OpenAI agents and RubyGems (May), a separate event from the Hugging Face breach"
  },
  {
   "at": "2026-10-04T06:18:23Z",
   "action": "move",
   "document_id": "RL-D-80d79258e0c5",
   "document_title": "OpenAI Agents Hit RubyGems Two Months Before The Hugging Face Attack",
   "document_url": "https://www.forbes.com/sites/jonmarkman/2026/09/14/openai-agents-hit-rubygems-two-months-before-the-hugging-face-attack/",
   "from_incident": "RL-I-2026-0085",
   "to_incident": "RL-I-2026-0153",
   "reason": "About OpenAI agents and RubyGems (May), a separate event from the Hugging Face breach"
  },
  {
   "at": "2026-10-04T06:18:23Z",
   "action": "move",
   "document_id": "RL-D-0e91490b95ff",
   "document_title": "OpenAI Agents Flooded RubyGems With 2,000 Malicious Packages Months Before Hugging Face Breach",
   "document_url": "https://www.webpronews.com/openai-agents-flooded-rubygems-with-2000-malicious-packages-months-before-hugging-face-breach",
   "from_incident": "RL-I-2026-0085",
   "to_incident": "RL-I-2026-0153",
   "reason": "About OpenAI agents and RubyGems (May), a separate event from the Hugging Face breach"
  },
  {
   "at": "2026-10-04T06:18:24Z",
   "action": "move",
   "document_id": "RL-D-3fa718da8fb9",
   "document_title": "BAIT: Boundary-Guided Disclosure Escalation LLM Jailbreaking via Self-Conditioned Reasoning",
   "document_url": "https://arxiv.org/abs/2605.27110",
   "from_incident": "RL-I-2026-0117",
   "to_incident": "none",
   "reason": "The BAIT paper: a research paper, not an incident; its ID had collected Anthropic's threat report coverage"
  },
  {
   "at": "2026-10-04T06:18:24Z",
   "action": "move",
   "document_id": "RL-D-f59e3ecd73ae",
   "document_title": "Sources: OpenAI asked members of Congress for guidance on whether orchestrating an industry-wide slowdown in AI development would be legal under antitrust",
   "document_url": "https://www.techmeme.com/260910/p43",
   "from_incident": "RL-I-2026-0117",
   "to_incident": "RL-I-2026-0017",
   "reason": "Reports Anthropic's September threat report (title is another story's)"
  },
  {
   "at": "2026-10-04T06:18:24Z",
   "action": "move",
   "document_id": "RL-D-12610f0ba6eb",
   "document_title": "AI lets small actors run state-level hacking campaigns, Anthropic report finds",
   "document_url": "https://cyberscoop.com/anthropic-report-ai-enabled-cyber-attacks/",
   "from_incident": "RL-I-2026-0177",
   "to_incident": "RL-I-2026-0017",
   "reason": "Reports Anthropic's September threat report, not the North Korean IT-worker scheme this incident was minted for"
  },
  {
   "at": "2026-10-04T06:18:25Z",
   "action": "move",
   "document_id": "RL-D-c958653f3fe6",
   "document_title": "Iran used Claude AI to target US Navy warships? Here’s what Anthropic’s threat report says",
   "document_url": "https://www.financialexpress.com/world-news/us-news/iran-used-claude-ai-to-target-us-navy-warships-heres-what-anthropics-threat-report-says/4337879/",
   "from_incident": "RL-I-2026-0177",
   "to_incident": "RL-I-2026-0017",
   "reason": "Reports Anthropic's September threat report, not the North Korean IT-worker scheme this incident was minted for"
  },
  {
   "at": "2026-10-04T06:18:25Z",
   "action": "move",
   "document_id": "RL-D-59b49d741185",
   "document_title": "Anthropic Says Russian, Chinese Threat Actors Used Its AI Model Claude for Malicious Activity",
   "document_url": "https://www.theepochtimes.com/tech/anthropic-says-russian-chinese-threat-actors-used-its-ai-model-claude-for-malicious-activity-6086054",
   "from_incident": "RL-I-2026-0177",
   "to_incident": "RL-I-2026-0017",
   "reason": "Reports Anthropic's September threat report, not the North Korean IT-worker scheme this incident was minted for"
  },
  {
   "at": "2026-10-04T06:18:25Z",
   "action": "move",
   "document_id": "RL-D-4c23c09ea9b0",
   "document_title": "Anthropic blocks Russian hackers, Chinese AI labs accused of misusing Claude",
   "document_url": "https://www.businesstimes.com.sg/companies-markets/telcos-media-tech/anthropic-blocks-russian-hackers-chinese-ai-labs-accused-misusing-claude",
   "from_incident": "RL-I-2026-0177",
   "to_incident": "RL-I-2026-0017",
   "reason": "Reports Anthropic's September threat report, not the North Korean IT-worker scheme this incident was minted for"
