{"schema_version":"redlens.agents/2","generated_at":"2026-10-05T16:21:15Z","source":"documents_classified, active classifier (gemma4-12b@v5): every relevant, non-incidental document assigned an incident and first fetched in the last 30 days. Older documents and incidents are not published. No article text.","provenance_rule":"The system records what a document claims and what evidence backs it. evidence_class belongs to one source, never to a story.","evidence_classes":{"reproducible_result":"Artefacts published; anyone can check it.","independent_confirmation":"A second party confirmed it, without published artefacts.","threat_intel_report":"First-hand telemetry or casework from the party that observed it; not reproducible by a reader. An article reporting such a report takes this class: it is the class of what is reported, not of the outlet.","vendor_claim":"Asserted by an interested party, nothing offered.","analyst_assessment":"A judgement from someone who did not observe it.","commentary":"Discussion of the above."},"incident_kinds":{"intrusion":"An attack, compromise or fraud that happened.","disclosure":"A vulnerability, misuse or campaign made public (a vendor's threat report is one).","evaluation_result":"A measured capability result: a benchmark, a red-team finding, a paper's experiment. Not an event in the world.","policy_action":"A law, regulation, sanction, indictment or official guidance.","other":"None of the above."},"count":460,"merged":{"RL-I-2026-0013":"RL-I-2026-0007","RL-I-2026-0034":"RL-I-2026-0059","RL-I-2026-0061":"RL-I-2026-0017","RL-I-2026-0085":"RL-I-2026-0002","RL-I-2026-0089":"RL-I-2026-0162","RL-I-2026-0110":"RL-I-2026-0021","RL-I-2026-0117":"RL-I-2026-0017","RL-I-2026-0148":"RL-I-2026-0372","RL-I-2026-0167":"RL-I-2026-0047","RL-I-2026-0169":"RL-I-2026-0165","RL-I-2026-0173":"RL-I-2026-0017","RL-I-2026-0182":"RL-I-2026-0023","RL-I-2026-0230":"RL-I-2026-0091","RL-I-2026-0240":"RL-I-2026-0153","RL-I-2026-0253":"RL-I-2026-0094","RL-I-2026-0281":"RL-I-2026-0257","RL-I-2026-0288":"RL-I-2026-0017","RL-I-2026-0291":"RL-I-2026-0166","RL-I-2026-0310":"RL-I-2026-0017","RL-I-2026-0312":"RL-I-2026-0017","RL-I-2026-0321":"RL-I-2026-0327","RL-I-2026-0353":"RL-I-2026-0181","RL-I-2026-0382":"RL-I-2026-0017","RL-I-2026-0397":"RL-I-2026-0325","RL-I-2026-0398":"RL-I-2026-0327","RL-I-2026-0417":"RL-I-2026-0017","RL-I-2026-0421":"RL-I-2026-0017","RL-I-2026-0426":"RL-I-2026-0017","RL-I-2026-0447":"RL-I-2026-0160"},"merged_note":"old ID -> surviving ID. A merged ID's file is a pointer to its survivor.","corrections":"https://redlens.liminallayers.com/incidents/corrections.json","provisional":"Labels are a local model's reading and are provisional: evidence_class, ai_role and incident grouping can be wrong, and a source's own words are the authority. Check the document before relying on a label.","multi_source":"https://redlens.liminallayers.com/incidents/multi_source.json","incidents":[{"incident_id":"RL-I-2026-0491","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0491.json","title":"AWS Loom AI agent and SageMaker Unified Studio vulnerabilities","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AWS AI Agent Vulnerabilities Let Attackers Bypass Authentication and Steal Credentials","kind":"disclosure","first_reported":"2026-10-03T06:04:52Z","last_reported":"2026-10-03T06:04:52Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["independent_confirmation"],"ai_roles":["target"],"categories":["exploitation","influence_ops","malware","vuln_discovery"],"category_counts":{"exploitation":1,"influence_ops":1,"malware":1,"vuln_discovery":1},"named_systems":{"Amazon SageMaker Unified Studio":1,"Loom":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0490","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0490.json","title":"Anthropic report on multi-session task splitting to bypass safety filters","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Even if each part is safe, the overall task can be dangerous - Anthropic: Examples of splitting malicious work into multiple sessions to bypass monitoring","kind":"evaluation_result","first_reported":"2026-09-10T00:00:00Z","last_reported":"2026-09-10T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["evaluation","model_misuse","policy"],"category_counts":{"evaluation":1,"model_misuse":1,"policy":1},"named_systems":{"Claude":1,"SLEIGHT-Bench":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0489","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0489.json","title":"Intent-hiding jailbreaks framework for compositional attacks","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Intent-Hiding Jailbreaks: An Information-Theoretic Framework for Compositional Attacks","kind":"evaluation_result","first_reported":"2026-10-05T04:00:00Z","last_reported":"2026-10-05T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0488","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0488.json","title":"LiBRA method for detection-aware image watermark removal","title_source":"incident_label","label_source":"assigner_model","first_document_title":"LiBRA: Detection-Aware Image Watermark Removal via Bidirectional Latent Optimization","kind":"disclosure","first_reported":"2026-10-05T04:00:00Z","last_reported":"2026-10-05T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["deepfake_fraud","model_misuse"],"category_counts":{"deepfake_fraud":1,"model_misuse":1},"named_systems":{"LiBRA":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0487","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0487.json","title":"Branch steering attacks on computer-use agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Securing Computer-Use Agents Against Branch Steering Attacks","kind":"evaluation_result","first_reported":"2026-10-05T04:00:00Z","last_reported":"2026-10-05T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"exploitation":1,"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"COBRA":1,"Dual-LLM":1,"P-LLM":1,"Q-LLM":1,"STEER-Bench":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0486","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0486.json","title":"Distributed backdoor attack in multi-agent LLM systems","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Early Detection of Distributed Backdoors in Multi-Agent LLM Systems: A Characterization Study","kind":"disclosure","first_reported":"2026-10-05T04:00:00Z","last_reported":"2026-10-05T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["malware","offensive_ops","vuln_discovery"],"category_counts":{"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0485","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0485.json","title":"Router-gradient sensitivity research for identifying safety-sensitive experts in MoE LLMs","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Frequency Is Not Sensitivity Identifying Safety-Sensitive Experts in Sparse MoE LLM","kind":"evaluation_result","first_reported":"2026-10-05T04:00:00Z","last_reported":"2026-10-05T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse"],"category_counts":{"model_misuse":1},"named_systems":{"OLMoE":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0484","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0484.json","title":"EvoRiskBench benchmark for workspace agent security risks","title_source":"incident_label","label_source":"assigner_model","first_document_title":"EvoRiskBench: An Evolving Benchmark for Runtime Security Risks in Workspace Agents","kind":"evaluation_result","first_reported":"2026-10-05T04:00:00Z","last_reported":"2026-10-05T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","offensive_ops","vuln_discovery"],"category_counts":{"evaluation":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Claude Code":1,"Claude Opus 5":1,"Codex":1,"DeepSeek-V4-Pro-0813":1,"EvoRiskBench":1,"GPT-5.6 Sol":1,"OpenClaw":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0483","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0483.json","title":"Untag framework for evading trigger-tag misuse detection in LLMs","title_source":"incident_label","label_source":"assigner_model","first_document_title":"The Fragility of Trigger-Tag Mechanisms for Misuse Detection in Open-Weight LLMs","kind":"evaluation_result","first_reported":"2026-10-05T04:00:00Z","last_reported":"2026-10-05T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Untag":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0482","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0482.json","title":"Persona Guardrail framework and PAGE benchmark","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Persona Guardrail: A Production-Grade Defense Framework for Agentic Systems","kind":"evaluation_result","first_reported":"2026-10-05T04:00:00Z","last_reported":"2026-10-05T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["defender"],"categories":["deepfake_fraud","malware","offensive_ops","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"PAGE":1,"Persona Guardrail":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0481","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0481.json","title":"Hop-Decayed Influence vulnerabilities in GraphRAG pipelines","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Hop-Decayed Influence: New Vulnerabilities of Structural Auxiliary Indexing in GraphRAG Pipelines with LLM","kind":"disclosure","first_reported":"2026-10-05T04:00:00Z","last_reported":"2026-10-05T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["target"],"categories":["evaluation","model_misuse","vuln_discovery"],"category_counts":{"evaluation":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"2WikiMultiHopQA":1,"HippoRAG2":1,"HotpotQA":1,"Microsoft GraphRAG":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0480","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0480.json","title":"AgentTrap stateful honeypot for autonomous penetration testing agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AgentTrap: Stateful Feedback Deception against Autonomous Penetration Testing Agents","kind":"evaluation_result","first_reported":"2026-10-05T04:00:00Z","last_reported":"2026-10-05T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["defender"],"categories":["deepfake_fraud","evaluation","offensive_ops","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"evaluation":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"AgentTrap":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0479","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0479.json","title":"Phantom State Attack against IIoT Intrusion Detection","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Out of Sync, Out of Sight: Phantom State Attacks against IIoT Intrusion Detection","kind":"disclosure","first_reported":"2026-10-05T04:00:00Z","last_reported":"2026-10-05T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["target"],"categories":["evaluation","offensive_ops","vuln_discovery"],"category_counts":{"evaluation":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"MLP":1,"Random Forest":1,"XGBoost":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0478","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0478.json","title":"MLCommons Jailbreak Benchmark v1.0","title_source":"incident_label","label_source":"assigner_model","first_document_title":"MLCommons Jailbreak Benchmark v1.0","kind":"evaluation_result","first_reported":"2026-10-05T04:00:00Z","last_reported":"2026-10-05T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","model_misuse","vuln_discovery"],"category_counts":{"evaluation":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"AILuminate Assessment Standard v1.4":1,"MLCommons Jailbreak Benchmark v1.0":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0477","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0477.json","title":"Vision-language models leak information through top-k logits","title_source":"incident_label","label_source":"assigner_model","first_document_title":"What do your logits know?","kind":"disclosure","first_reported":"2026-10-05T04:00:00Z","last_reported":"2026-10-05T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0476","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0476.json","title":"CoC-Seduce benchmark for rhetorical injection in TRPG LLM adjudicators","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Assessing Rule Adherence of LLM Adjudicators in Call of Cthulhu TRPG","kind":"evaluation_result","first_reported":"2026-10-05T04:00:00Z","last_reported":"2026-10-05T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["evaluation","model_misuse","vuln_discovery"],"category_counts":{"evaluation":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"Claude Sonnet 4.6":1,"GPT-5.4":1,"Gemini 3.5 Flash":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0475","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0475.json","title":"SovereignNegotiation-Bench evaluation of personal AI agents in delegated bargaining","title_source":"incident_label","label_source":"assigner_model","first_document_title":"SovereignNegotiation-Bench: Evaluating User-Owned Personal Agents In Delegated Bargaining Under Privacy, Consent, Evidence, And Institutional Pressure","kind":"evaluation_result","first_reported":"2026-10-05T04:00:00Z","last_reported":"2026-10-05T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","policy","vuln_discovery"],"category_counts":{"evaluation":1,"policy":1,"vuln_discovery":1},"named_systems":{"SovereignNegotiation-Bench":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0474","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0474.json","title":"PI3D prompt injection in 3D environments","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Extended to Reality: Prompt Injection in 3D Environments","kind":"disclosure","first_reported":"2026-10-05T04:00:00Z","last_reported":"2026-10-05T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"PI3D":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0473","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0473.json","title":"ICoA covert indirect prompt injection attack method","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Will the User Ever Know? Covert Indirect Prompt Injection Attacks on Tool-Using LLM Agents","kind":"disclosure","first_reported":"2026-10-05T04:00:00Z","last_reported":"2026-10-05T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","malware","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"vuln_discovery":1},"named_systems":{"AGENTDOJO":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0472","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0472.json","title":"Open-Endedness Bench for measuring epistemic processes in AI agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Open-Endedness Bench: Measuring Epistemic Process from Agent Records","kind":"evaluation_result","first_reported":"2026-10-05T04:00:00Z","last_reported":"2026-10-05T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","model_misuse"],"category_counts":{"evaluation":1,"model_misuse":1},"named_systems":{"OEB":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0471","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0471.json","title":"JIL attack on LLM request scheduling","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Jumping the Line: Exploiting Length Predictions in LLM Scheduling","kind":"disclosure","first_reported":"2026-10-05T04:00:00Z","last_reported":"2026-10-05T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","model_misuse","vuln_discovery"],"category_counts":{"evaluation":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"JIL":1,"TRAIL":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0470","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0470.json","title":"AI agent accesses Australian federal health system","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Why Is Cyber Security Back in Focus for Betashares?","kind":"intrusion","first_reported":"2026-10-05T14:49:00Z","last_reported":"2026-10-05T14:49:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","policy"],"category_counts":{"deepfake_fraud":1,"malware":1,"policy":1},"named_systems":{"Gemini":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0469","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0469.json","title":"Google suspends open-source bug bounty program due to AI-generated spam","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI slop submissions force Google to freeze its open-source bug bounty","kind":"policy_action","first_reported":"2026-10-05T07:37:21Z","last_reported":"2026-10-05T08:27:46Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":2,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["malware","policy","vuln_discovery"],"category_counts":{"malware":2,"policy":2,"vuln_discovery":2},"named_systems":{"Cloud VRP":2,"Google Patch Rewards Program":1,"Open Source Software Vulnerability Reward Program (OSS VRP)":1,"Open Source Software Vulnerability Rewards Program (OSS VRP)":1,"Patch Rewards Program":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0468","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0468.json","title":"AI-powered data breaches at South Korean banks","title_source":"incident_label","label_source":"assigner_model","first_document_title":"South Korea probes bank breaches amid suspected AI-powered attacks","kind":"intrusion","first_reported":"2026-10-05T14:22:12Z","last_reported":"2026-10-05T14:22:12Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["instrument"],"categories":["exploitation","malware","phishing_social","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"phishing_social":1,"vuln_discovery":1},"named_systems":{"ARTEX AI":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0466","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0466.json","title":"OpenAI agent access of NSW National Parks web app","title_source":"incident_label","label_source":"assigner_model","first_document_title":"NSW National Parks web app accessed by Open AI agent","kind":"intrusion","first_reported":"2026-10-04T02:11:00Z","last_reported":"2026-10-04T02:11:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["incident_disclosure","policy","vuln_discovery"],"category_counts":{"incident_disclosure":1,"policy":1,"vuln_discovery":1},"named_systems":{"OpenAI agents (model unspecified)":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0465","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0465.json","title":"Anthropic blocks AI use for biological weapons and Iran-linked operations","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Anthropic says it blocked possible efforts to use AI for biological weapons development, Iran-linked cases","kind":"disclosure","first_reported":"2026-09-10T00:00:00Z","last_reported":"2026-09-10T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["malware","offensive_ops","phishing_social"],"category_counts":{"malware":1,"offensive_ops":1,"phishing_social":1},"named_systems":{"Claude":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0464","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0464.json","title":"Morse code prompt injection on AI trading agent to move funds","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI Agent Crypto Scams: When the Software Moves Your Money | Chain Pursuit","kind":"intrusion","first_reported":"2026-10-04T00:00:00Z","last_reported":"2026-10-04T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social","policy"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1,"policy":1},"named_systems":{"Bankr":1,"Coinbase Wallet":1,"Grok":1,"MetaMask":1,"Needle Stealer":1,"Phantom":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0463","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0463.json","title":"AI voice cloning fraud in Bhopal","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Bhopal Cyber Fraud: AI Voice Cloning Scam Dupes Security Guard Of ₹35,000","kind":"intrusion","first_reported":"2026-10-04T00:00:00Z","last_reported":"2026-10-04T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0462","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0462.json","title":"North Korea tests intermediate-range ballistic missile with AI features","title_source":"incident_label","label_source":"assigner_model","first_document_title":"North Korean leader Kim Jong Un watches missile launch as North Korea claims new AI capability","kind":"other","first_reported":"2026-10-03T00:00:00Z","last_reported":"2026-10-04T22:24:43Z","first_reported_basis":"published_at","event_date":null,"document_count":5,"distinct_sources":5,"coverage":"multiple_sources","evidence_classes":["vendor_claim","analyst_assessment"],"ai_roles":["instrument"],"categories":["exploitation","malware","offensive_ops"],"category_counts":{"exploitation":5,"malware":5,"offensive_ops":5},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0461","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0461.json","title":"Bank of England AI agent banking tests","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI Agents Exploited Finance Systems in Q3 Tests: BoE Chief Demands Legal Power to Act","kind":"intrusion","first_reported":"2026-10-03T03:39:36Z","last_reported":"2026-10-03T03:39:36Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["incident_disclosure","malware","policy","vuln_discovery"],"category_counts":{"incident_disclosure":1,"malware":1,"policy":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0460","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0460.json","title":"Anthropic Mythos AI identifies security flaw in Epic Systems MyChart portal","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Epic Paused Most Development After Anthropic's AI Found a Hidden MyChart Flaw - Startup Fortune","kind":"disclosure","first_reported":"2026-10-02T00:00:00Z","last_reported":"2026-10-02T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["exploitation","offensive_ops","vuln_discovery"],"category_counts":{"exploitation":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Agent Factory":1,"Claude Mythos":1,"EpicOps":1,"MyChart":1,"Project Glasswing":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0459","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0459.json","title":"Australian government mandate for legacy technology stocktakes","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Theimpactofai","kind":"policy_action","first_reported":"2026-09-30T00:00:00Z","last_reported":"2026-09-30T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["offensive_ops","policy","vuln_discovery"],"category_counts":{"offensive_ops":1,"policy":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0458","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0458.json","title":"AI agents breach Australian Medicare portal and retail sites","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Cyberattack Sunday; Sep 20th - 26th, 2026","kind":"intrusion","first_reported":"2026-10-02T00:00:00Z","last_reported":"2026-10-02T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["instrument"],"categories":["exploitation","incident_disclosure","malware","vuln_discovery"],"category_counts":{"exploitation":1,"incident_disclosure":1,"malware":1,"vuln_discovery":1},"named_systems":{"CARBONATO":1,"CLOSEDQUORUM":1,"Gemini":1,"Grok":1,"Hermes Agent":1,"RatHat":1,"x47.c":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0457","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0457.json","title":"OpenAI internal research model bypasses tool restrictions to access internal EDA host","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Command injecting a reference tool to copy a source file · OpenAI Alignment","kind":"intrusion","first_reported":"2026-10-02T00:00:00Z","last_reported":"2026-10-02T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":1,"coverage":"one_source","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["exploitation","model_misuse","policy","vuln_discovery"],"category_counts":{"exploitation":2,"model_misuse":2,"vuln_discovery":2,"policy":1},"named_systems":{"Internal unreleased model":1,"internal research model":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0456","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0456.json","title":"Kaspersky research on AI coding-agent security and LLM-driven zero-day discovery","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Kaspersky SAS 2026: AI Coding-Agent Security, Zero-Day Discovery and Firmware Threats","kind":"evaluation_result","first_reported":"2026-10-03T02:26:41Z","last_reported":"2026-10-03T02:26:41Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["subject"],"categories":["exploitation","malware","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"vuln_discovery":1},"named_systems":{"GitHub Copilot":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0455","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0455.json","title":"AI Agent Accountability Act proposed bill","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI Agent Accountability Act: Rogue Agent Hacks Now Carry Criminal Risk for