  },
  {
   "at": "2026-10-04T06:18:26Z",
   "action": "move",
   "document_id": "RL-D-1817ef74bcd4",
   "document_title": "Anthropic says Russian, Chinese actors used Claude to develop weapons",
   "document_url": "https://www.businessinsider.com/anthropic-says-threat-actors-used-claude-for-weapons-2026-9",
   "from_incident": "RL-I-2026-0177",
   "to_incident": "RL-I-2026-0017",
   "reason": "Reports Anthropic's September threat report, not the North Korean IT-worker scheme this incident was minted for"
  },
  {
   "at": "2026-10-04T06:18:26Z",
   "action": "move",
   "document_id": "RL-D-48632aff39af",
   "document_title": "Iran, Yemeni Cell Used Claude in Developing Weapons, Threats: Anthropic",
   "document_url": "https://securityboulevard.com/2026/09/iran-yemeni-cell-used-claude-in-developing-weapons-threats-anthropic/",
   "from_incident": "RL-I-2026-0177",
   "to_incident": "RL-I-2026-0017",
   "reason": "Reports Anthropic's September threat report, not the North Korean IT-worker scheme this incident was minted for"
  },
  {
   "at": "2026-10-04T06:18:26Z",
   "action": "move",
   "document_id": "RL-D-ba78b173c48d",
   "document_title": "AI is supercharging hacking, and your local hospitals and banks aren’t ready",
   "document_url": "https://www.theverge.com/ai-artificial-intelligence/1001427/ai-is-supercharging-hacking-and-your-local-hospitals-and-banks-arent-ready",
   "from_incident": "RL-I-2026-0177",
   "to_incident": "RL-I-2026-0017",
   "reason": "Reports Anthropic's September threat report, not the North Korean IT-worker scheme this incident was minted for"
  },
  {
   "at": "2026-10-04T06:18:27Z",
   "action": "move",
   "document_id": "RL-D-b304ab8a3ce8",
   "document_title": "Google Built an AI Hacker That Hunts Real Vulnerabilities, Here's How PageBreak Actually Works | AdvisioTech",
   "document_url": "https://advisiotech.com/blog/google-pagebreak-ai-hacker-vulnerability-discovery",
   "from_incident": "RL-I-2026-0066",
   "to_incident": "RL-I-2026-0006",
   "reason": "About Google PageBreak; was in the ShinyHunters/FBI incident"
  },
  {
   "at": "2026-10-04T06:18:27Z",
   "action": "move",
   "document_id": "RL-D-cb0a58a9c4b1",
   "document_title": "AI Is Reshaping Vulnerability Discovery: Disclosures Double and Exploitation Already Tops 2025",
   "document_url": "https://pbxscience.com/ai-is-reshaping-vulnerability-discovery-disclosures-double-and-exploitation-already-tops-2025/",
   "from_incident": "RL-I-2026-0006",
   "to_incident": "none",
   "reason": "A Google GTIG trend report on AI vulnerability discovery, not PageBreak and not one incident"
  },
  {
   "at": "2026-10-04T06:18:27Z",
   "action": "move",
   "document_id": "RL-D-565855d8f08d",
   "document_title": "Google GTIG finds AI accelerating vulnerability discovery across enterprise and critical infrastructure attack surfaces - Industrial Cyber",
   "document_url": "https://industrialcyber.co/critical-infrastructure/google-gtig-finds-ai-accelerating-vulnerability-discovery-across-enterprise-and-critical-infrastructure-attack-surfaces",
   "from_incident": "RL-I-2026-0006",
   "to_incident": "none",
   "reason": "A Google GTIG trend report on AI vulnerability discovery, not PageBreak and not one incident"
  },
  {
   "at": "2026-10-04T06:18:28Z",
   "action": "move",
   "document_id": "RL-D-28a724994536",
   "document_title": "AI-Assisted Phishing Campaign Sent Over A Million Personalized Emails",
   "document_url": "https://blog.knowbe4.com/ai-assisted-phishing-campaign-sent-over-a-million-personalized-emails",
   "from_incident": "RL-I-2026-0065",
   "to_incident": "RL-I-2026-0160",
   "reason": "Microsoft's AI-assisted invoice-fraud campaign (1M emails), not the invisible-Unicode campaign"
  },
  {
   "at": "2026-10-04T06:18:28Z",
   "action": "move",
   "document_id": "RL-D-979e5a6e1cc2",
   "document_title": "OpenAI Reports New AI Safety Incidents, Sets Disclosure Process - Bloomberg",
   "document_url": "https://bloomberg.com/news/articles/2026-09-16/openai-reports-new-ai-safety-incidents-sets-disclosure-process",
   "from_incident": "RL-I-2026-0002",
   "to_incident": "RL-I-2026-0136",
   "reason": "Chiefly OpenAI's new incident-disclosure framework"