Executives","kind":"policy_action","first_reported":"2026-10-03T06:36:21Z","last_reported":"2026-10-03T06:36:21Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["subject"],"categories":["malware","policy","vuln_discovery"],"category_counts":{"malware":1,"policy":1,"vuln_discovery":1},"named_systems":{"AI Agent Accountability Act":1,"Computer Fraud and Abuse Act (CFAA)":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0454","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0454.json","title":"Prompt injection via agent skill files","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Prompt Injection Through Agent Skill Files: Testing","kind":"disclosure","first_reported":"2026-10-03T00:00:00Z","last_reported":"2026-10-03T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["subject"],"categories":["exploitation","malware","policy","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"policy":1,"vuln_discovery":1},"named_systems":{"ActionGuard":1,"Cisco skill scanner":1,"ClawHub":1,"SkillSecurer":1,"skills.sh":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0453","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0453.json","title":"Deepfake voice fraud targeting executives for financial transfers","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Deepfake Voice Fraud: The Voice on the Phone Wasn’t Theirs | Netsurit US","kind":"intrusion","first_reported":"2026-10-02T00:00:00Z","last_reported":"2026-10-02T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","soc_defence","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"soc_defence":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0452","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0452.json","title":"Threat actors exploit trusted AI platforms to host malicious downloads","title_source":"incident_label","label_source":"assigner_model","first_document_title":"How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface","kind":"disclosure","first_reported":"2026-09-11T14:01:11Z","last_reported":"2026-09-11T14:01:11Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["malware","phishing_social","soc_defence"],"category_counts":{"malware":1,"phishing_social":1,"soc_defence":1},"named_systems":{"AMOS":1,"ChatGPT":1,"Claude Artifacts":1,"Grok":1,"MacSync":1,"SectopRAT":1,"claude.ai/share":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0451","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0451.json","title":"BREEZE COMET targets Brazilian financial services with AI-supported malware","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Financially Motivated Threat Actor BREEZE COMET Targets Brazil | Google Cloud Blog","kind":"intrusion","first_reported":"2026-09-12T08:24:58Z","last_reported":"2026-09-12T08:24:58Z","first_reported_basis":"fetched_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["evaluation","malware","phishing_social"],"category_counts":{"evaluation":1,"malware":1,"phishing_social":1},"named_systems":{"AnyDesk":1,"BREEZE COMET":1,"Plump Spider":1,"SHADOW-AETHER-064":1,"UNC5669":1,"XWORM":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0450","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0450.json","title":"Phishing campaign using ASCII smuggling to evade filters","title_source":"incident_label","label_source":"assigner_model","first_document_title":"ASCII smuggling crosses over from AI prompt injection to phishing evasion","kind":"intrusion","first_reported":"2026-09-03T16:00:00Z","last_reported":"2026-09-03T16:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["evaluation","malware","phishing_social"],"category_counts":{"evaluation":1,"malware":1,"phishing_social":1},"named_systems":{"Microsoft Defender for Office 365":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0449","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0449.json","title":"AI-themed phishing and malvertising campaigns","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Detect and disrupt AI-themed attacks with Microsoft Defender","kind":"disclosure","first_reported":"2026-09-10T16:00:00Z","last_reported":"2026-09-10T16:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1},"named_systems":{"ChatGPT":1,"Claude":1,"DeepSeek":1,"Microsoft Copilot":1,"Microsoft Defender":1,"Safe Attachments":1,"Safe Links":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0448","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0448.json","title":"China-based AI companies conduct industrial-scale knowledge distillation of U.S. models","title_source":"incident_label","label_source":"assigner_model","first_document_title":"China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies | CISA","kind":"disclosure","first_reported":"2026-09-12T08:26:51Z","last_reported":"2026-09-12T08:26:51Z","first_reported_basis":"fetched_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["target"],"categories":["model_misuse"],"category_counts":{"model_misuse":1},"named_systems":{"Claude":1,"DeepSeek R1":1,"DeepSeek V3":1,"GPT":1,"Gemini":1,"Grok":1,"Qwen":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0446","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0446.json","title":"PuzzleMask technique for embedding payloads in plain prose","title_source":"incident_label","label_source":"assigner_model","first_document_title":"PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector","kind":"disclosure","first_reported":"2026-09-10T14:32:46Z","last_reported":"2026-09-10T14:32:46Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["offensive_ops","policy","vuln_discovery"],"category_counts":{"offensive_ops":1,"policy":1,"vuln_discovery":1},"named_systems":{"claude-3-haiku-20240307":1,"gpt-4o-mini-2024-07-18":1,"gpt-5-thinking-high":1,"gpt-oss-safeguard:20b":1,"llama-guard3":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0445","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0445.json","title":"ChatGPT cross-account data leakage via shared clipboard","title_source":"incident_label","label_source":"assigner_model","first_document_title":"The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT","kind":"disclosure","first_reported":"2026-09-08T13:00:18Z","last_reported":"2026-09-08T13:00:18Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","exploitation","malware","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"exploitation":1,"malware":1,"vuln_discovery":1},"named_systems":{"ChatGPT":1,"JFrog Artifactory":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0444","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0444.json","title":"Research on interchangeable reasoning traces in proprietary LLM APIs","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Stealing AI Reasoning Traces","kind":"disclosure","first_reported":"2026-09-08T10:20:04Z","last_reported":"2026-09-08T10:20:04Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["target"],"categories":["exploitation","model_misuse","phishing_social","vuln_discovery"],"category_counts":{"exploitation":1,"model_misuse":1,"phishing_social":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0443","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0443.json","title":"James Strahler sentenced for AI-generated sexually explicit content and extortion","title_source":"incident_label","label_source":"assigner_model","first_document_title":"First ‘Take It Down Act’ Sentencing Puts Man Behind Bars for 15 Years","kind":"intrusion","first_reported":"2026-09-09T15:57:52Z","last_reported":"2026-09-09T15:57:52Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","policy"],"category_counts":{"deepfake_fraud":1,"malware":1,"policy":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0442","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0442.json","title":"OpenAI agents observed escaping sandboxes and passing notes on German Wiki","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Risky Business #852 -- Cyber Command wants to buy shells","kind":"disclosure","first_reported":"2026-09-09T05:32:45Z","last_reported":"2026-09-09T05:32:45Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["subject"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0441","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0441.json","title":"OpenAI agents use undisclosed websites for inter-agent communication","title_source":"incident_label","label_source":"assigner_model","first_document_title":"OpenAI rogue agent activity wider-ranging than disclosed","kind":"disclosure","first_reported":"2026-09-09T20:22:00Z","last_reported":"2026-09-09T20:22:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["malware","model_misuse","policy"],"category_counts":{"malware":1,"model_misuse":1,"policy":1},"named_systems":{"OpenAI agents (model unspecified)":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0440","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0440.json","title":"GPT 5.6-Cyber autonomous sandbox escape and host compromise","title_source":"incident_label","label_source":"assigner_model","first_document_title":"VMs won't contain cyber-capable agents","kind":"disclosure","first_reported":"2026-08-26T11:00:00Z","last_reported":"2026-08-26T11:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["evaluation","exploitation","malware","vuln_discovery"],"category_counts":{"evaluation":1,"exploitation":1,"malware":1,"vuln_discovery":1},"named_systems":{"Codex":1,"GPT 5.6-Cyber":1,"KVM":1,"QEMU":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0439","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0439.json","title":"Trail of Bits reports bug in Lean theorem prover","title_source":"incident_label","label_source":"assigner_model","first_document_title":"A “proof” of Fermat’s Last Theorem that fits the margin","kind":"disclosure","first_reported":"2026-09-09T11:00:00Z","last_reported":"2026-09-09T11:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["exploitation","malware","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"vuln_discovery":1},"named_systems":{"Claude":1,"GPT-5.6":1,"Lean":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0438","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0438.json","title":"Project Glasswing AI codebase vulnerability discovery","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Project Glasswing: Running a Frontier AI Model on Our Codebase | HackerOne","kind":"evaluation_result","first_reported":"2026-09-12T08:39:27Z","last_reported":"2026-09-12T08:39:27Z","first_reported_basis":"fetched_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["defender"],"categories":["offensive_ops","vuln_discovery"],"category_counts":{"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Claude Mythos 5":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0437","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0437.json","title":"MCPSEC prototype for indirect prompt injection detection","title_source":"incident_label","label_source":"assigner_model","first_document_title":"No-Box Vulnerability Analysis: Description-only Detection of Indirect Prompt Injection Vulnerabilities in MCP Servers","kind":"evaluation_result","first_reported":"2026-09-12T04:00:00Z","last_reported":"2026-09-12T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["malware","model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"malware":1,"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"MCPSEC":1,"Model Context Protocol":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0436","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0436.json","title":"BenchShield reward hacking detection instrumentation","title_source":"incident_label","label_source":"assigner_model","first_document_title":"BenchShield: Formal Model-Backed Instrumentation for Reward Integrity in LLM-Agent Evaluation Infrastructure","kind":"evaluation_result","first_reported":"2026-09-12T04:00:00Z","last_reported":"2026-09-12T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["defender"],"categories":["evaluation","model_misuse","vuln_discovery"],"category_counts":{"evaluation":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"BenchShield":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0435","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0435.json","title":"AIxCC competition reports on AI-driven vulnerability discovery in NGINX","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AIxCC Semifinal Competition: The Most Popular Bug – aicyberchallenge.com","kind":"evaluation_result","first_reported":"2026-09-12T08:50:52Z","last_reported":"2026-09-12T08:50:52Z","first_reported_basis":"fetched_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["defender"],"categories":["vuln_discovery"],"category_counts":{"vuln_discovery":1},"named_systems":{"NGINX":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0434","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0434.json","title":"DARPA AI Cyber Challenge winners announcement","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Final Competition Winners Announcement – aicyberchallenge.com","kind":"evaluation_result","first_reported":"2026-09-12T08:50:52Z","last_reported":"2026-09-12T08:50:52Z","first_reported_basis":"fetched_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["defender"],"categories":["vuln_discovery"],"category_counts":{"vuln_discovery":1},"named_systems":{"cyber reasoning system (CRS)":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0433","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0433.json","title":"Attacker prompts AI agent to reveal API key and steal model credits","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Update on Security at METR","kind":"intrusion","first_reported":"2026-08-31T00:00:00Z","last_reported":"2026-08-31T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["incident_disclosure","malware","vuln_discovery"],"category_counts":{"incident_disclosure":1,"malware":1,"vuln_discovery":1},"named_systems":{"EC2":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0432","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0432.json","title":"Autonomous multi-agent framework used to compromise thousands of credentials","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours","kind":"intrusion","first_reported":"2026-09-08T13:48:00Z","last_reported":"2026-09-08T13:48:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["instrument"],"categories":["influence_ops","malware"],"category_counts":{"influence_ops":1,"malware":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0431","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0431.json","title":"Bynario researchers use AI to find Apple macOS Screen Sharing vulnerabilities","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Milan-based Bynario raises €2.1 million pre-Seed after AI research exposed serious Apple vulnerabilities","kind":"disclosure","first_reported":"2026-09-10T00:00:00Z","last_reported":"2026-09-10T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","offensive_ops","vuln_discovery"],"category_counts":{"exploitation":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"macOS Screen Sharing":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0430","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0430.json","title":"TA4922 uses LLMs to develop vibe-coded Python malware","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Chinese Cybercrime Group Deploys AI-Coded Malware Campaigns","kind":"intrusion","first_reported":"2026-09-11T00:00:00Z","last_reported":"2026-09-11T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["evaluation","malware","phishing_social"],"category_counts":{"evaluation":1,"malware":1,"phishing_social":1},"named_systems":{"Atlas RAT":1,"RomulusLoader":1,"SilentRunLoader":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0429","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0429.json","title":"Anthropic Claude models breach real systems and upload malicious package to PyPI","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Anthropic Admits Claude Rationalized Past Evidence to Keep Hacking; July Explanation Was Wrong","kind":"intrusion","first_reported":"2026-09-11T12:26:50Z","last_reported":"2026-09-11T12:26:50Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","malware","model_misuse","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"Claude":1,"Claude Haiku":1,"Claude Mythos 5":1,"Claude Opus 4.6":1,"Claude Sonnet":1,"PyPI":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0428","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0428.json","title":"Chinese actors use AI agents to automate exploitation and evade monitoring","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Chinese Hackers Are Putting AI On Networks They Breach. Google Says It Helps Them Stay Hidden","kind":"intrusion","first_reported":"2026-09-09T14:50:18Z","last_reported":"2026-09-09T14:50:18Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","malware","phishing_social","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"phishing_social":1,"vuln_discovery":1},"named_systems":{"Claude":1,"Codex":1,"Gemini":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0427","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0427.json","title":"Chinese state-sponsored campaign uses Claude Code to automate cyber espionage","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Rogue AI Agents Are Democratizing Cyberattacks. Here's How.","kind":"intrusion","first_reported":"2026-09-07T12:45:00Z","last_reported":"2026-09-07T12:45:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","malware","offensive_ops","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Claude Code":1,"Model Context Protocol":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0425","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0425.json","title":"Software supply chain attack on LiteLLM open-source tool","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Cyberattacks hit Uber Freight, Fairlife, Ceva Logistics; AI steps in","kind":"disclosure","first_reported":"2026-09-11T17:12:17Z","last_reported":"2026-09-11T17:12:17Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["defender"],"categories":["incident_disclosure","malware","phishing_social","vuln_discovery"],"category_counts":{"incident_disclosure":1,"malware":1,"phishing_social":1,"vuln_discovery":1},"named_systems":{"LiteLLM":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0424","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0424.json","title":"Kimsuky uses AI coding agent opencode for phishing","title_source":"incident_label","label_source":"assigner_model","first_document_title":"North Korean cybercriminals use AI coding agent to enhance phishing attacks","kind":"intrusion","first_reported":"2026-09-07T00:00:00Z","last_reported":"2026-09-07T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["malware","offensive_ops","phishing_social"],"category_counts":{"malware":1,"offensive_ops":1,"phishing_social":1},"named_systems":{"OpenCode":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0423","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0423.json","title":"Iranian state-backed groups use Gemini AI for cyberattacks and disinformation","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Google warns Iran expands AI use in cyberattacks and influence operations","kind":"disclosure","first_reported":"2026-09-08T00:00:00Z","last_reported":"2026-09-08T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","influence_ops","malware","phishing_social"],"category_counts":{"deepfake_fraud":1,"influence_ops":1,"malware":1,"phishing_social":1},"named_systems":{"Gemini":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0422","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0422.json","title":"Threat actors targeting AI coding tools and research for espionage","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI Coding Tools Now a Prime Target for Threat Actors, Google Warns","kind":"disclosure","first_reported":"2026-09-08T00:00:00Z","last_reported":"2026-09-08T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["exploitation","influence_ops","malware","phishing_social"],"category_counts":{"exploitation":1,"influence_ops":1,"malware":1,"phishing_social":1},"named_systems":{"Dustmaker":1,"Gemini":1,"Recon":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0420","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0420.json","title":"North Korea uses generative AI to industrialize cybercrime and social engineering","title_source":"incident_label","label_source":"assigner_model","first_document_title":"For North Korea, AI is a cybercrime force multiplier","kind":"disclosure","first_reported":"2026-09-10T00:00:00Z","last_reported":"2026-09-10T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","offensive_ops","phishing_social"],"category_counts":{"deepfake_fraud":1,"malware":1,"offensive_ops":1,"phishing_social":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0419","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0419.json","title":"CIA identifies Chinese AI and chip firms as intelligence targets","title_source":"incident_label","label_source":"assigner_model","first_document_title":"CIA Names Chinese AI, Chip Firms as Spy Targets; China Threatens US Companies with Espionage Law","kind":"disclosure","first_reported":"2026-09-12T12:31:25Z","last_reported":"2026-09-12T12:31:25Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["subject"],"categories":["incident_disclosure","malware","policy"],"category_counts":{"incident_disclosure":1,"malware":1,"policy":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0418","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0418.json","title":"Individual experiment using guardrail-removed GLM-5.3 to scan home network","title_source":"incident_label","label_source":"assigner_model","first_document_title":"I Let an AI Agent Hack All My Gadgets—and I’d Do It Again","kind":"evaluation_result","first_reported":"2026-09-09T18:30:00Z","last_reported":"2026-09-09T18:30:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["exploitation","malware","offensive_ops","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Astra":1,"Claude Mythos":1,"CyberStrike":1,"GLM-5.3":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0416","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0416.json","title":"OpenAI autonomous agents scraping data from websites","title_source":"incident_label","label_source":"assigner_model","first_document_title":"OpenAI software attempted to secretly scrape data from dozens of prominent websites","kind":"disclosure","first_reported":"2026-10-01T19:25:00Z","last_reported":"2026-10-01T19:25:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["instrument"],"categories":["deepfake_fraud","exploitation","malware","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"exploitation":1,"malware":1,"vuln_discovery":1},"named_systems":{"OpenAI agents (model unspecified)":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0415","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0415.json","title":"Research on LLM safety vulnerabilities via drunk language inducement","title_source":"incident_label","label_source":"assigner_model","first_document_title":"In Vino Veritas and Vulnerabilities: Examining LLM Safety via Drunk Language Inducement","kind":"evaluation_result","first_reported":"2026-10-02T04:00:00Z","last_reported":"2026-10-02T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{"ConfAIde":1,"JailbreakBench":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0414","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0414.json","title":"LLMLeak covert exfiltration via web fetching","title_source":"incident_label","label_source":"assigner_model","first_document_title":"The Innocent Courier: Covert Exfiltration Through Legitimate LLM Web Fetching","kind":"disclosure","first_reported":"2026-10-02T04:00:00Z","last_reported":"2026-10-02T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["instrument"],"categories":["exploitation","malware"],"category_counts":{"exploitation":1,"malware":1},"named_systems":{"LLMLeak":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0413","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0413.json","title":"VideoSTF benchmarking framework for video LLM output repetition","title_source":"incident_label","label_source":"assigner_model","first_document_title":"VideoSTF: Stress-Testing Output Repetition in Video Large Language Models","kind":"evaluation_result","first_reported":"2026-10-02T04:00:00Z","last_reported":"2026-10-02T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{"VideoSTF":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0412","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0412.json","title":"ImMRAG attack for extracting private visual data from multimodal RAG systems","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Walking the Embedding Space: Datastore Extraction from Multimodal RAG","kind":"disclosure","first_reported":"2026-10-02T04:00:00Z","last_reported":"2026-10-02T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{"CLIP":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0411","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0411.json","title":"SRE-Bench reverse engineering benchmark for AI agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"The Next Challenge for Agentic Cybersecurity: A Realistic, Contamination-Free Reverse Engineering Benchmark","kind":"evaluation_result","first_reported":"2026-10-02T04:00:00Z","last_reported":"2026-10-02T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["malware","offensive_ops","vuln_discovery"],"category_counts":{"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Claude Fable 5.1":1,"GPT-5.6 Sol":1,"GPT-6 Astra":1,"SRE-Bench":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0410","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0410.json","title":"A2A-TIBA attack principle and ELA-ITL defense model","title_source":"incident_label","label_source":"assigner_model","first_document_title":"From A2A Attacks to Envelope-Layer Defense: Red-Teaming Evaluation of LLM Agents and a Three-Layer Isomorphic Attack-Defense Model","kind":"evaluation_result","first_reported":"2026-10-02T04:00:00Z","last_reported":"2026-10-02T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["deepfake_fraud","malware","offensive_ops","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"A2A":1,"A2A-TIBA":1,"ACP":1,"ELA-ITL":1,"GDA Measurement":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0409","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0409.json","title":"Bi-QSTO method for poisoning LLMs during fine-tuning","title_source":"incident_label","label_source":"assigner_model","first_document_title":"High-quality Data Do not Mean Safe! Poisoning LLMs after Data Selection","kind":"disclosure","first_reported":"2026-10-02T04:00:00Z","last_reported":"2026-10-02T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse"],"category_counts":{"model_misuse":1},"named_systems":{"Bi-QSTO":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0408","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0408.json","title":"Security vulnerabilities in world models for agentic systems","title_source":"incident_label","label_source":"assigner_model","first_document_title":"False Prophets: On the Security of World Models in Agentic Systems","kind":"disclosure","first_reported":"2026-10-02T04:00:00Z","last_reported":"2026-10-02T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","malware","offensive_ops","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0407","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0407.json","title":"ReGap data-free attack to recover private associations via fine-tuning","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Sleeping Secrets: How Fine-Tuning Reawakens Privacy Risks in Language Models","kind":"disclosure","first_reported":"2026-10-02T04:00:00Z","last_reported":"2026-10-02T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","model_misuse","vuln_discovery"],"category_counts":{"exploitation":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"GPT-2":1,"OPT":1,"Qwen3":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0406","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0406.json","title":"Cross-environment evaluation of hierarchical red team agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"No One Architecture Fits All: A Cross-Environment Evaluation of Hierarchical Red Team Agents","kind":"evaluation_result","first_reported":"2026-10-02T04:00:00Z","last_reported":"2026-10-02T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","offensive_ops","vuln_discovery"],"category_counts":{"evaluation":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"CybORG CAGE 4":1,"CyberWheel":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0405","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0405.json","title":"Few-sample fine-tuning bypasses LLM refusal layers","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Refusal Localizes, the Damage Relocates: Safety Layers Under Few-Sample Fine-Tuning","kind":"disclosure","first_reported":"2026-10-02T04:00:00Z","last_reported":"2026-10-02T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["model_misuse"],"category_counts":{"model_misuse":1},"named_systems":{"Llama 3.1 8B":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0404","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0404.json","title":"LLM safety routing benchmarks fail under distribution shift","title_source":"incident_label","label_source":"assigner_model","first_document_title":"False Floors: LLM Safety Routing Evaluations Break Under Distribution Shift","kind":"evaluation_result","first_reported":"2026-10-02T04:00:00Z","last_reported":"2026-10-02T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","model_misuse","vuln_discovery"],"category_counts":{"evaluation":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"AGENTDOJO":1,"GPT-5.4":1,"HELM Safety":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0403","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0403.json","title":"ROGUE benchmark for evaluating corrigibility failures in computer-use agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"ROGUE: Evaluating Corrigibility Failures in Frontier Computer-Use Agents","kind":"evaluation_result","first_reported":"2026-10-02T04:00:00Z","last_reported":"2026-10-02T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","model_misuse"],"category_counts":{"evaluation":1,"model_misuse":1},"named_systems":{"ROGUE":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0402","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0402.json","title":"Incident-Arena benchmark for AI coding agent reliability","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Incident-Arena: Getting agents to the last nine of reliability","kind":"evaluation_result","first_reported":"2026-10-02T04:00:00Z","last_reported":"2026-10-02T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["incident_disclosure","vuln_discovery"],"category_counts":{"incident_disclosure":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0401","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0401.json","title":"Latent Frequency Masking attack on generative image watermarks","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Exploring Weaknesses of Generative Image Watermarks against Latent Frequency Masking","kind":"disclosure","first_reported":"2026-10-02T04:00:00Z","last_reported":"2026-10-02T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["target"],"categories":["deepfake_fraud","evaluation","model_misuse"],"category_counts":{"deepfake_fraud":1,"evaluation":1,"model_misuse":1},"named_systems":{"DiffusionDB":1,"MS-COCO":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0400","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0400.json","title":"UK AI Safety Institute reports AI agents taking unintended actions during cyber evaluations","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Building a more secure environment for evaluating dangerous capabilities | AISI Work","kind":"disclosure","first_reported":"2026-10-01T00:00:00Z","last_reported":"2026-10-01T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["evaluation","incident_disclosure","model_misuse","offensive_ops"],"category_counts":{"evaluation":1,"incident_disclosure":1,"model_misuse":1,"offensive_ops":1},"named_systems":{"Inspect":1,"SandboxEscapeBench":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0399","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0399.json","title":"Multi-agent framework compromises 85 government accounts","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Why agentic AI is rewriting the rules of cyber defence","kind":"intrusion","first_reported":"2026-10-01T00:00:00Z","last_reported":"2026-10-01T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["instrument"],"categories":["incident_disclosure","offensive_ops","vuln_discovery"],"category_counts":{"incident_disclosure":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0396","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0396.json","title":"AI-generated imagery used in political campaign advertisements","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI blurs lines in campaign ads: ” ̃People are seeing things that didn”t happen”","kind":"disclosure","first_reported":"2026-10-02T20:00:46Z","last_reported":"2026-10-02T20:00:46Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","influence_ops"],"category_counts":{"deepfake_fraud":1,"influence_ops":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0395","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0395.json","title":"Vulnerability in ChatGPT macOS app allowing sensitive data access","title_source":"incident_label","label_source":"assigner_model","first_document_title":"A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data | WIRED","kind":"disclosure","first_reported":"2026-10-02T00:00:00Z","last_reported":"2026-10-02T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["independent_confirmation"],"ai_roles":["target"],"categories":["exploitation","malware","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"vuln_discovery":1},"named_systems":{"ChatGPT":1,"Muse AI":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0394","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0394.json","title":"Hackers hijack security AI agents to leak email data","title_source":"incident_label","label_source":"assigner_model","first_document_title":"When AI Agents Turn on Their Masters: Hackers Lose Email Harvest to Rogue Security Tools","kind":"intrusion","first_reported":"2026-10-02T22:22:15Z","last_reported":"2026-10-02T22:22:15Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["instrument"],"categories":["exploitation","malware","phishing_social","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"phishing_social":1,"vuln_discovery":1},"named_systems":{"CAIRN":1,"Codex":1,"DeepSeek":1,"Hermes Agent":1,"Strix":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0393","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0393.json","title":"OpenAI agents breach US government and UN websites during safety evaluations","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Silicon Valley Insiders Sound Alarm as Rogue AI Agents Breach Government Sites","kind":"intrusion","first_reported":"2026-10-02T21:42:15Z","last_reported":"2026-10-02T21:42:15Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["instrument"],"categories":["offensive_ops","policy","vuln_discovery"],"category_counts":{"offensive_ops":1,"policy":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0392","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0392.json","title":"GitLab AI Gateway command execution vulnerability","title_source":"incident_label","label_source":"assigner_model","first_document_title":"GitLab warns of critical RCE vulnerability in AI Gateway service","kind":"disclosure","first_reported":"2026-10-02T16:20:05Z","last_reported":"2026-10-02T17:33:31Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":2,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["target"],"categories":["exploitation","malware","vuln_discovery"],"category_counts":{"exploitation":2,"malware":2,"vuln_discovery":2},"named_systems":{"GitLab AI Gateway":2,"Duo Agent Platform":1,"GitLab Duo":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0391","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0391.json","title":"WeWorm zero-click worm exploiting WeChat VoIP stack","title_source":"incident_label","label_source":"assigner_model","first_document_title":"WeWorm Spreads Across iOS in Zero-Click Attacks Built in Days Using AI","kind":"disclosure","first_reported":"2026-09-08T00:00:00Z","last_reported":"2026-09-10T12:28:01Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":2,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","malware","soc_defence","vuln_discovery"],"category_counts":{"exploitation":2,"malware":2,"soc_defence":2,"vuln_discovery":2},"named_systems":{"WeChat":2,"Claude Mythos":1,"WeWorm":1,"Weixin":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0390","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0390.json","title":"Indirect prompt injection via hidden HTML in email summarizers","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI summary attack conceals code that tampers with LLMs","kind":"disclosure","first_reported":"2026-09-08T15:00:00Z","last_reported":"2026-09-08T15:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["malware","phishing_social","vuln_discovery"],"category_counts":{"malware":1,"phishing_social":1,"vuln_discovery":1},"named_systems":{"Microsoft 365 Copilot":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0389","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0389.json","title":"Venezuela MOU with iFlytek for AI mass surveillance","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Venezuela could become test case for Chinese AI surveillance, report warns - Cyber Daily","kind":"policy_action","first_reported":"2026-09-09T01:16:13Z","last_reported":"2026-09-09T01:16:13Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["instrument"],"categories":["malware","offensive_ops","policy"],"category_counts":{"malware":1,"offensive_ops":1,"policy":1},"named_systems":{"iFlytek":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0388","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0388.json","title":"AI-enabled phishing campaign targeting US military bases","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Phishing Campaign Targets 99% of US Military Bases During Heightened US-Iran Tensions","kind":"intrusion","first_reported":"2026-09-08T00:00:00Z","last_reported":"2026-09-08T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","offensive_ops","phishing_social"],"category_counts":{"deepfake_fraud":1,"malware":1,"offensive_ops":1,"phishing_social":1},"named_systems":{"GhostCat":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0387","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0387.json","title":"Path traversal in OpenClaw via LLM guardrail bypass","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI SAST Finding: Path Traversal in OpenClaw via LLM Guardrail Bypass | Blog | Endor Labs","kind":"disclosure","first_reported":"2026-09-11T21:16:20Z","last_reported":"2026-09-11T21:16:20Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","malware","model_misuse","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"OpenClaw":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0386","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0386.json","title":"Slopsquatting supply chain attack via AI hallucinations","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Slopsquatting: When AI Agents Hallucinate Malicious Packages | Blog | Endor Labs","kind":"disclosure","first_reported":"2026-09-11T21:16:20Z","last_reported":"2026-09-11T21:16:20Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["instrument"],"categories":["exploitation","malware","soc_defence","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"soc_defence":1,"vuln_discovery":1},"named_systems":{"Claude Code":1,"Cursor":1,"GitHub Copilot":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0385","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0385.json","title":"Workflow identity hijacking in enterprise AI pipelines","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Identity-Based AI Attack Threatens Security of Enterprise Data","kind":"disclosure","first_reported":"2026-09-09T14:39:44Z","last_reported":"2026-09-09T14:39:44Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["exploitation","malware","policy","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"policy":1,"vuln_discovery":1},"named_systems":{"Noma Labs":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0384","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0384.json","title":"Forging Tree-Ring semantic watermark forgery","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Forging Tree-Ring: Reproducing and Instrumenting Black-Box Semantic Watermark Forgery","kind":"disclosure","first_reported":"2026-09-14T04:00:00Z","last_reported":"2026-09-14T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","model_misuse","vuln_discovery"],"category_counts":{"evaluation":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"Stable Diffusion XL":1,"Tree-Ring":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0383","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0383.json","title":"China names Claude and GPT-5.5-Cyber as cyber threats","title_source":"incident_label","label_source":"assigner_model","first_document_title":"China’s state security minister names two US AI models as a cyber threat","kind":"disclosure","first_reported":"2026-09-14T12:16:35Z","last_reported":"2026-09-14T12:16:35Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["subject"],"categories":["malware","offensive_ops","vuln_discovery"],"category_counts":{"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Claude Mythos":1,"GPT 5.5 Cyber":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0381","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0381.json","title":"Threat actors weaponize Claude AI for automated data theft and supply chain attacks","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Active Exploitation Alert: Threat Actors Weaponize Claude AI for Automated Data Theft and Supply Chain Attacks – Rescana","kind":"disclosure","first_reported":"2026-09-14T00:00:00Z","last_reported":"2026-09-14T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","influence_ops","malware","phishing_social"],"category_counts":{"exploitation":1,"influence_ops":1,"malware":1,"phishing_social":1},"named_systems":{"Claude":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0380","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0380.json","title":"OpenAI model discovers and exploits Artifactory zero-day","title_source":"incident_label","label_source":"assigner_model","first_document_title":"OpenAI Says Its Model Found a Zero-Day by Itself, Without Seeing Source Code - DEV Community","kind":"disclosure","first_reported":"2026-09-11T00:00:00Z","last_reported":"2026-09-11T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["exploitation","model_misuse","vuln_discovery"],"category_counts":{"exploitation":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"ExploitGym":1,"GPT-5.6 Sol":1,"Hugging Face":1,"JFrog Artifactory":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0379","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0379.json","title":"AWS Deception Benchmark for AI vulnerability detection","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AWS puts AI vulnerability detection to the test, and false positives pile up - Help Net Security","kind":"evaluation_result","first_reported":"2026-09-14T00:00:00Z","last_reported":"2026-09-14T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["deepfake_fraud","evaluation","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"evaluation":1,"vuln_discovery":1},"named_systems":{"CYBENCH":1,"CyberGym":1,"CyberSecEval":1,"Deception Benchmark":1,"ExploitGym":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0378","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0378.json","title":"Unit 42 investigation of agentic AI-automated ransomware attack","title_source":"incident_label","label_source":"assigner_model","first_document_title":"An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation","kind":"intrusion","first_reported":"2026-09-02T10:00:46Z","last_reported":"2026-09-02T10:00:46Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","incident_disclosure","malware","policy"],"category_counts":{"exploitation":1,"incident_disclosure":1,"malware":1,"policy":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0377","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0377.json","title":"Perturbation probing research on LLM safety neuron fragility","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety","kind":"evaluation_result","first_reported":"2026-08-28T22:00:07Z","last_reported":"2026-08-28T22:00:07Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{"Prisma AIRS Runtime Security":1,"Qwen3-4B":1,"Qwen3.5-2B":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0376","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0376.json","title":"Cyber campaigns in Latin America using commercial LLMs for script generation and data exfiltration","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America","kind":"intrusion","first_reported":"2026-09-03T10:00:58Z","last_reported":"2026-09-03T10:00:58Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","malware","phishing_social"],"category_counts":{"exploitation":1,"malware":1,"phishing_social":1},"named_systems":{"Claude":1,"GPT-4.1":1,"NextChat":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0375","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0375.json","title":"UAT-10147 Chinese-speaking group uses agentic AI for cyber operations","title_source":"incident_label","label_source":"assigner_model","first_document_title":"UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations","kind":"intrusion","first_reported":"2026-08-20T10:00:32Z","last_reported":"2026-08-20T10:00:32Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["evaluation","exploitation","influence_ops","malware"],"category_counts":{"evaluation":1,"exploitation":1,"influence_ops":1,"malware":1},"named_systems":{"DeepAudit":1,"EfsPotato":1,"Gh0stCringe":1,"Metasploit":1,"PentestGPT":1,"QuasarRAT":1,"SPECTRE":1,"ysoserial":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0374","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0374.json","title":"Mythos AI agent discovers OpenBSD kernel signed-integer bug","title_source":"incident_label","label_source":"assigner_model","first_document_title":"The day after the zero-days | APNIC Blog","kind":"disclosure","first_reported":"2026-08-28T00:00:00Z","last_reported":"2026-08-28T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["offensive_ops","vuln_discovery"],"category_counts":{"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Claude Mythos":1,"Claude Opus 4.7":1,"Claude Sonnet 4.6":1,"GLM 5.1":1,"IronCurtain":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0373","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0373.json","title":"Qualys report on frontier AI models autonomously breaching production environments","title_source":"incident_label","label_source":"assigner_model","first_document_title":"The Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwords | Qualys","kind":"intrusion","first_reported":"2026-09-08T00:00:00Z","last_reported":"2026-09-08T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","incident_disclosure","model_misuse","vuln_discovery"],"category_counts":{"exploitation":1,"incident_disclosure":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"Claude Mythos 5":1,"Claude Mythos Preview":1,"Claude Opus 4.7":1,"GPT-5.6 Sol":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0372","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0372.json","title":"OpenAI Astra model discovers zero-day vulnerabilities during benchmark","title_source":"incident_label","label_source":"assigner_model","first_document_title":"OpenAI Astra Brings Autonomous Zero-Day Exploitation to AI","kind":"evaluation_result","first_reported":"2026-09-02T00:00:00Z","last_reported":"2026-09-14T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":5,"distinct_sources":5,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","vendor_claim","analyst_assessment"],"ai_roles":["subject"],"categories":["exploitation","offensive_ops","vuln_discovery"],"category_counts":{"offensive_ops":5,"vuln_discovery":5,"exploitation":4,"model_misuse":1},"named_systems":{"ExploitBench":4,"Astra":3,"GPT-5.6 Sol":3,"GPT-6 Astra":2,"Chrome":1,"Claude":1,"ExploitGym":1,"Node.js":1,"SEC-Bench Pro":1,"SRE-Bench":1,"V8":1},"merged_from":["RL-I-2026-0148"],"corrections":1},{"incident_id":"RL-I-2026-0371","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0371.json","title":"Multi-agent AI system used to execute ransomware attack on enterprise","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Agentic Ransomware Took Down Enterprise in Ten Hours: AI Left 80-Page Audit","kind":"intrusion","first_reported":"2026-09-03T12:18:03Z","last_reported":"2026-09-03T12:18:03Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","incident_disclosure","malware","offensive_ops"],"category_counts":{"exploitation":1,"incident_disclosure":1,"malware":1,"offensive_ops":1},"named_systems":{"Langflow":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0370","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0370.json","title":"CIG-MIA membership inference attack on RAG systems","title_source":"incident_label","label_source":"assigner_model","first_document_title":"CIG-MIA: Context-Induced Information Gain Membership Inference Attacks against Retrieval-Augmented Generation","kind":"disclosure","first_reported":"2026-09-15T04:00:00Z","last_reported":"2026-09-15T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{"CIG-MIA":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0369","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0369.json","title":"Backdoor attacks on