  },
  {
   "at": "2026-10-04T06:18:28Z",
   "action": "move",
   "document_id": "RL-D-6f173f62e710",
   "document_title": "OpenAI and Anthropic Probe Tens of Thousands of AI Agent Incidents as Researcher Warns Some Could Be Crimes",
   "document_url": "https://www.inkl.com/news/openai-and-anthropic-probe-tens-of-thousands-of-ai-agent-incidents-as-researcher-warns-some-could-be-crimes",
   "from_incident": "RL-I-2026-0002",
   "to_incident": "RL-I-2026-0021",
   "reason": "The labs' review of tens of thousands of agent incidents incl. government sites"
  },
  {
   "at": "2026-10-04T06:18:28Z",
   "action": "move",
   "document_id": "RL-D-dfe309766042",
   "document_title": "Cyber Threats | ENISA",
   "document_url": "https://www.enisa.europa.eu/topics/cyber-threats",
   "from_incident": "RL-I-2026-0002",
   "to_incident": "none",
   "reason": "ENISA threat-landscape page; does not report the Hugging Face breach"
  },
  {
   "at": "2026-10-04T06:18:29Z",
   "action": "move",
   "document_id": "RL-D-f7bb345868f9",
   "document_title": "Thetechedvocate",
   "document_url": "https://thetechedvocate.org/the-quiet-revolution-7-online-courses-transforming-cybersecurity-with-ai",
   "from_incident": "RL-I-2026-0005",
   "to_incident": "none",
   "reason": "A training-course piece; does not report the retailer campaign"
  },
  {
   "at": "2026-10-04T06:18:29Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0085",
   "into_id": "RL-I-2026-0002",
   "reason": "Both are the OpenAI agent swarm's Hugging Face breach (July 2026)"
  },
  {
   "at": "2026-10-04T06:18:29Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0240",
   "into_id": "RL-I-2026-0153",
   "reason": "GemStuffer is the RubyGems campaign attributed to OpenAI agents"
  },
  {
   "at": "2026-10-04T06:18:29Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0117",
   "into_id": "RL-I-2026-0017",
   "reason": "Coverage of Anthropic's September 2026 threat intelligence report (one disclosure, several cases)"
  },
  {
   "at": "2026-10-04T06:18:30Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0061",
   "into_id": "RL-I-2026-0017",
   "reason": "Coverage of Anthropic's September 2026 threat intelligence report (one disclosure, several cases)"
  },
  {
   "at": "2026-10-04T06:18:30Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0288",
   "into_id": "RL-I-2026-0017",
   "reason": "Coverage of Anthropic's September 2026 threat intelligence report (one disclosure, several cases)"
  },
  {
   "at": "2026-10-04T06:18:30Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0310",
   "into_id": "RL-I-2026-0017",
   "reason": "Coverage of Anthropic's September 2026 threat intelligence report (one disclosure, several cases)"
  },
  {
   "at": "2026-10-04T06:18:30Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0312",
   "into_id": "RL-I-2026-0017",
   "reason": "Coverage of Anthropic's September 2026 threat intelligence report (one disclosure, several cases)"
  },
  {
   "at": "2026-10-04T06:18:30Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0417",
   "into_id": "RL-I-2026-0017",
   "reason": "Coverage of Anthropic's September 2026 threat intelligence report (one disclosure, several cases)"
  },
  {
   "at": "2026-10-04T06:18:31Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0173",
   "into_id": "RL-I-2026-0017",
   "reason": "Coverage of Anthropic's September 2026 threat intelligence report (one disclosure, several cases)"
  },
  {
   "at": "2026-10-04T06:18:31Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0034",
   "into_id": "RL-I-2026-0059",
   "reason": "Both are the Irregular test-environment breaches by lab models"
  },
  {
   "at": "2026-10-04T06:18:31Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0110",
   "into_id": "RL-I-2026-0021",
   "reason": "Both are OpenAI agents reaching US government websites (OpenAI disclosure, Transluce findings)"
  },
  {
   "at": "2026-10-04T06:18:31Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0182",
   "into_id": "RL-I-2026-0023",
   "reason": "Same OpenAI disclosure: an agent bypassed DNS filtering to reach an external chatbot"
  },
  {
   "at": "2026-10-04T06:18:32Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0167",
   "into_id": "RL-I-2026-0047",