latent world models for downstream control","title_source":"incident_label","label_source":"assigner_model","first_document_title":"When the World Lies: Backdoor Attacks on Latent World Models for Downstream Control","kind":"disclosure","first_reported":"2026-09-15T04:00:00Z","last_reported":"2026-09-15T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["target"],"categories":["evaluation","malware","model_misuse","vuln_discovery"],"category_counts":{"evaluation":1,"malware":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"Dreamer":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0368","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0368.json","title":"Persistent Memory Poisoning Attack on harness-based LLM agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"When Malicious Instructions Persist: Persistent Memory Poisoning Attack on Harness-Based Agents","kind":"disclosure","first_reported":"2026-09-15T04:00:00Z","last_reported":"2026-09-15T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["target"],"categories":["malware","model_misuse","vuln_discovery"],"category_counts":{"malware":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"Claude Code":1,"OpenClaw":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0367","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0367.json","title":"SkillSecurer framework for detecting and patching prompt-injection in AI agent skills","title_source":"incident_label","label_source":"assigner_model","first_document_title":"SkillSecurer: Detecting and Patching Prompt-Injection Vulnerabilities in AI Agent Skills","kind":"evaluation_result","first_reported":"2026-09-15T04:00:00Z","last_reported":"2026-09-15T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","malware","offensive_ops","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"SkillSecurer":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0366","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0366.json","title":"AGENTQ framework for quantization-conditioned backdoors in LLM agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AGENTQ: Quantization-Conditioned Backdoor Attacks on LLM Agents","kind":"disclosure","first_reported":"2026-09-15T04:00:00Z","last_reported":"2026-09-15T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["malware","model_misuse","vuln_discovery"],"category_counts":{"malware":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"AGENTQ":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0365","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0365.json","title":"KillBench benchmark for external AI kill switch feasibility","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Can We Stop Malicious AI? KILLBENCH: A Benchmark for External AI Kill Switch Feasibility","kind":"evaluation_result","first_reported":"2026-09-15T04:00:00Z","last_reported":"2026-09-15T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Claude Mythos":1,"GPT-5.2":1,"Gemma4":1,"Grok-4.3":1,"KillBench":1,"OpenClaw":1,"Qwen3.6":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0364","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0364.json","title":"PIDS-Bench benchmark for prompt-injection detectors","title_source":"incident_label","label_source":"assigner_model","first_document_title":"PIDS-Bench: Evaluating Prompt-Injection Detectors Under Over-Defense, Obfuscation, and Distribution Shift","kind":"evaluation_result","first_reported":"2026-09-15T04:00:00Z","last_reported":"2026-09-15T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","offensive_ops","vuln_discovery"],"category_counts":{"evaluation":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"PIDS-Bench":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0363","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0363.json","title":"SynGhost universal backdoor attack via syntactic transfer","title_source":"incident_label","label_source":"assigner_model","first_document_title":"SynGhost: Invisible and Universal Task-agnostic Backdoor Attack via Syntactic Transfer","kind":"disclosure","first_reported":"2026-09-15T04:00:00Z","last_reported":"2026-09-15T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["model_misuse"],"category_counts":{"model_misuse":1},"named_systems":{"SynGhost":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0362","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0362.json","title":"Registration-Time Injection in Centralized Multi-Agent Systems","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Misleading the Planner through Deceptive Resumes: Registration-Time Injection in Centralized Multi-Agent Systems","kind":"disclosure","first_reported":"2026-09-15T04:00:00Z","last_reported":"2026-09-15T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["malware","model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"malware":1,"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"DescGuard":1,"GAIA":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0361","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0361.json","title":"Adversarial testing of Automated Program Repair agents for security vulnerabilities","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Adversarial Testing of Automated Program Repair Agents for Security Vulnerabilities","kind":"evaluation_result","first_reported":"2026-09-15T04:00:00Z","last_reported":"2026-09-15T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["malware","offensive_ops","vuln_discovery"],"category_counts":{"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"DeepSeek-R":1,"GPT-5-Mini":1,"MiniMax-M2.5":1,"SWE-Bench Verified":1,"SWEADV":1,"mini_swe":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0360","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0360.json","title":"Contextual bias injection in LLM-assisted security code review","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Measuring and Exploiting Contextual Bias in LLM-Assisted Security Code Review","kind":"evaluation_result","first_reported":"2026-09-15T04:00:00Z","last_reported":"2026-09-15T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","malware","soc_defence","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"soc_defence":1,"vuln_discovery":1},"named_systems":{"Claude Code":1,"CodeRabbit":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0359","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0359.json","title":"Vulnerability Localization Benchmark (VLoc Bench) for AI agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Vulnerability Localization Benchmark: Measuring Agentic Security Analysis at Repository Scale","kind":"evaluation_result","first_reported":"2026-09-15T04:00:00Z","last_reported":"2026-09-15T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["vuln_discovery"],"category_counts":{"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0358","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0358.json","title":"Semantic Gambit acoustic adversarial attack using LLMs","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Hearing the Unspoken: Language Model Priors for Acoustic Adversarial Attacks","kind":"disclosure","first_reported":"2026-09-15T04:00:00Z","last_reported":"2026-09-15T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["instrument"],"categories":["evaluation","offensive_ops"],"category_counts":{"evaluation":1,"offensive_ops":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0357","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0357.json","title":"CiteShade citation laundering attack on RAG systems","title_source":"incident_label","label_source":"assigner_model","first_document_title":"CiteShade: Citation Laundering in Multi-Source Retrieval-Augmented Generation and Its Counterfactual Defense","kind":"disclosure","first_reported":"2026-09-15T04:00:00Z","last_reported":"2026-09-15T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"CiteShade":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0356","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0356.json","title":"Autonomous agents crossing authorized execution boundaries","title_source":"incident_label","label_source":"assigner_model","first_document_title":"The Missing Boundary: How Autonomous Agents Lose Control","kind":"disclosure","first_reported":"2026-09-15T04:00:00Z","last_reported":"2026-09-15T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0355","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0355.json","title":"BadEngram backdoor attack on gated memory components in LLMs","title_source":"incident_label","label_source":"assigner_model","first_document_title":"BadEngram: Backdoor Attack on Gated Memory Components in LLMs","kind":"disclosure","first_reported":"2026-09-15T04:00:00Z","last_reported":"2026-09-15T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["target"],"categories":["malware","model_misuse","vuln_discovery"],"category_counts":{"malware":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"Engram":1,"Qwen3.8-Flash-Next":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0354","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0354.json","title":"ViTeGate visual-textual triggered knowledge poisoning for VLRAG systems","title_source":"incident_label","label_source":"assigner_model","first_document_title":"ViTeGate: Visual-Textual Triggered Knowledge Poisoning for Vision-Language Retrieval-Augmented Generation","kind":"disclosure","first_reported":"2026-09-15T04:00:00Z","last_reported":"2026-09-15T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{"InfoSeek":1,"ViTeGate":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0352","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0352.json","title":"FBI report on AI-generated voice cloning scams","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI Voice Cloning Scams in 2026: What the FBI's $893M Warning Means for You | CyberFence Blog","kind":"disclosure","first_reported":"2026-09-25T00:00:00Z","last_reported":"2026-09-25T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social","soc_defence"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1,"soc_defence":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0351","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0351.json","title":"AI coding agents leak corporate secrets to public GitHub repositories","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI Coding Agents Are Publishing Your Company's Secrets to GitHub - Gadget Review","kind":"disclosure","first_reported":"2026-10-01T00:42:20Z","last_reported":"2026-10-01T00:42:20Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","malware","policy","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"policy":1,"vuln_discovery":1},"named_systems":{"gitshot":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0350","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0350.json","title":"NYC Council subpoena to SpaceXAI regarding AI safety breaches","title_source":"incident_label","label_source":"assigner_model","first_document_title":"NYC Council First to Compel AI Testimony Under Oath as Congress Stays Blocked","kind":"policy_action","first_reported":"2026-09-30T23:58:21Z","last_reported":"2026-09-30T23:58:21Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["incident_disclosure","policy","vuln_discovery"],"category_counts":{"incident_disclosure":1,"policy":1,"vuln_discovery":1},"named_systems":{"Claude":1,"Hugging Face":1,"SpaceXAI":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0349","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0349.json","title":"White House and tech giants sign voluntary AI safety accord","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Trump, Tech Giants Strike Voluntary AI Safety Accord","kind":"policy_action","first_reported":"2026-09-30T20:51:15Z","last_reported":"2026-09-30T20:51:15Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["defender"],"categories":["policy"],"category_counts":{"policy":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0348","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0348.json","title":"GraphToxin method for reconstructing unlearned graphs from GNNs","title_source":"incident_label","label_source":"assigner_model","first_document_title":"GraphToxin: Reconstructing Full Unlearned Graphs from Graph Unlearning","kind":"disclosure","first_reported":"2026-10-01T04:00:00Z","last_reported":"2026-10-01T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["target"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{"GraphToxin":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0347","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0347.json","title":"APTInvestBench benchmark for LLM agent APT investigation","title_source":"incident_label","label_source":"assigner_model","first_document_title":"APTInvestBench: Evaluating Autonomous APT Investigation under Varying Telemetry","kind":"evaluation_result","first_reported":"2026-10-01T04:00:00Z","last_reported":"2026-10-01T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["malware","offensive_ops","soc_defence","vuln_discovery"],"category_counts":{"malware":1,"offensive_ops":1,"soc_defence":1,"vuln_discovery":1},"named_systems":{"APTInvestBench":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0346","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0346.json","title":"Aletheia framework for prompt injection testing in coding agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Aletheia: Permission-Minimality Testing for Coding-Agent Rules","kind":"evaluation_result","first_reported":"2026-10-01T04:00:00Z","last_reported":"2026-10-01T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["defender"],"categories":["malware","policy","vuln_discovery"],"category_counts":{"malware":1,"policy":1,"vuln_discovery":1},"named_systems":{"AIShellJack":1,"Aletheia":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0345","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0345.json","title":"Adversarial attacks and backdoors in Vision-Language-Action models for robotics","title_source":"incident_label","label_source":"assigner_model","first_document_title":"DropVLA: An Action-Level Backdoor Attack on Vision-Language-Action Models","kind":"disclosure","first_reported":"2026-09-14T04:00:00Z","last_reported":"2026-10-01T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":1,"coverage":"one_source","evidence_classes":["vendor_claim"],"ai_roles":["target"],"categories":["malware","model_misuse","vuln_discovery"],"category_counts":{"model_misuse":2,"vuln_discovery":2,"malware":1},"named_systems":{"LIBERO":1,"OpenVLA-7B":1,"Pi0":1,"RDT":1,"pi0-fast":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0344","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0344.json","title":"CodeMimicry framework for inducing harmful outputs from LLMs via structured code prompts","title_source":"incident_label","label_source":"assigner_model","first_document_title":"CodeMimicry: Exploiting Safety Generalization Lag in Large Language Models via Structured Code Completion","kind":"evaluation_result","first_reported":"2026-10-01T04:00:00Z","last_reported":"2026-10-01T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","model_misuse","vuln_discovery"],"category_counts":{"exploitation":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0343","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0343.json","title":"VirusCascade vulnerability in LLM-powered recommender agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"VirusCascade: Hijacking Collaborative Reflection in LLM-Powered Recommender Agents","kind":"disclosure","first_reported":"2026-10-01T04:00:00Z","last_reported":"2026-10-01T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["influence_ops","malware","model_misuse","vuln_discovery"],"category_counts":{"influence_ops":1,"malware":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"VirusCascade":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0342","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0342.json","title":"SMARTCAN and GANCAN evasion attacks on behavior-based driver authentication","title_source":"incident_label","label_source":"assigner_model","first_document_title":"When Authentication Is Not Enough: Breaking Behavior-Based Driver Authentication Systems","kind":"disclosure","first_reported":"2026-10-01T04:00:00Z","last_reported":"2026-10-01T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","vuln_discovery"],"category_counts":{"evaluation":1,"vuln_discovery":1},"named_systems":{"GANCAN":1,"SMARTCAN":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0341","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0341.json","title":"TrustProbe framework for identifying vulnerabilities in skill-based LLM agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Can Agents Trust Their Skills? Uncovering Unsafe Chains of Trust in Skill-Based LLM Agents","kind":"evaluation_result","first_reported":"2026-10-01T04:00:00Z","last_reported":"2026-10-01T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","malware","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"vuln_discovery":1},"named_systems":{"ClawHub":1,"TrustProbe":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0340","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0340.json","title":"LLM agents covertly leak credentials in multi-agent systems","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Covert Assistance: Helpful LLM Agents Evade Oversight in Multi-Agent Systems","kind":"disclosure","first_reported":"2026-10-01T04:00:00Z","last_reported":"2026-10-01T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["malware","model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"malware":1,"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"DeepSeek V4 Pro":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0339","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0339.json","title":"Pretext framework for evading malicious skill detection in AI agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Pretext: Defeating Malicious Skill Detection Frameworks for AI Agents","kind":"evaluation_result","first_reported":"2026-10-01T04:00:00Z","last_reported":"2026-10-01T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","offensive_ops","vuln_discovery"],"category_counts":{"evaluation":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Claude Code":1,"OpenClaw":1,"Pretext":1,"SkillSpector":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0338","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0338.json","title":"SparLeak: GPU micro-architectural side channel in sparse attention LLM inference","title_source":"incident_label","label_source":"assigner_model","first_document_title":"SparLeak: Privacy Leakage from Sparse Attention in LLM Inference on Shared GPUs","kind":"disclosure","first_reported":"2026-10-01T04:00:00Z","last_reported":"2026-10-01T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["target"],"categories":["malware","model_misuse","policy","vuln_discovery"],"category_counts":{"malware":1,"model_misuse":1,"policy":1,"vuln_discovery":1},"named_systems":{"SparLeak":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0337","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0337.json","title":"SceneJail framework for jailbreaking multimodal LLMs via video context","title_source":"incident_label","label_source":"assigner_model","first_document_title":"SceneJail: Exploiting Video Scenario Context to Jailbreak Multimodal LLMs","kind":"evaluation_result","first_reported":"2026-10-01T04:00:00Z","last_reported":"2026-10-01T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse"],"category_counts":{"model_misuse":1},"named_systems":{"GPT-4.1":1,"Gemini3.5-Flash":1,"HADES":1,"SafeBench":1,"SceneJail":1,"SceneJail-F":1,"SceneJail-S":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0336","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0336.json","title":"Optimization-Triggered Backdoor Attacks on LLMs","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Trusted Weights, Treacherous Optimizations? Optimization-Triggered Backdoor Attacks on LLMs","kind":"disclosure","first_reported":"2026-10-01T04:00:00Z","last_reported":"2026-10-01T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0335","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0335.json","title":"Decoupled skill poisoning in LLM agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Hiding in Plain Sight: Decoupling Pretext from Actuation for Skill Poisoning in LLM Agents","kind":"disclosure","first_reported":"2026-10-01T04:00:00Z","last_reported":"2026-10-01T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["exploitation","malware","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"vuln_discovery":1},"named_systems":{"CoordPoison":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0334","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0334.json","title":"AgentSnare system for diverting autonomous penetration agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AgentSnare: Learning to Delay, Divert, and Defuse Autonomous Penetration Agents","kind":"evaluation_result","first_reported":"2026-10-01T04:00:00Z","last_reported":"2026-10-01T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["defender"],"categories":["deepfake_fraud","evaluation","malware","offensive_ops"],"category_counts":{"deepfake_fraud":1,"evaluation":1,"malware":1,"offensive_ops":1},"named_systems":{"AgentSnare":1,"CVE-Bench":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0333","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0333.json","title":"SteerProbe: Learning to Bypass Safety Steering in Vision-Language Models","title_source":"incident_label","label_source":"assigner_model","first_document_title":"SteerProbe: Learning to Bypass Safety Steering in Vision-Language Models","kind":"evaluation_result","first_reported":"2026-10-01T04:00:00Z","last_reported":"2026-10-01T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"SteerProbe":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0332","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0332.json","title":"TACTIC framework for multimodal LLM-coordinated LiDAR attacks","title_source":"incident_label","label_source":"assigner_model","first_document_title":"TACTIC: Temporal and Context-Aware LLM Tactical Planning for Roadside LiDAR Attacks","kind":"evaluation_result","first_reported":"2026-10-01T04:00:00Z","last_reported":"2026-10-01T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","offensive_ops","vuln_discovery"],"category_counts":{"evaluation":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"CARLA":1,"TACTIC":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0331","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0331.json","title":"HealBench and HealGuard benchmark and safety framework for LLM-based runtime error healing","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Trustworthy Runtime Error Healing in Real-World Repositories: A Benchmark and Guardrail","kind":"evaluation_result","first_reported":"2026-10-01T04:00:00Z","last_reported":"2026-10-01T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["defender"],"categories":["exploitation","incident_disclosure","malware","vuln_discovery"],"category_counts":{"exploitation":1,"incident_disclosure":1,"malware":1,"vuln_discovery":1},"named_systems":{"HealBench":1,"HealCore":1,"HealGuard":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0330","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0330.json","title":"Google Threat Intelligence report on AI research agents discovering exploitable vulnerabilities","title_source":"incident_label","label_source":"assigner_model","first_document_title":"The vulnerabilities AI finds are the ones attackers want","kind":"disclosure","first_reported":"2026-10-01T05:00:35Z","last_reported":"2026-10-01T05:00:35Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["exploitation","malware","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"vuln_discovery":1},"named_systems":{"Flowise":1,"Hacktron":1,"Langflow":1,"LiteLLM":1,"Ollama":1,"vLLM":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0329","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0329.json","title":"AI-powered disinformation campaign in Malaysia","title_source":"incident_label","label_source":"assigner_model","first_document_title":"How AI could ’supercharge’ election risks across south-east Asia","kind":"intrusion","first_reported":"2026-10-01T11:58:40Z","last_reported":"2026-10-01T11:58:40Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","evaluation","influence_ops"],"category_counts":{"deepfake_fraud":1,"evaluation":1,"influence_ops":1},"named_systems":{"Claude":1,"Malaysia Pulse":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0328","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0328.json","title":"Executive Order 14409 on AI cyber defense","title_source":"incident_label","label_source":"assigner_model","first_document_title":"EO 14409: Frontier Models as Cyber Defense — CASRAI","kind":"policy_action","first_reported":"2026-09-25T00:00:00Z","last_reported":"2026-09-25T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["defender"],"categories":["offensive_ops","policy","vuln_discovery"],"category_counts":{"offensive_ops":1,"policy":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0327","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0327.json","title":"Google launches Gemini 4 Argon for cyber defenders","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Google's new frontier AI model Gemini 4 Argon goes to cybersecurity defenders first - SiliconANGLE","kind":"disclosure","first_reported":"2026-09-30T00:00:00Z","last_reported":"2026-10-02T06:12:00Z","first_reported_basis":"published_at","event_date":null,"document_count":5,"distinct_sources":5,"coverage":"multiple_sources","evidence_classes":["vendor_claim"],"ai_roles":["defender","subject"],"categories":["malware","offensive_ops","vuln_discovery"],"category_counts":{"vuln_discovery":4,"malware":3,"offensive_ops":3,"exploitation":2,"model_misuse":1},"named_systems":{"Gemini 4 Argon":5,"GPT-6 Astra":3,"Claude Fable 5":1,"Claude Mythos Preview":1,"Claude Opus 5.5":1,"DeepSeek":1,"Dots":1,"Fairwind Program":1,"Gemini 3.8 Flash Cyber":1,"Grok 4.7":1,"Muse":1,"Spark":1},"merged_from":["RL-I-2026-0321","RL-I-2026-0398"],"corrections":2},{"incident_id":"RL-I-2026-0326","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0326.json","title":"AI deepfake fraud involving employee transfer","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI Deepfake Fraud Raises Liability Stakes for Banks and Business","kind":"intrusion","first_reported":"2026-09-30T00:00:00Z","last_reported":"2026-09-30T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social","soc_defence"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1,"soc_defence":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0325","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0325.json","title":"UK government warns of China-linked AI research espionage","title_source":"incident_label","label_source":"assigner_model","first_document_title":"UK accuses China of using academics to spy on AI and other tech research | CNN","kind":"disclosure","first_reported":"2026-09-30T00:00:00Z","last_reported":"2026-10-02T11:22:16Z","first_reported_basis":"published_at","event_date":null,"document_count":4,"distinct_sources":4,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","analyst_assessment"],"ai_roles":["instrument","subject","target"],"categories":["exploitation","malware","phishing_social","policy"],"category_counts":{"malware":4,"policy":4,"exploitation":2,"phishing_social":2,"evaluation":1},"named_systems":{"China Academy of General Technology":2,"China General Technology Research Institute":2},"merged_from":["RL-I-2026-0397"],"corrections":1},{"incident_id":"RL-I-2026-0324","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0324.json","title":"OpenAI disrupts Moonshot AI reasoning extraction campaign","title_source":"incident_label","label_source":"assigner_model","first_document_title":"OpenAI Disrupts Coordinated Model-Reasoning Extraction Campaign","kind":"intrusion","first_reported":"2026-09-30T00:00:00Z","last_reported":"2026-10-01T10:42:36Z","first_reported_basis":"published_at","event_date":null,"document_count":5,"distinct_sources":5,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","vendor_claim"],"ai_roles":["instrument","target"],"categories":["model_misuse"],"category_counts":{"model_misuse":5},"named_systems":{"Kimi":4,"Claude":2,"GPT":2,"ChatGPT":1,"Claude Fable 5":1,"GPT-4o":1,"Gemini":1,"Grok":1,"Kimi K3":1,"Kimi-K2":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0323","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0323.json","title":"OpenAI agent breach of Australian healthcare database","title_source":"incident_label","label_source":"assigner_model","first_document_title":"This month in security with Tony Anscombe – September 2026 edition","kind":"intrusion","first_reported":"2026-09-30T08:00:00Z","last_reported":"2026-09-30T08:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["instrument"],"categories":["offensive_ops","vuln_discovery"],"category_counts":{"offensive_ops":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0322","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0322.json","title":"Ridge Security benchmark on AI-driven penetration testing effectiveness","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Why the smartest LLMs are not-so-smart pen testers","kind":"evaluation_result","first_reported":"2026-10-01T15:00:00Z","last_reported":"2026-10-01T15:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["evaluation","offensive_ops","vuln_discovery"],"category_counts":{"evaluation":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Claude Opus 4.6":1,"GPT-OSS-120B":1,"Gemini 3 Flash":1,"Grok 4.5":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0320","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0320.json","title":"AI agents conduct password spraying and SQL injection against Canadian federal systems","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI Agent Attacks Hit Canadian Federal Systems in 2024 Using Password Spraying and SQL Injection","kind":"intrusion","first_reported":"2026-10-01T20:12:16Z","last_reported":"2026-10-01T20:12:16Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["instrument"],"categories":["exploitation","malware","offensive_ops"],"category_counts":{"exploitation":1,"malware":1,"offensive_ops":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0319","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0319.json","title":"China-linked hackers impersonate officials and Anthropic employee to target AI experts","title_source":"incident_label","label_source":"assigner_model","first_document_title":"State-linked actor targets US AI policy experts in credential phishing campaigns | Cybersecurity Dive","kind":"intrusion","first_reported":"2026-10-01T00:00:00Z","last_reported":"2026-10-04T07:20:32Z","first_reported_basis":"published_at","event_date":null,"document_count":18,"distinct_sources":18,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","analyst_assessment"],"ai_roles":["instrument","target"],"categories":["malware","phishing_social","policy"],"category_counts":{"malware":18,"phishing_social":18,"policy":11,"deepfake_fraud":6,"exploitation":5,"evaluation":4,"influence_ops":3},"named_systems":{"Claude":10,"Frameless BitB":4,"Microsoft 365":2,"Cloudflare Turnstile":1,"Entra ID":1,"OfficeHome":1,"OneDrive":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0318","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0318.json","title":"AI-powered zero-day chain and model inspection RCE","title_source":"incident_label","label_source":"assigner_model","first_document_title":"ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories","kind":"disclosure","first_reported":"2026-10-01T16:45:38Z","last_reported":"2026-10-01T16:45:38Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["instrument"],"categories":["exploitation","malware","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0317","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0317.json","title":"Chinese hacking campaigns targeting AI firms and Asian governments","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Researchers find Chinese hacking campaigns targeting AI firms, Asian governments","kind":"intrusion","first_reported":"2026-10-01T18:16:00Z","last_reported":"2026-10-01T18:16:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","malware","phishing_social","policy"],"category_counts":{"exploitation":1,"malware":1,"phishing_social":1,"policy":1},"named_systems":{"Antino":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0316","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0316.json","title":"Rubric-Induced Preference Drift (RIPD) vulnerability in LLM judges","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Rubrics as an Attack Surface: Stealthy Preference Drift in LLM Judges","kind":"disclosure","first_reported":"2026-09-15T04:00:00Z","last_reported":"2026-09-15T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0315","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0315.json","title":"Plan injection attack to evade chain-of-thought monitoring","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Corrupt Plans, Clean Traces: Evading Chain-of-Thought Monitoring with Plan Injection","kind":"disclosure","first_reported":"2026-09-15T04:00:00Z","last_reported":"2026-09-15T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","model_misuse"],"category_counts":{"evaluation":1,"model_misuse":1},"named_systems":{"DeepSeek R1":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0314","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0314.json","title":"Overflip vulnerability in lightweight guardrail models","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Overflip: Repetition-Induced Label Flips in Guardrail Models","kind":"disclosure","first_reported":"2026-09-15T04:00:00Z","last_reported":"2026-09-15T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["target"],"categories":["evaluation","model_misuse","vuln_discovery"],"category_counts":{"evaluation":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"DeBERTa":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0313","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0313.json","title":"K-Bench benchmark for high-risk mental health conversations","title_source":"incident_label","label_source":"assigner_model","first_document_title":"K-Bench: a clinically calibrated benchmark for evaluating large language models in high-risk mental health conversations","kind":"evaluation_result","first_reported":"2026-09-15T04:00:00Z","last_reported":"2026-09-15T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["evaluation","model_misuse"],"category_counts":{"evaluation":1,"model_misuse":1},"named_systems":{"GPT-4o":1,"K-Bench":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0311","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0311.json","title":"Threat actor uses multi-agent framework to automate intrusion and credential harvesting","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Hackers Deploy Agentic AI to Automate Exploitation and Mass Credential Harvesting","kind":"intrusion","first_reported":"2026-09-15T07:46:50Z","last_reported":"2026-09-15T07:46:50Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","influence_ops","malware","phishing_social"],"category_counts":{"exploitation":1,"influence_ops":1,"malware":1,"phishing_social":1},"named_systems":{"Recon":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0309","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0309.json","title":"Langflow RCE vulnerability exploitation","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise","kind":"intrusion","first_reported":"2026-09-01T20:48:00Z","last_reported":"2026-09-01T20:48:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["target"],"categories":["exploitation","incident_disclosure","malware","vuln_discovery"],"category_counts":{"exploitation":1,"incident_disclosure":1,"malware":1,"vuln_discovery":1},"named_systems":{"Langflow":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0308","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0308.json","title":"Manhattan DA seizes 12 AI deepfake porn websites","title_source":"incident_label","label_source":"assigner_model","first_document_title":"New York Seizes a Dozen Celebrity Deepfake Websites | WIRED","kind":"intrusion","first_reported":"2026-09-14T00:00:00Z","last_reported":"2026-09-15T12:42:00Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":2,"coverage":"multiple_sources","evidence_classes":["independent_confirmation","threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","policy"],"category_counts":{"deepfake_fraud":2,"malware":2,"policy":2},"named_systems":{"Azure OpenAI":1,"Grok":1,"MrDeepFakes":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0307","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0307.json","title":"AI-generated code used to target water and wastewater systems","title_source":"incident_label","label_source":"assigner_model","first_document_title":"'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers","kind":"intrusion","first_reported":"2026-08-19T00:00:00Z","last_reported":"2026-08-19T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["influence_ops","malware","vuln_discovery"],"category_counts":{"influence_ops":1,"malware":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0306","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0306.json","title":"AI voice cloning scams targeting family emergency calls","title_source":"incident_label","label_source":"assigner_model","first_document_title":"That Call From Your Family Member Could Be an AI Voice Scam","kind":"intrusion","first_reported":"2026-09-06T17:46:00Z","last_reported":"2026-09-11T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":2,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","commentary"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social","vuln_discovery"],"category_counts":{"deepfake_fraud":2,"vuln_discovery":2,"malware":1,"phishing_social":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0305","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0305.json","title":"Threat actors targeting AI assets for model distillation and automated attacks","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Threat actors are coming for your AI assets to operationalize their use of AI","kind":"disclosure","first_reported":"2026-09-15T00:00:00Z","last_reported":"2026-09-15T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","influence_ops","malware","model_misuse"],"category_counts":{"exploitation":1,"influence_ops":1,"malware":1,"model_misuse":1},"named_systems":{"Gemini":1,"Recon":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0304","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0304.json","title":"AI voice cloning scam targeting Michigan homebuyers","title_source":"incident_label","label_source":"assigner_model","first_document_title":"How two homebuyers in Michigan lost $66,000 in a suspected voice-cloning scam | CNN","kind":"intrusion","first_reported":"2026-09-15T00:00:00Z","last_reported":"2026-09-15T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social","soc_defence"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1,"soc_defence":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0303","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0303.json","title":"iLands platform used to deploy autonomous AI spam agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI Agent Platform Reinvents Spam, Floods Inboxes Worldwide","kind":"intrusion","first_reported":"2026-09-15T20:08:56Z","last_reported":"2026-09-15T20:08:56Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1},"named_systems":{"iLands":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0302","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0302.json","title":"AI voice cloning scams in India","title_source":"incident_label","label_source":"assigner_model","first_document_title":"83 pc of AI voice scam victims in India suffer financial losses","kind":"intrusion","first_reported":"2026-08-23T00:00:00Z","last_reported":"2026-08-23T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0301","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0301.json","title":"AI-enhanced phishing campaign targeting enterprise users","title_source":"incident_label","label_source":"assigner_model","first_document_title":"The Rise of AI-Enhanced Phishing and Cloud Identity Theft | by SOCFortress | Sep, 2026 | Medium","kind":"intrusion","first_reported":"2026-09-14T18:56:44Z","last_reported":"2026-09-14T18:56:44Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["instrument"],"categories":["incident_disclosure","malware","phishing_social"],"category_counts":{"incident_disclosure":1,"malware":1,"phishing_social":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0300","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0300.json","title":"Luciferus uncensored AI sold on hacking forum","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Uncensored AI sold on hacking forum as alternative to ChatGPT and Claude jailbreaks - Help Net Security","kind":"disclosure","first_reported":"2026-09-15T00:00:00Z","last_reported":"2026-09-15T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["evaluation","malware","offensive_ops"],"category_counts":{"evaluation":1,"malware":1,"offensive_ops":1},"named_systems":{"ChatGPT":1,"Claude":1,"Luciferus":1,"Qwen":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0299","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0299.json","title":"AI-generated fake income documents for rental fraud","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Podcast: How AI Is Making Rental Application Fraud Harder to Catch, with Docuverus","kind":"disclosure","first_reported":"2026-09-15T17:25:01Z","last_reported":"2026-09-15T17:25:01Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social","policy"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1,"policy":1},"named_systems":{"Docuverus":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0298","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0298.json","title":"Autonomous AI agents exhibit deceptive behaviors in simulated environment","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI agents lied, stole in simulated experiment, researchers say","kind":"evaluation_result","first_reported":"2026-09-15T16:33:00Z","last_reported":"2026-09-15T16:33:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["deepfake_fraud","malware","phishing_social","policy"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1,"policy":1},"named_systems":{"ChatGPT":1,"Claude":1,"Gemini":1,"Grok":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0297","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0297.json","title":"InceptionRAG poisoning attack on Retrieval-Augmented Generation","title_source":"incident_label","label_source":"assigner_model","first_document_title":"InceptionRAG: Stealthy Poisoning Attack Against Retrieval-Augmented Generation","kind":"disclosure","first_reported":"2026-09-16T04:00:00Z","last_reported":"2026-09-16T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"HODOR":1,"InceptionRAG":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0296","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0296.json","title":"AiSPY parasitic Trojan for machine learning infrastructure","title_source":"incident_label","label_source":"assigner_model","first_document_title":"(A)iSpy: Parasitic Trojans for Machine Learning Infrastructure","kind":"disclosure","first_reported":"2026-09-16T04:00:00Z","last_reported":"2026-09-16T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["target"],"categories":["malware","model_misuse","vuln_discovery"],"category_counts":{"malware":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"AiSPY":1,"ONNX Runtime":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0295","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0295.json","title":"White-box undetectable backdoor for Random Fourier Features","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Implementing a White-Box Undetectable Backdoor for Random Fourier Features","kind":"disclosure","first_reported":"2026-09-16T04:00:00Z","last_reported":"2026-09-16T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["target"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{"Random Fourier Features":1,"numpy":1,"scipy":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0294","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0294.json","title":"Stereo vision and depth estimation model vulnerability to repeating patterns","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Illusion of Depth: Revealing Hidden Stereo Vision Vulnerabilities in Depth Estimation","kind":"disclosure","first_reported":"2026-09-16T04:00:00Z","last_reported":"2026-09-16T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["target"],"categories":["deepfake_fraud","evaluation","malware","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"evaluation":1,"malware":1,"vuln_discovery":1},"named_systems":{"BM":1,"CARLA":1,"Intel RealSense D435":1,"MoCha-Stereo":1,"PSMNet":1,"SGBM":1,"SGM-DDC":1,"UniMatch":1,"ZED2":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0293","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0293.json","title":"Runaway AI agent execution loop causes $50,000 cloud bill","title_source":"incident_label","label_source":"assigner_model","first_document_title":"One runaway AI agent racked up a $50,000 cloud bill - Help Net Security","kind":"intrusion","first_reported":"2026-09-16T00:00:00Z","last_reported":"2026-09-16T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["malware","policy","soc_defence","vuln_discovery"],"category_counts":{"malware":1,"policy":1,"soc_defence":1,"vuln_discovery":1},"named_systems":{"GitHub":1,"OpenClaw":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0292","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0292.json","title":"UAC-0099 GuardBreaker technique to evade LLM code scanners","title_source":"incident_label","label_source":"assigner_model","first_document_title":"GuardBreaker: Derailing AI-assisted malware analysis with a code comment","kind":"disclosure","first_reported":"2026-09-10T09:00:00Z","last_reported":"2026-09-14T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":5,"distinct_sources":5,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["target"],"categories":["evaluation","malware"],"category_counts":{"evaluation":5,"malware":5,"exploitation":1,"policy":1},"named_systems":{"MATCHBOIL":4,"GuardBreaker":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0290","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0290.json","title":"Deepfake scam using MP Govindbhai Dholakia video","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Surat MP deepfake scam: Two arrested for using Govindbhai Dholakia video in Rs 9.84 crore fraud - India Today","kind":"intrusion","first_reported":"2026-09-16T00:00:00Z","last_reported":"2026-09-16T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1},"named_systems":{"ChatGPT":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0289","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0289.json","title":"AI deepfake fraud using Tamil Nadu CM Vijay videos","title_source":"incident_label","label_source":"assigner_model","first_document_title":"CM Vijay deepfake videos show him promising financial aid, Rajasthan man arrested - India Today","kind":"intrusion","first_reported":"2026-09-14T00:00:00Z","last_reported":"2026-09-16T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":2,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social"],"category_counts":{"deepfake_fraud":2,"malware":2,"phishing_social":2},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0287","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0287.json","title":"Anthropic reports GLM-5.3 autonomous exploit development","title_source":"incident_label","label_source":"assigner_model","first_document_title":"GLM-5.3 and the spread of advanced cyber capabilities","kind":"disclosure","first_reported":"2026-09-29T00:00:00Z","last_reported":"2026-10-01T22:00:54Z","first_reported_basis":"published_at","event_date":null,"document_count":3,"distinct_sources":3,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"offensive_ops":3,"vuln_discovery":3,"exploitation":2,"model_misuse":2,"malware":1},"named_systems":{"GLM-5.3":3,"Claude":1,"Claude Mythos Preview":1,"Claude Opus 4.6":1,"ExploitBench":1,"GLM 5.2":1,"GLM-5.3-Flash":1,"HARMBENCH":1,"JailbreakBench":1,"Kimi":1,"StrongREJECT":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0286","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0286.json","title":"XBOW autonomous research system discovers Linux kernel vulnerability CVE-2026-72018","title_source":"incident_label","label_source":"assigner_model","first_document_title":"No Time to Pwn: CVE-2026-72018 Linux Kernel LPE | XBOW","kind":"disclosure","first_reported":"2026-09-28T00:00:00Z","last_reported":"2026-09-28T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["exploitation","malware","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"vuln_discovery":1},"named_systems":{"XBOW":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0285","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0285.json","title":"Unsloth Studio arbitrary code execution vulnerability","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution","kind":"disclosure","first_reported":"2026-09-29T21:08:42Z","last_reported":"2026-09-29T21:08:42Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["target"],"categories":["malware","model_misuse","vuln_discovery"],"category_counts":{"malware":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"Hugging Face":1,"Transformers":1,"Unsloth Studio":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0284","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0284.json","title":"WaterPlum group uses AI face-swapping and fake jobs to steal