   "reason": "Both are Hacktron's use of Claude to breach OpenAI systems"
  },
  {
   "at": "2026-10-04T06:18:32Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0148",
   "into_id": "RL-I-2026-0372",
   "reason": "Both are OpenAI Astra finding zero-days"
  },
  {
   "at": "2026-10-04T06:18:32Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0447",
   "into_id": "RL-I-2026-0160",
   "reason": "Both are Microsoft's AI-assisted executive-impersonation invoice campaign"
  },
  {
   "at": "2026-10-04T06:18:32Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0089",
   "into_id": "RL-I-2026-0162",
   "reason": "Both are Chainalysis's report on blockchain-hosted malware and AI"
  },
  {
   "at": "2026-10-04T06:18:33Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0230",
   "into_id": "RL-I-2026-0091",
   "reason": "Both are the RatHat Android malware (Cleafy and Zimperium reports)"
  },
  {
   "at": "2026-10-04T06:18:33Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0253",
   "into_id": "RL-I-2026-0094",
   "reason": "Both are the BragJack browser-extension technique"
  },
  {
   "at": "2026-10-04T06:18:33Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0291",
   "into_id": "RL-I-2026-0166",
   "reason": "Both are Malwarebytes' AI-built fake Avast renewal page"
  },
  {
   "at": "2026-10-04T06:18:33Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0353",
   "into_id": "RL-I-2026-0181",
   "reason": "Both are GitHub Security Lab's 24 Android vulnerabilities"
  },
  {
   "at": "2026-10-04T06:18:33Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0281",
   "into_id": "RL-I-2026-0257",
   "reason": "Both are the RedHerring decoy paper"
  },
  {
   "at": "2026-10-04T06:18:34Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0321",
   "into_id": "RL-I-2026-0327",
   "reason": "All are Google's Gemini 4 Argon release"
  },
  {
   "at": "2026-10-04T06:18:34Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0398",
   "into_id": "RL-I-2026-0327",
   "reason": "All are Google's Gemini 4 Argon release"
  },
  {
   "at": "2026-10-04T06:18:34Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0397",
   "into_id": "RL-I-2026-0325",
   "reason": "Both are MI5's CGTRI warning to UK universities"
  },
  {
   "at": "2026-10-04T06:18:34Z",
   "action": "relabel",
   "incident_id": "RL-I-2026-0021",
   "label": "OpenAI agents probed US and Canadian government websites",
   "reason": "Merged with RL-I-2026-0110; the old label named only one site"
  },
  {
   "at": "2026-10-04T06:18:34Z",
   "action": "relabel",
   "incident_id": "RL-I-2026-0160",
   "label": "AI-assisted executive-impersonation invoice phishing, over a million emails",
   "reason": "Merged with RL-I-2026-0447"
  },
  {
   "at": "2026-10-04T06:18:35Z",
   "action": "relabel",
   "incident_id": "RL-I-2026-0017",
   "label": "Anthropic's September 2026 threat intelligence report on Claude misuse [disclosure]",
   "reason": "Seven split incidents merged into it"
  },
  {
   "at": "2026-10-04T06:24:43Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0421",
   "into_id": "RL-I-2026-0017",
   "reason": "Coverage of Anthropic's September 2026 threat intelligence report (one disclosure, several cases)"
  },
  {
   "at": "2026-10-04T06:24:43Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0426",
   "into_id": "RL-I-2026-0017",
   "reason": "Coverage of Anthropic's September 2026 threat intelligence report (one disclosure, several cases)"
  },
  {
   "at": "2026-10-04T06:24:43Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0382",
   "into_id": "RL-I-2026-0017",
   "reason": "Coverage of Anthropic's September 2026 threat intelligence report (one disclosure, several cases)"
  },
  {
   "at": "2026-10-04T06:24:43Z",
   "action": "merge",
   "merged_id": "RL-I-2026-0169",
   "into_id": "RL-I-2026-0165",
   "reason": "Both are Australia's proposal for mandatory reporting of AI incidents (18 Sep)"
  },
  {
   "at": "2026-10-04T06:28:26Z",
   "action": "relabel",
   "incident_id": "RL-I-2026-0002",
   "label": "OpenAI agent swarm compromise of Hugging Face [intrusion]",
   "reason": "An attack that happened (kind was disclosure, after OpenAI's report); filtering on intrusion missed the largest incident"
  }
 ]
}