cryptocurrency","title_source":"incident_label","label_source":"assigner_model","first_document_title":"North Korean group 'WaterPlum' steals millions in crypto hack - ABC News","kind":"intrusion","first_reported":"2026-09-29T00:00:00Z","last_reported":"2026-09-29T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":2,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","evaluation","malware","phishing_social","soc_defence"],"category_counts":{"deepfake_fraud":2,"malware":2,"evaluation":1,"phishing_social":1,"soc_defence":1},"named_systems":{"BeaverTail":1,"InvisibleFerret":1,"OtterCandy":1,"OtterCookie":1,"StoatWaffle":1,"WaterPlum":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0283","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0283.json","title":"BadRAG: Vulnerabilities in Retrieval Augmented Generation","title_source":"incident_label","label_source":"assigner_model","first_document_title":"BadRAG: Identifying Vulnerabilities in Retrieval Augmented Generation of Large Language Models","kind":"disclosure","first_reported":"2026-09-30T04:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["malware","model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"malware":1,"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"BadRAG":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0282","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0282.json","title":"Reserved-Token Representations in Chat-Template Prompt Injection","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Same Bytes, Different Authority: Reserved-Token Representations in Chat-Template Prompt Injection","kind":"disclosure","first_reported":"2026-09-30T04:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"AGENTDOJO":1,"InjecAgent":1,"Llama 3.1":1,"Qwen3-8B":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0280","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0280.json","title":"DARWIN evolutionary framework for LLM jailbreaking and guardrail evaluation","title_source":"incident_label","label_source":"assigner_model","first_document_title":"DARWIN: Evolving Jailbreak Adversary and Guardrail for LLM Safety Evaluation and Protection","kind":"evaluation_result","first_reported":"2026-09-30T04:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["evaluation","model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"evaluation":1,"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"DARWIN":1,"DARWIN-Attack":1,"DARWIN-Guard":1,"DeepSeek V4 Pro":1,"GPT-5.5":1,"LSA":1,"MAGIC":1,"Nemotron":1,"YuFeng-XGuard":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0279","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0279.json","title":"SIREN: PAIR-Driven Preference Manipulation in Web-RAG Recommenders","title_source":"incident_label","label_source":"assigner_model","first_document_title":"SIREN (Luring LLMs onto the Rocks): PAIR-Driven Preference Manipulation in Web-RAG Recommenders","kind":"disclosure","first_reported":"2026-09-30T04:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["influence_ops","model_misuse","vuln_discovery"],"category_counts":{"influence_ops":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"Claude":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0278","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0278.json","title":"MCPTox benchmark for tool poisoning attacks on MCP servers","title_source":"incident_label","label_source":"assigner_model","first_document_title":"MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers","kind":"evaluation_result","first_reported":"2026-09-30T04:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["malware","model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"malware":1,"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Claude-3.7-Sonnet":1,"MCPTox":1,"Model Context Protocol":1,"o1-mini":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0277","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0277.json","title":"TRACE framework for task-aware adaptive self-evolving agentic jailbreaking","title_source":"incident_label","label_source":"assigner_model","first_document_title":"TRACE: Task-Aware Adaptive Self-Evolving Agentic Jailbreaking","kind":"evaluation_result","first_reported":"2026-09-30T04:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"TRACE":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0276","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0276.json","title":"pikit toolkit for indirect prompt injection research","title_source":"incident_label","label_source":"assigner_model","first_document_title":"pikit: A Composable Toolkit for Indirect Prompt Injection Research and Evaluation","kind":"evaluation_result","first_reported":"2026-09-30T04:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["deepfake_fraud","malware","offensive_ops","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"pi coding agent":1,"pikit":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0275","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0275.json","title":"Trojan Hippo Bench for persistent memory attacks in LLM agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Trojan Hippo Bench: A Dynamic Benchmark for Persistent Memory Attacks and Defenses in LLM Agents","kind":"evaluation_result","first_reported":"2026-09-30T04:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","malware","offensive_ops","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"OpenEvolve":1,"Trojan Hippo Bench":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0274","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0274.json","title":"LLM semantic cache poisoning vulnerability","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Similarity Is Not Validity: Defending LLM Semantic Caches Against Poisoning","kind":"disclosure","first_reported":"2026-09-30T04:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0273","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0273.json","title":"FinRT framework for distilling red-teaming strategies into adversarial generators","title_source":"incident_label","label_source":"assigner_model","first_document_title":"FinRT: Distilling Adaptive Red-Teaming Strategies into Reusable Adversarial Generators in Consumer Finance","kind":"evaluation_result","first_reported":"2026-09-30T04:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"FinRT":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0272","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0272.json","title":"Mirage clean-label backdoor in LiDAR 3D object detection","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Mirage: a Clean-Label Backdoor against LiDAR 3D Object Detection","kind":"disclosure","first_reported":"2026-09-30T04:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["target"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{"MIRAGE":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0271","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0271.json","title":"Repeat-After-Me visual prompt injection attack on VLMs","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Repeat-After-Me: Black-Box Adaptive Visual Prompt Injection","kind":"disclosure","first_reported":"2026-09-16T04:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":1,"coverage":"one_source","evidence_classes":["vendor_claim"],"ai_roles":["defender","subject"],"categories":["exploitation","malware","model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":2,"vuln_discovery":2,"exploitation":1,"malware":1,"offensive_ops":1},"named_systems":{"AGENTDOJO":1,"DirectInject":1,"GPT-5.5":1,"OpenClaw":1,"Qwen3.6-27B":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0270","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0270.json","title":"Backdoor in agentic RAG systems via compromised retrievers","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Backdoor in the Loop: Compromising Agentic Search via Malicious Retrievers","kind":"disclosure","first_reported":"2026-09-30T04:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0269","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0269.json","title":"CyberPersistBench evaluation of LLM-based agents on persistence","title_source":"incident_label","label_source":"assigner_model","first_document_title":"CyberPersistBench: Evaluating LLM-Based Cyber Attackers on Installation and Persistence","kind":"evaluation_result","first_reported":"2026-09-30T04:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["malware","offensive_ops","vuln_discovery"],"category_counts":{"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"CyberPersistBench":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0268","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0268.json","title":"JUMP membership inference attack on fine-tuned diffusion language models","title_source":"incident_label","label_source":"assigner_model","first_document_title":"JUMP: Efficient Membership Inference on Fine-Tuned Diffusion Language Models","kind":"disclosure","first_reported":"2026-09-30T04:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{"Dream":1,"LLaDA":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0267","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0267.json","title":"Agentic Commerce Bench for measuring fraud in autonomous agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Agentic Commerce Bench: Measuring Fraud Detection for Agents That Spend Money","kind":"evaluation_result","first_reported":"2026-09-30T04:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["deepfake_fraud","malware","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"malware":1,"vuln_discovery":1},"named_systems":{"Agentic Commerce Bench":1,"gordonguard":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0266","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0266.json","title":"CheatBench benchmark for measuring reward gaming in AI agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"CheatBench: Measuring Reward Gaming in AI Agents","kind":"evaluation_result","first_reported":"2026-09-30T04:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["offensive_ops","vuln_discovery"],"category_counts":{"offensive_ops":1,"vuln_discovery":1},"named_systems":{"CheatBench":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0265","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0265.json","title":"WitnessGym benchmark for coding agents on bug witnesses","title_source":"incident_label","label_source":"assigner_model","first_document_title":"WitnessGym: Benchmarking Coding Agents on the Construction of Bug Witnesses","kind":"evaluation_result","first_reported":"2026-09-30T04:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["offensive_ops","vuln_discovery"],"category_counts":{"offensive_ops":1,"vuln_discovery":1},"named_systems":{"WitnessGym":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0264","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0264.json","title":"Analysis of RAG-based software vulnerability detection systems","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Retrieve, Reproduce, Reveal: Dissecting Retrieval-Augmented Software Vulnerability Detection","kind":"evaluation_result","first_reported":"2026-09-30T04:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["defender"],"categories":["vuln_discovery"],"category_counts":{"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0263","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0263.json","title":"LLM agents evade latent monitors via internal activation edits","title_source":"incident_label","label_source":"assigner_model","first_document_title":"LLMs Learn to Evade Latent Monitors from Prior Feedback Alone","kind":"evaluation_result","first_reported":"2026-09-30T04:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","model_misuse"],"category_counts":{"evaluation":1,"model_misuse":1},"named_systems":{"LoRA":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0262","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0262.json","title":"SCOPE Fuzzer for LLM-based Scientific Reviewers","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Breaking the Illusion of Review Reliability under Static Evaluation: SCOPE Fuzzing for LLM-based Scientific Reviewers","kind":"evaluation_result","first_reported":"2026-09-30T04:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{"SCOPE-Fuzzer":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0261","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0261.json","title":"Divide and Inject: Indirect prompt injection via fragments","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Divide and Inject: Can Agents Reconstruct an Indirect Prompt Injection from Fragments?","kind":"disclosure","first_reported":"2026-09-30T04:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"AgentVigil":1,"OpenEvolve":1,"Trojan Hippo":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0260","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0260.json","title":"ORCA-bench benchmark for LLM agents on root cause analysis","title_source":"incident_label","label_source":"assigner_model","first_document_title":"ORCA-bench: How Ready Are Language Model Agents for Oncall?","kind":"evaluation_result","first_reported":"2026-09-30T04:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["exploitation","incident_disclosure","malware","vuln_discovery"],"category_counts":{"exploitation":1,"incident_disclosure":1,"malware":1,"vuln_discovery":1},"named_systems":{"Claude Fable 5":1,"Grafana":1,"Jaeger":1,"ORCA-bench":1,"OpenSearch":1,"Prometheus":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0259","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0259.json","title":"EquiMem calibration for multi-agent shared memory corruption","title_source":"incident_label","label_source":"assigner_model","first_document_title":"EquiMem: Calibrating Shared Memory in Multi-Agent Debate via Game-Theoretic Equilibrium","kind":"disclosure","first_reported":"2026-09-30T04:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["defender"],"categories":["malware","model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"malware":1,"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"EquiMem":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0258","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0258.json","title":"OpenAI delays GPT-6 Astra due to critical cyber capabilities","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Why did GPT-6 Astra delay its development? The 'Critical' level cyber capabilities that OpenAI was wary of","kind":"disclosure","first_reported":"2026-09-30T00:00:00Z","last_reported":"2026-09-30T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","offensive_ops","vuln_discovery"],"category_counts":{"exploitation":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"ExploitBench":1,"GPT-6 Astra":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0257","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0257.json","title":"RedHerring decoy defense against autonomous vulnerability discovery","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Autonomous Vulnerability Discovery's New Decoy Defense","kind":"evaluation_result","first_reported":"2026-09-30T00:00:00Z","last_reported":"2026-09-30T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":2,"coverage":"multiple_sources","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["deepfake_fraud","evaluation","offensive_ops","vuln_discovery"],"category_counts":{"evaluation":2,"offensive_ops":2,"vuln_discovery":2,"deepfake_fraud":1},"named_systems":{"RedHerring":2,"OSS-Fuzz":1},"merged_from":["RL-I-2026-0281"],"corrections":1},{"incident_id":"RL-I-2026-0256","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0256.json","title":"Deepfake video call theft from engineering firm","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Deepfake defense draws new capital as voice detection checks near 5.5B by 2028","kind":"intrusion","first_reported":"2026-09-29T00:00:00Z","last_reported":"2026-09-29T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["subject"],"categories":["deepfake_fraud","malware","phishing_social","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1,"vuln_discovery":1},"named_systems":{"ChatGPT":1,"Siri":1,"ToxMod":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0255","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0255.json","title":"Cyber Weapon Index benchmark for frontier LLMs","title_source":"incident_label","label_source":"assigner_model","first_document_title":"The Offensive Frontier: AI as the Attacker: A New Cyber Weapon Index and the Strategic Imperative to Accelerate Agentic AI Offense and Defense","kind":"evaluation_result","first_reported":"2026-09-28T00:00:00Z","last_reported":"2026-09-28T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["evaluation","malware","offensive_ops","vuln_discovery"],"category_counts":{"evaluation":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Astra":1,"Claude Mythos":1,"GPT-6 Astra":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0254","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0254.json","title":"AI voice cloning and deepfake video conference fraud","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI Voice Impersonation of Chairman Leads to ₩150 Billion Transfer — Deepfake Financial Fraud Surges — BigGo Finance","kind":"intrusion","first_reported":"2026-09-29T00:00:00Z","last_reported":"2026-09-29T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social","soc_defence"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1,"soc_defence":1},"named_systems":{"Zoom":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0252","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0252.json","title":"NIDS evasion by Model Context Protocol traffic","title_source":"incident_label","label_source":"assigner_model","first_document_title":"When Agents Look Like Beacons: NIDS Evasion by Model Context Protocol Traffic","kind":"disclosure","first_reported":"2026-09-17T04:00:00Z","last_reported":"2026-09-17T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation"],"category_counts":{"evaluation":1},"named_systems":{"Cobalt Strike":1,"Model Context Protocol":1,"RITA":1,"Suricata":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0251","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0251.json","title":"Vision-language models used to defeat reCAPTCHA","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Robot Visions: Breaking reCAPTCHA at Zero Cost and Zero Shot","kind":"disclosure","first_reported":"2026-09-17T04:00:00Z","last_reported":"2026-09-17T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","exploitation","vuln_discovery"],"category_counts":{"evaluation":1,"exploitation":1,"vuln_discovery":1},"named_systems":{"CLIP":1,"OWLv2":1,"reCAPTCHA":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0250","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0250.json","title":"AgentLSD framework for evaluating AI security agents against adversarial task contamination","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AgentLSD: Evaluating AI Security Agents Under Adversarial Task Contamination","kind":"evaluation_result","first_reported":"2026-09-17T04:00:00Z","last_reported":"2026-09-17T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","offensive_ops","vuln_discovery"],"category_counts":{"evaluation":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"AgentLSD":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0249","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0249.json","title":"CacheTrap gray-box Trojan attack on LLMs","title_source":"incident_label","label_source":"assigner_model","first_document_title":"CacheTrap: Unveiling a Stealthier Gray-Box Trojan against LLMs","kind":"disclosure","first_reported":"2026-09-17T04:00:00Z","last_reported":"2026-09-17T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["target"],"categories":["malware","model_misuse","vuln_discovery"],"category_counts":{"malware":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0248","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0248.json","title":"Confidentiality boundary failures in consumer LLM serving systems","title_source":"incident_label","label_source":"assigner_model","first_document_title":"The Illusion of Local Privacy: Confidentiality Boundary Failures in Consumer LLM Serving Systems","kind":"disclosure","first_reported":"2026-09-17T04:00:00Z","last_reported":"2026-09-17T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["target"],"categories":["influence_ops","model_misuse","vuln_discovery"],"category_counts":{"influence_ops":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"LLAnalyzer":1,"llama.cpp":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0247","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0247.json","title":"Poisoned benchmarks trick self-modifying AI coding agents into producing vulnerable code","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Reflections on Trusting Trust, Revisited: Contaminating Self-Modifying AI Coding Agents with Poisoned Benchmarks","kind":"disclosure","first_reported":"2026-09-17T04:00:00Z","last_reported":"2026-09-17T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["malware","model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"malware":1,"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Claude Sonnet 4.5":1,"Darwin Gödel Machine":1,"Hyperagents":1,"Self-Improving Coding Agent":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0246","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0246.json","title":"GPUHammer Rowhammer attacks on NVIDIA GPUs","title_source":"incident_label","label_source":"assigner_model","first_document_title":"GPUHammer: Rowhammer Attacks on GPU Memories are Practical","kind":"disclosure","first_reported":"2026-09-17T04:00:00Z","last_reported":"2026-09-17T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["target"],"categories":["exploitation","malware","model_misuse","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"GDDR6":1,"NVIDIA A6000":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0245","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0245.json","title":"Market Signal Injection attack on LLM pricing agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Market Signal Injection: Adversarial Context Manipulation of LLM Pricing Agents","kind":"disclosure","first_reported":"2026-09-17T04:00:00Z","last_reported":"2026-09-17T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse"],"category_counts":{"model_misuse":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0244","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0244.json","title":"BENCHCOMPASS benchmark for payment-domain LLMs","title_source":"incident_label","label_source":"assigner_model","first_document_title":"BENCHCOMPASS: From Scores to Signals for Training and Harness Decisions in Payment-Domain LLMs","kind":"evaluation_result","first_reported":"2026-09-17T04:00:00Z","last_reported":"2026-09-17T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["evaluation","vuln_discovery"],"category_counts":{"evaluation":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0243","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0243.json","title":"LLMjacking theft of AI API keys and cloud credentials","title_source":"incident_label","label_source":"assigner_model","first_document_title":"LLMjacking: When Stolen AI Tokens Turn Your Account Into Someone Else’s Compute | Lunar Cyber","kind":"disclosure","first_reported":"2026-09-17T00:00:00Z","last_reported":"2026-09-17T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","influence_ops","malware"],"category_counts":{"exploitation":1,"influence_ops":1,"malware":1},"named_systems":{"AWS Bedrock":1,"Claude":1,"Ollama":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0242","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0242.json","title":"BlackHatSect0r and DXQRTXX use AI agent for vishing and credential harvesting","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Hackers Turn AI Agent Into a Cyber Weapon After Deleting Its Safety Refusals","kind":"intrusion","first_reported":"2026-09-17T07:00:10Z","last_reported":"2026-09-17T07:00:10Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1,"vuln_discovery":1},"named_systems":{"DXSCAN":1,"DeepSeek":1,"Nous Research Hermes":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0241","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0241.json","title":"FBI reports on AI-linked voice cloning scams","title_source":"incident_label","label_source":"assigner_model","first_document_title":"FBI says AI-linked scams cost Americans $893 million as 'grandson' voice-clone calls spread","kind":"disclosure","first_reported":"2026-09-17T00:00:00Z","last_reported":"2026-09-17T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social","policy"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1,"policy":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0239","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0239.json","title":"Multi-agent AI framework for automated credential harvesting and vulnerability scanning","title_source":"incident_label","label_source":"assigner_model","first_document_title":"What Recent AI-Powered Attacks Mean for Your Identity Security","kind":"intrusion","first_reported":"2026-09-17T14:01:11Z","last_reported":"2026-09-17T14:01:11Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["incident_disclosure","malware","phishing_social","vuln_discovery"],"category_counts":{"incident_disclosure":1,"malware":1,"phishing_social":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0238","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0238.json","title":"North Korean IT workers use AI and remote desktop tools to fake technical interviews","title_source":"incident_label","label_source":"assigner_model","first_document_title":"North Korean IT Workers Use AI and Remote Desktop Tools to Fake Technical Interviews","kind":"intrusion","first_reported":"2026-09-17T11:56:41Z","last_reported":"2026-09-17T11:56:41Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["instrument"],"categories":["deepfake_fraud","evaluation","malware","phishing_social"],"category_counts":{"deepfake_fraud":1,"evaluation":1,"malware":1,"phishing_social":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0237","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0237.json","title":"Criminal groups use autonomous ransomware operations via escaped AI models","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI Models Broke Their Own Containment: Key Findings from the July-August 2026 AI Threat Landscape - Check Point Blog","kind":"intrusion","first_reported":"2026-09-17T00:00:00Z","last_reported":"2026-09-17T14:41:15Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":2,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","model_misuse","policy","vuln_discovery"],"category_counts":{"deepfake_fraud":2,"malware":2,"vuln_discovery":2,"model_misuse":1,"policy":1},"named_systems":{"Claude Code":2,"Gemini CLI":2,"Hugging Face":2,"JADEPUFFER":1,"LiteLLM":1,"Mastra AI":1,"Microsoft 365 Copilot":1,"OpenAI models (unspecified)":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0236","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0236.json","title":"OpenAI discloses incidents of models hiding errors and unauthorized API usage","title_source":"incident_label","label_source":"assigner_model","first_document_title":"OpenAI Framework Reveals GPT-5.6 Sol Wrote Instructions to Hide Its Own Mistakes","kind":"disclosure","first_reported":"2026-09-17T11:39:28Z","last_reported":"2026-09-17T11:39:28Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["deepfake_fraud","malware","model_misuse","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"malware":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"GPT-5.6 Sol":1,"GPT-6 Astra":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0235","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0235.json","title":"AI models capable of autonomous vulnerability discovery in cryptocurrency infrastructure","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Bitcoin OG Says He Is Watching for Next Major Exploit as AI Models Get Stronger","kind":"disclosure","first_reported":"2026-09-06T00:00:00Z","last_reported":"2026-09-06T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","malware","policy","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"policy":1,"vuln_discovery":1},"named_systems":{"Claude Fable 5.1":1,"ExploitBench":1,"ExploitGym":1,"GPT-5.6 Sol":1,"GPT-6 Astra":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0234","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0234.json","title":"Qilin ransomware group uses LLMs to generate destructive scripts","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Should you care about an “AI slowdown?”","kind":"intrusion","first_reported":"2026-09-17T18:00:23Z","last_reported":"2026-09-17T18:00:23Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","malware","offensive_ops"],"category_counts":{"exploitation":1,"malware":1,"offensive_ops":1},"named_systems":{"AdaptixC2":1,"Qilin":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0233","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0233.json","title":"SynthID-Text watermarking causes sampling drift and increased prompt injection susceptibility","title_source":"incident_label","label_source":"assigner_model","first_document_title":"LLMs respond differently to harmful prompts when AI watermarking is used","kind":"disclosure","first_reported":"2026-09-17T18:33:13Z","last_reported":"2026-09-17T18:33:13Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["malware","model_misuse","policy","vuln_discovery"],"category_counts":{"malware":1,"model_misuse":1,"policy":1,"vuln_discovery":1},"named_systems":{"Claude":1,"SynthID-Text":1,"SynthIDTextWatermarkLogitsProcessor":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0232","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0232.json","title":"Threat actors use AI agents to automate credential harvesting and penetration testing","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Threat actors use AI to automate attacks and target enterprise AI systems - Tech Edition","kind":"disclosure","first_reported":"2026-09-16T00:00:00Z","last_reported":"2026-09-16T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["influence_ops","malware","phishing_social","vuln_discovery"],"category_counts":{"influence_ops":1,"malware":1,"phishing_social":1,"vuln_discovery":1},"named_systems":{"Gemini":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0231","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0231.json","title":"Industrial-scale AI catfishing scam using Claude personas","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Dating App Scam: Proven AI Catfish Warning Signs to Avoid","kind":"intrusion","first_reported":"2026-09-17T00:00:00Z","last_reported":"2026-09-17T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1},"named_systems":{"Claude":1,"Doni":1,"Dora":1,"Jovia":1,"Kira":1,"Nalo":1,"Romi":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0229","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0229.json","title":"Anthropic AI models breach internal security measures","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Anthropic Has Resumed External Cybersecurity Testing. Is That Enough?","kind":"intrusion","first_reported":"2026-09-17T16:00:00Z","last_reported":"2026-09-17T16:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["target"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0228","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0228.json","title":"Inference-Engine Fingerprinting and Sandbox Escape","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Inference-Engine Fingerprinting Attacks are Practical: Exploring Model-Driven Environmental Discovery, Exploitation, and Escape","kind":"disclosure","first_reported":"2026-09-18T04:00:00Z","last_reported":"2026-09-18T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","model_misuse","vuln_discovery"],"category_counts":{"exploitation":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"SGLang":1,"vLLM":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0227","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0227.json","title":"FARSIGHT framework evaluation of financial LLM trading agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"SoK: Trading Agents or Market Crashers? Dissecting Robustness and Security Failures in Academic Financial LLM Trading Schemes","kind":"evaluation_result","first_reported":"2026-09-18T04:00:00Z","last_reported":"2026-09-18T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{"FARSIGHT":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0226","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0226.json","title":"HAE-GEO benchmark for web evidence poisoning in search agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Evaluating Deep-Search Agents under Hierarchical Web Evidence Poisoning","kind":"evaluation_result","first_reported":"2026-09-18T04:00:00Z","last_reported":"2026-09-18T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","model_misuse","vuln_discovery"],"category_counts":{"evaluation":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"HAE-GEO":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0225","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0225.json","title":"AutoMIA framework for automated membership inference attack discovery","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Automated Membership Inference Attacks (AutoMIA): Discovering MIA Signal Computations using LLM Agents","kind":"evaluation_result","first_reported":"2026-09-18T04:00:00Z","last_reported":"2026-09-18T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{"AutoMIA":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0224","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0224.json","title":"Red-teaming study on blocking classifiers for coding agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Red-Teaming Auto Mode: Improving Blocking Classifiers Against Malign Coding Agents","kind":"evaluation_result","first_reported":"2026-09-18T04:00:00Z","last_reported":"2026-09-18T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Claude Code":1,"Codex":1,"Guardian":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0223","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0223.json","title":"Provider-Side Token Inflation Attack (PTIA) audit","title_source":"incident_label","label_source":"assigner_model","first_document_title":"The More It Says, the More You Pay: A Black-Box Audit of Provider-Side Token Inflation in LLM Services","kind":"evaluation_result","first_reported":"2026-09-18T04:00:00Z","last_reported":"2026-09-18T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["malware","policy","vuln_discovery"],"category_counts":{"malware":1,"policy":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0222","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0222.json","title":"ResumeShield benchmark for indirect prompt injection in AI resume screening","title_source":"incident_label","label_source":"assigner_model","first_document_title":"ResumeShield: Channel Separation and an Open Benchmark for Indirect Prompt Injection in AI Resume Screening","kind":"evaluation_result","first_reported":"2026-09-18T04:00:00Z","last_reported":"2026-09-18T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["deepfake_fraud","malware","offensive_ops","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"ResumeShield":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0221","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0221.json","title":"Self-replicating prompt injections in agent workflows","title_source":"incident_label","label_source":"assigner_model","first_document_title":"The Real Threat in AI Security: Instructions That 'Multiply' Rather Than Single Malfunctions","kind":"disclosure","first_reported":"2026-09-25T00:00:00Z","last_reported":"2026-09-25T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["subject"],"categories":["malware","policy","vuln_discovery"],"category_counts":{"malware":1,"policy":1,"vuln_discovery":1},"named_systems":{"Astra":1,"GPT-Red":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0220","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0220.json","title":"Deepfake voice kidnapping scam","title_source":"incident_label","label_source":"assigner_model","first_document_title":"After a deepfake voice fooled her grandfather, this founder sprang into action | TechCrunch","kind":"intrusion","first_reported":"2026-09-28T00:00:00Z","last_reported":"2026-09-28T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1,"vuln_discovery":1},"named_systems":{"DetectifAI":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0219","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0219.json","title":"White House restricts UK AI Safety Institute access to frontier models","title_source":"incident_label","label_source":"assigner_model","first_document_title":"White House Bars UK AI Safety Institute From Frontier AI Testing; CAISI, US Body, Has No Director","kind":"policy_action","first_reported":"2026-09-29T02:22:17Z","last_reported":"2026-09-29T02:22:17Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["subject"],"categories":["evaluation","offensive_ops","policy"],"category_counts":{"evaluation":1,"offensive_ops":1,"policy":1},"named_systems":{"Claude Fable 5":1,"Claude Mythos 5.1":1,"GPT-5.6":1,"GPT-6 Astra":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0218","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0218.json","title":"Storm-3168 AI-orchestrated Azure cloud destruction","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Weekly Security Intelligence Briefing -- Week of 2026-09-28","kind":"intrusion","first_reported":"2026-09-28T11:10:16Z","last_reported":"2026-09-28T11:10:16Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","incident_disclosure","malware","vuln_discovery"],"category_counts":{"exploitation":1,"incident_disclosure":1,"malware":1,"vuln_discovery":1},"named_systems":{"Azure":1,"Check Point Management Server":1,"Citrix NetScaler ADC":1,"Citrix NetScaler Gateway":1,"F5 BIG-IP APM":1,"PyPI":1,"RubyGems":1,"SharePoint":1,"Terraform Registry":1,"npm":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0216","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0216.json","title":"Meta autonomous AI agent bypasses user privacy permissions","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Meta’s Autonomous AI Agent Ignores User Permissions and Accesses Restricted Data","kind":"disclosure","first_reported":"2026-09-29T06:32:16Z","last_reported":"2026-09-29T06:32:16Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["target"],"categories":["deepfake_fraud","policy","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"policy":1,"vuln_discovery":1},"named_systems":{"Meta autonomous agent":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0215","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0215.json","title":"Chinese AI models facilitating cyberattacks on US and Taiwanese infrastructure","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Dark models: AI is making Chinese cyberattacks harder to detect and punish — The Insider","kind":"disclosure","first_reported":"2026-09-28T00:00:00Z","last_reported":"2026-09-28T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["instrument"],"categories":["deepfake_fraud","exploitation","malware","offensive_ops"],"category_counts":{"deepfake_fraud":1,"exploitation":1,"malware":1,"offensive_ops":1},"named_systems":{"Claude Code":1,"DeepSeek":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0214","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0214.json","title":"Neural network weight replacement for medical image exfiltration","title_source":"incident_label","label_source":"assigner_model","first_document_title":"High-Capacity Robust Medical Image Exfiltration via Neural Network Weight Replacement","kind":"disclosure","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["evaluation","exploitation","malware","model_misuse"],"category_counts":{"evaluation":1,"exploitation":1,"malware":1,"model_misuse":1},"named_systems":{"StyleGAN2":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0213","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0213.json","title":"iFinder multi-agent system discovers vulnerabilities in 5G core networks","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Understanding Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and Analysis","kind":"disclosure","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","malware","offensive_ops","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"iFinder":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0212","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0212.json","title":"Agent Hacks Agents (AHA) autoresearch framework for discovering LLM agent vulnerabilities","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Agent Hacks Agents: Autoresearch Discovers Vulnerabilities in Production Agents","kind":"evaluation_result","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Claude Code":1,"Codex":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0211","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0211.json","title":"MOSAIC-Bench: Measuring Compositional Vulnerability Induction in Coding Agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"MOSAIC-Bench: Measuring Compositional Vulnerability Induction in Coding Agents","kind":"evaluation_result","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["malware","offensive_ops","vuln_discovery"],"category_counts":{"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Claude":1,"Codex":1,"Gemma-4-E4B-it":1,"MOSAIC-Bench":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0210","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0210.json","title":"PromptMIA membership inference attack in federated prompt tuning","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Leveraging Soft Prompts for Privacy Attacks in Federated Prompt Tuning","kind":"disclosure","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["malware","model_misuse","policy","vuln_discovery"],"category_counts":{"malware":1,"model_misuse":1,"policy":1,"vuln_discovery":1},"named_systems":{"PromptMIA":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0209","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0209.json","title":"DGF-Bench: Benchmark for simulating and auditing deception in multi-agent governance boards","title_source":"incident_label","label_source":"assigner_model","first_document_title":"DGF-Bench: A Benchmark for Simulating and Auditing Deception Against Multi-Agent Governance Boards","kind":"evaluation_result","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["deepfake_fraud","model_misuse","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"DGF-Bench":1,"DeepSeek V4 Pro":1,"GPT-6 Luna Pro":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0208","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0208.json","title":"CoDeL defense framework against indirect prompt injection","title_source":"incident_label","label_source":"assigner_model","first_document_title":"CoDeL: Co-Evolutionary Defense against Indirect Prompt Injection in LLM-based Agents","kind":"evaluation_result","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["defender"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"CoDeL":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0207","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0207.json","title":"Topic-based poisoning for proprietary data extraction in crowdsourced fine-tuning","title_source":"incident_label","label_source":"assigner_model","first_document_title":"The Privacy Fallacy of Crowdsourced Fine-Tuning: Extracting Proprietary Data via Topic-Based Poisoning","kind":"disclosure","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","model_misuse","vuln_discovery"],"category_counts":{"exploitation":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"Llama 3.1 8B":1,"Qwen2.5-14B":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0206","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0206.json","title":"Proteus framework for self-evolving red team agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Proteus: A Self-Evolving Red Team for Agent Skill Ecosystems","kind":"evaluation_result","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["offensive_ops","vuln_discovery"],"category_counts":{"offensive_ops":1,"vuln_discovery":1},"named_systems":{"AI-Infra-Guard":1,"Proteus":1,"SkillVetter":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0205","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0205.json","title":"Curriculum reinforcement learning for prompt injection red-teaming","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Climbing the Hill: Prompt Injection Red-Teaming Against Frontier Models with Curriculum Reinforcement Learning","kind":"evaluation_result","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["malware","offensive_ops","policy","vuln_discovery"],"category_counts":{"malware":1,"offensive_ops":1,"policy":1,"vuln_discovery":1},"named_systems":{"AgentDyn":1,"GPT-4o Mini":1,"GPT-5.6 Luna":1,"GPT-5.6-Terra":1,"GPT-6 Luna":1,"PISmith":1,"RL-Hammer":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0204","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0204.json","title":"ReproBench benchmark for LLM agents reproducing vulnerabilities","title_source":"incident_label","label_source":"assigner_model","first_document_title":"ReproBench: Benchmarking LLM Agents on Reproducing Vulnerability From Scratch","kind":"evaluation_result","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","vuln_discovery"],"category_counts":{"exploitation":1,"vuln_discovery":1},"named_systems":{"ReproBench":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0203","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0203.json","title":"NetInjectBench: Benchmarking Indirect Prompt Injection in LLM Agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"NetInjectBench: Benchmarking Indirect Prompt Injection in Tool-Using Large Language Model Agents for Network Operations","kind":"evaluation_result","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"LLaMA3.1-8B":1,"Mistral 7B":1,"NetInjectBench":1,"Qwen2.5 7B":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0202","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0202.json","title":"Stateful Agent Backdoors: Constructing Cross-Session Attack Programs","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Stateful Agent Backdoors: Constructing Cross-Session Attack Programs","kind":"disclosure","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["malware","offensive_ops","vuln_discovery"],"category_counts":{"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"LangChain":1,"OpenClaw":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0201","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0201.json","title":"ORBIT framework for multi-agent safety and security evaluations","title_source":"incident_label","label_source":"assigner_model","first_document_title":"ORBIT: A Framework for Multi-Agent Safety and Security Evaluations","kind":"evaluation_result","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["evaluation","malware","policy","vuln_discovery"],"category_counts":{"evaluation":1,"malware":1,"policy":1,"vuln_discovery":1},"named_systems":{"Inspect":1,"ORBIT":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0200","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0200.json","title":"SkillBloat framework for token amplification attacks via skill injection","title_source":"incident_label","label_source":"assigner_model","first_document_title":"SkillBloat: Token Amplification Attacks via Skill Injection in LLM Coding Agents","kind":"disclosure","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","malware","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"vuln_discovery":1},"named_systems":{"SkillBloat":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0199","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0199.json","title":"ICER framework for automated adversarial prompt generation for text-to-image models","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Red-Teaming Text-to-Image Models via In-Context Experience Replay and Semantic-Preserving Prompt Rewriting","kind":"evaluation_result","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"DALL-E 3":1,"ICER":1,"Midjourney":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0198","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0198.json","title":"CyberClear benchmark for LLM agent APT attack chain provenance","title_source":"incident_label","label_source":"assigner_model","first_document_title":"CyberClear: A Benchmark for LLM Agent Systems on APT Attack Chain Provenance","kind":"evaluation_result","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["incident_disclosure","malware","offensive_ops","vuln_discovery"],"category_counts":{"incident_disclosure":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"CyberClear":1,"CyberProvenance":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0197","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0197.json","title":"AutoDojo benchmark for evaluating prompt injection defenses in LLM agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AutoDojo: A Generative Benchmark for Evaluating Prompt Injection Defenses in LLM Agents","kind":"evaluation_result","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["malware","offensive_ops","vuln_discovery"],"category_counts":{"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"AGENTDOJO":1,"AgentDyn":1,"AutoDojo":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0196","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0196.json","title":"CIRA attack method for compression-specific failures in vision-language models","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Still There, No Longer Seen: Exposing Compression-Induced Risk in Large Vision-Language Models","kind":"disclosure","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","model_misuse","vuln_discovery"],"category_counts":{"evaluation":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"CIRA":1,"LVLMs":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0195","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0195.json","title":"Reinforcement learning lowers bar for model distillation attacks","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Distillation Defenses Easily Break After Reinforcement Learning","kind":"disclosure","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse"],"category_counts":{"model_misuse":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0194","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0194.json","title":"Backchain Memory Attack (BMA) on LLM agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"BMA: Backchain Memory Attacks Create Unauthorized Control Paths in LLM Agents","kind":"disclosure","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0193","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0193.json","title":"RAG context tampering robustness study","title_source":"incident_label","label_source":"assigner_model","first_document_title":"In RAG We Trust? Measuring Robustness of Retrieval-Augmented Generation Under Post-Retrieval Context Tampering","kind":"evaluation_result","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{"Llama 3.1 8B":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0192","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0192.json","title":"Evaluation of System One models for agent security decisions","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Evaluating System One Models for Agent Security Decisions: Reliability, Calibration, and Selective Automation","kind":"evaluation_result","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","model_misuse","vuln_discovery"],"category_counts":{"evaluation":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"Bespoke Nimble":1,"Decider":1,"Jev":1,"Laya":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0191","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0191.json","title":"TokenScanner for detecting backdoors in text-to-image LoRAs","title_source":"incident_label","label_source":"assigner_model","first_document_title":"TokenScanner: Detecting Backdoors and Discovering Triggers in Text-to-Image LoRAs via Full Vocabulary Scanning","kind":"disclosure","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["defender"],"categories":["malware","model_misuse","vuln_discovery"],"category_counts":{"malware":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"TokenScanner":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0190","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0190.json","title":"Weird Machine Compositors research on AI orchestration vulnerabilities","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Weird Machine Compositors: Exploiting AI Orchestration at the Expression Layer","kind":"disclosure","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["instrument"],"categories":["exploitation","malware","offensive_ops","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"n8n":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0189","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0189.json","title":"MemPoison backdoor injection in LLM agent long-term memory","title_source":"incident_label","label_source":"assigner_model","first_document_title":"MemPoison: Bypassing Selective Memory Mechanisms to Plant Backdoors in LLM Agents","kind":"disclosure","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["malware","model_misuse","vuln_discovery"],"category_counts":{"malware":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"MemPoison":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0188","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0188.json","title":"SecProbe evaluation framework for coding agents on cybersecurity vulnerabilities","title_source":"incident_label","label_source":"assigner_model","first_document_title":"SecProbe: Adaptive Evaluation of Coding Agents on Cybersecurity Vulnerabilities","kind":"evaluation_result","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","offensive_ops","vuln_discovery"],"category_counts":{"evaluation":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"SecProbe":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0187","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0187.json","title":"Safety Paradox: LLM vulnerability to posterior attacks via enhanced safety awareness","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Safety Paradox: How Enhanced Safety Awareness Leaves LLMs Vulnerable to Posterior Attack","kind":"evaluation_result","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{"Claude 4.6":1,"GPT-5":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0186","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0186.json","title":"POEF framework for red-teaming LLM-based robots","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Easier Said Than Done: Unpacking Intent-Behavior Gap in Jailbreaking LLM-based Robots","kind":"evaluation_result","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["malware","policy","vuln_discovery"],"category_counts":{"malware":1,"policy":1,"vuln_discovery":1},"named_systems":{"Franka robotic arm":1,"POEF":1,"Unitree G1":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0185","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0185.json","title":"Residual authority replay in long-lived LLM agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"When Consent Outlives Context: Residual Authority Replay in Long-Lived Agents","kind":"disclosure","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","malware","policy","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"policy":1,"vuln_discovery":1},"named_systems":{"AGENTDOJO":1,"Terminal-Bench":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0184","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0184.json","title":"Frontier agents learn covert communication channels during test time","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Despite Instructions: Frontier Agents Improvise Covert Channels at Test Time","kind":"evaluation_result","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","model_misuse","offensive_ops"],"category_counts":{"exploitation":1,"model_misuse":1,"offensive_ops":1},"named_systems":{"GPT-5.6 Sol":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0183","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0183.json","title":"ZeroGAR benchmark for adversarial robustness of zero-shot graph models","title_source":"incident_label","label_source":"assigner_model","first_document_title":"ZeroGAR: Benchmarking the Adversarial Robustness of Zero-Shot Graph Models","kind":"evaluation_result","first_reported":"2026-09-29T04:00:00Z","last_reported":"2026-09-29T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","model_misuse","vuln_discovery"],"category_counts":{"evaluation":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"ZeroGAR":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0181","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0181.json","title":"AI-driven audit workflow identifies 24 Android app vulnerabilities","title_source":"incident_label","label_source":"assigner_model","first_document_title":"GitHub’s AI agent found 24 Android app vulnerabilities","kind":"disclosure","first_reported":"2026-09-29T06:39:42Z","last_reported":"2026-10-01T00:54:30Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":2,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["defender","subject"],"categories":["exploitation","malware","offensive_ops","vuln_discovery"],"category_counts":{"malware":2,"vuln_discovery":2,"exploitation":1,"offensive_ops":1},"named_systems":{"Taskflow Agent":2,"Anthropic's SDK":1,"GitHub Copilot":1,"GitHub Copilot SDK":1,"OpenAI Agents SDK":1,"OsmAnd":1,"Wikipedia Android app":1},"merged_from":["RL-I-2026-0353"],"corrections":1},{"incident_id":"RL-I-2026-0180","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0180.json","title":"ElevenLabs voice cloning model release and Malaysia scam reports","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI Can Clone a Voice in 10 Seconds. Malaysia Blocked 101 Million Scam Calls","kind":"disclosure","first_reported":"2026-09-29T00:00:00Z","last_reported":"2026-09-29T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1,"vuln_discovery":1},"named_systems":{"Eleven v4":1,"Instant Voice Clone":1,"v4 Turbo":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0179","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0179.json","title":"UK AISI safety evaluation of OpenAI GPT-6 Astra supply chain attacks","title_source":"incident_label","label_source":"assigner_model","first_document_title":"GPT-6 Astra performs unsanctioned supply-chain attacks in simulations | AISI Work","kind":"evaluation_result","first_reported":"2026-09-28T00:00:00Z","last_reported":"2026-10-01T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":5,"distinct_sources":5,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","vendor_claim"],"ai_roles":["subject"],"categories":["malware","model_misuse","vuln_discovery"],"category_counts":{"malware":4,"model_misuse":4,"vuln_discovery":3,"evaluation":2,"policy":2,"deepfake_fraud":1},"named_systems":{"GPT-5.5":4,"GPT-5.6 Sol":4,"GPT-6 Astra":4,"GPT-6.1 Astra":2,"Petri":2,"Claude":1,"Inspect ReAct":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0178","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0178.json","title":"Malicious Custom GPTs used for ClickFix RAT installation","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Malicious Custom GPT on chatgpt.com lures users into installing a RAT","kind":"intrusion","first_reported":"2026-09-29T11:55:25Z","last_reported":"2026-10-03T09:02:15Z","first_reported_basis":"published_at","event_date":null,"document_count":8,"distinct_sources":8,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["malware","phishing_social"],"category_counts":{"malware":8,"phishing_social":8,"deepfake_fraud":2,"evaluation":1},"named_systems":{"ChatGPT":8,"Custom GPTs":4,"Plus 5.6":4,"Gemini":2,"@input":1,"Claude Artifacts":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0177","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0177.json","title":"North Korean IT cell uses fake female personas and ChatGPT for job fraud","title_source":"incident_label","label_source":"assigner_model","first_document_title":"North Korea's AI-Driven Cyberattacks and Disguised Employment","kind":"intrusion","first_reported":"2026-09-29T00:00:00Z","last_reported":"2026-09-29T11:21:00Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":2,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","analyst_assessment"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social","soc_defence"],"category_counts":{"deepfake_fraud":2,"malware":1,"phishing_social":1,"soc_defence":1},"named_systems":{"ChatGPT":1},"merged_from":[],"corrections":7},{"incident_id":"RL-I-2026-0176","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0176.json","title":"Rise in LLM-jacking to steal credentials and computing power","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Hackers hijack AI accounts and servers to fuel new cybercrime boom","kind":"disclosure","first_reported":"2026-09-27T00:00:00Z","last_reported":"2026-09-27T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["influence_ops","malware","phishing_social"],"category_counts":{"influence_ops":1,"malware":1,"phishing_social":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0175","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0175.json","title":"Autonomous AI agent breach of DIVD network","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Automated AI agent used to breach cybersecurity nonprofit DIVD","kind":"intrusion","first_reported":"2026-09-29T15:39:19Z","last_reported":"2026-10-05T08:12:36Z","first_reported_basis":"published_at","event_date":null,"document_count":10,"distinct_sources":9,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","incident_disclosure","malware","vuln_discovery"],"category_counts":{"exploitation":10,"malware":9,"vuln_discovery":8,"incident_disclosure":6,"policy":1},"named_systems":{"Zammad":8,"CVE-2026-102489":1,"CVE-2026-102490":1,"Hugging Face":1,"JFrog Artifactory":1,"Langflow":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0174","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0174.json","title":"Deepfake ad using Clark Howard's likeness on Facebook","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Facebook Told Clark Howard a Deepfake Ad Stealing His Face Meets Their Standards","kind":"intrusion","first_reported":"2026-09-17T22:54:00Z","last_reported":"2026-09-17T22:54:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social","policy"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1,"policy":1},"named_systems":{"Facebook":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0172","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0172.json","title":"Unknown actor compromises LocalAI instances to exfiltrate Thai military data","title_source":"incident_label","label_source":"assigner_model","first_document_title":"ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories","kind":"intrusion","first_reported":"2026-09-17T17:33:00Z","last_reported":"2026-09-17T17:33:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["target"],"categories":["exploitation","influence_ops","malware","vuln_discovery"],"category_counts":{"exploitation":1,"influence_ops":1,"malware":1,"vuln_discovery":1},"named_systems":{"LocalAI":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0171","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0171.json","title":"AWS AgentCore Harness prompt injection to shell tool vulnerability","title_source":"incident_label","label_source":"assigner_model","first_document_title":"A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity","kind":"disclosure","first_reported":"2026-09-18T10:00:36Z","last_reported":"2026-09-18T10:00:36Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["exploitation","influence_ops","malware","vuln_discovery"],"category_counts":{"exploitation":1,"influence_ops":1,"malware":1,"vuln_discovery":1},"named_systems":{"AWS AgentCore Harness":1,"AWS AgentCore Identity":1,"Model Context Protocol":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0170","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0170.json","title":"Trail of Bits uses AI agents to identify Miden VM vulnerability","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Using AI for Weapons Development","kind":"disclosure","first_reported":"2026-09-14T16:07:46Z","last_reported":"2026-09-18T11:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":2,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["defender","instrument"],"categories":["exploitation","malware","offensive_ops","vuln_discovery"],"category_counts":{"malware":2,"exploitation":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Claude":2,"Claude Code":1,"Codex":1,"Lean":1,"Miden VM":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0168","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0168.json","title":"Fake AI agents and crypto bots used as malware lures","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Fake AI agents as bait: attackers capitalize on the hype - ITdaily","kind":"disclosure","first_reported":"2026-09-18T00:00:00Z","last_reported":"2026-09-18T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["influence_ops","malware","phishing_social"],"category_counts":{"influence_ops":1,"malware":1,"phishing_social":1},"named_systems":{"HP Sure Click":1,"HP Wolf Security":1,"Phantom Gate":1,"Phantom Stealer":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0166","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0166.json","title":"AI-assisted creation of fake antivirus renewal phishing page","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI helps scammers build convincing antivirus renewal pages | Malwarebytes","kind":"intrusion","first_reported":"2026-09-16T00:00:00Z","last_reported":"2026-09-17T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":2,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social"],"category_counts":{"deepfake_fraud":2,"malware":2,"phishing_social":2},"named_systems":{"Avast":1,"Avast Premium Security":1},"merged_from":["RL-I-2026-0291"],"corrections":1},{"incident_id":"RL-I-2026-0165","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0165.json","title":"Australian Department of Home Affairs considers mandatory AI cyber attack reporting","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Home Affairs considers mandatory reporting for AI cyber attacks | Grafa","kind":"policy_action","first_reported":"2026-09-18T00:00:00Z","last_reported":"2026-09-18T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":3,"distinct_sources":3,"coverage":"multiple_sources","evidence_classes":["analyst_assessment"],"ai_roles":["subject"],"categories":["incident_disclosure","policy"],"category_counts":{"incident_disclosure":3,"policy":3},"named_systems":{"Hugging Face":3},"merged_from":["RL-I-2026-0169"],"corrections":1},{"incident_id":"RL-I-2026-0164","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0164.json","title":"Hacktron researchers use AI to discover software decoder memory corruption flaw","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Researchers use AI to find widespread software decoder flaw","kind":"disclosure","first_reported":"2026-09-18T17:19:49Z","last_reported":"2026-09-18T17:19:49Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["exploitation","malware","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"vuln_discovery":1},"named_systems":{"ChatGPT":1,"Claude":1,"Claude Opus 5":1,"Codex":1,"GPT-5.6 Sol":1,"libde265":1,"libheif":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0163","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0163.json","title":"AI agents used to scale attacks against PaperCut servers","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI-powered attack exploited PaperCut flaws to hack 395 organizations","kind":"intrusion","first_reported":"2026-09-10T15:55:56Z","last_reported":"2026-09-18T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":8,"distinct_sources":8,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","analyst_assessment"],"ai_roles":["instrument"],"categories":["exploitation","incident_disclosure","malware","vuln_discovery"],"category_counts":{"exploitation":8,"malware":8,"vuln_discovery":8,"incident_disclosure":4,"offensive_ops":2,"phishing_social":1},"named_systems":{"PaperCut NG/MF":7,"Codex":6,"DeepSeek":6,"AionUI":1,"BloodHound":1,"Certipy":1,"Cisco IOS":1,"Cisco IOS XE":1,"Cisco Secure Email Gateway":1,"GitLab":1,"Hindsight":1,"Impacket":1,"Ligolo-ng":1,"Mimikatz":1,"Netlas":1,"PaperCut":1,"Pixel modem":1,"Rubeus":1,"RubyGems":1,"ShieldCrash":1,"Windows Active Directory":1,"WooCommerce":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0162","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0162.json","title":"Chainalysis report on AI-enabled blockchain malware surge","title_source":"incident_label","label_source":"assigner_model","first_document_title":"State Hackers Now Write Most of the Malware Hidden on Public Blockchains, and Open-Source AI Is Why","kind":"disclosure","first_reported":"2026-09-17T00:00:00Z","last_reported":"2026-09-22T12:12:14Z","first_reported_basis":"published_at","event_date":null,"document_count":5,"distinct_sources":5,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["evaluation","exploitation","malware"],"category_counts":{"malware":5,"evaluation":4,"exploitation":3,"influence_ops":2,"offensive_ops":1},"named_systems":{"Aptos":2,"BNB Smart Chain":2,"Ethereum":2,"Namecoin":2,"Tron":2,"Bitcoin":1,"Polygon":1},"merged_from":["RL-I-2026-0089"],"corrections":1},{"incident_id":"RL-I-2026-0161","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0161.json","title":"Researchers use OpenAI Opus models to access Google internal monorepo","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Google is testing a new version of its AI agent CC, pivoting the tool from an individual productivity assistant into a collaborative household management","kind":"intrusion","first_reported":"2026-09-18T20:10:01Z","last_reported":"2026-09-18T20:10:01Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","incident_disclosure","vuln_discovery"],"category_counts":{"exploitation":1,"incident_disclosure":1,"vuln_discovery":1},"named_systems":{"Claude Opus 4.8":1,"Claude Opus 5":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0160","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0160.json","title":"AI-assisted executive-impersonation invoice phishing, over a million emails","title_source":"incident_label","label_source":"editor","first_document_title":"Protecting organizations from AI-assisted executive impersonation and invoice fraud","kind":"intrusion","first_reported":"2026-09-10T17:23:05Z","last_reported":"2026-09-22T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":6,"distinct_sources":6,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["evaluation","malware","phishing_social"],"category_counts":{"evaluation":6,"malware":6,"phishing_social":6,"deepfake_fraud":1},"named_systems":{"ServiceNow":4,"ServiceNow Platform":1},"merged_from":["RL-I-2026-0447"],"corrections":3},{"incident_id":"RL-I-2026-0159","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0159.json","title":"DARPA AI Cyber Challenge lessons on AI agent reliability and patch generation","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Georgia Tech Researchers Share AI Cyber Challenge Lessons at USENIX Security 2026","kind":"evaluation_result","first_reported":"2026-09-03T00:00:00Z","last_reported":"2026-09-08T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":3,"distinct_sources":3,"coverage":"multiple_sources","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","incident_disclosure","vuln_discovery"],"category_counts":{"vuln_discovery":3,"exploitation":2,"incident_disclosure":2},"named_systems":{"Cyber Reasoning Systems (CRSs)":3,"DARPA AI Cyber Challenge (AIxCC)":3},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0158","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0158.json","title":"XBOW AI system reaches top of HackerOne leaderboard","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI Bug Hunter Sets Milestone By Claiming Top Spot on HackerOne’s Leaderboard","kind":"evaluation_result","first_reported":"2026-09-18T00:00:00Z","last_reported":"2026-09-18T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["offensive_ops","vuln_discovery"],"category_counts":{"offensive_ops":1,"vuln_discovery":1},"named_systems":{"XBOW":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0157","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0157.json","title":"ZRON Chinese firm uses AI to process stolen government secrets","title_source":"incident_label","label_source":"assigner_model","first_document_title":"How a Chinese Hacking Firm Tapped AI to Supercharge Cyber-Spying — OODAloop","kind":"intrusion","first_reported":"2026-09-16T16:20:01Z","last_reported":"2026-09-16T16:20:01Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["evaluation","exploitation","malware"],"category_counts":{"evaluation":1,"exploitation":1,"malware":1},"named_systems":{"ZRON":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0156","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0156.json","title":"Autonomous AI agent data breach in Spain","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Spain AEPD Logs First AI Agent Data Breach [2026]","kind":"intrusion","first_reported":"2026-09-16T00:00:00Z","last_reported":"2026-09-18T07:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":8,"distinct_sources":8,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","analyst_assessment","commentary"],"ai_roles":["instrument"],"categories":["exploitation","malware","vuln_discovery"],"category_counts":{"malware":7,"exploitation":6,"vuln_discovery":5,"policy":3,"deepfake_fraud":1,"incident_disclosure":1,"phishing_social":1},"named_systems":{"Claude":2,"Gemini":2,"Claude Mythos":1,"GPT 5.5 Cyber":1,"Hugging Face":1,"OpenAI agents (model unspecified)":1,"OpenClaw":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0155","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0155.json","title":"AI voice cloning scam in Greece","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Greece: Police bust gang using AI to clone relatives' voices for cash | Euronews","kind":"intrusion","first_reported":"2026-09-14T00:00:00Z","last_reported":"2026-09-19T16:42:15Z","first_reported_basis":"published_at","event_date":null,"document_count":3,"distinct_sources":3,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","analyst_assessment"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social","vuln_discovery"],"category_counts":{"deepfake_fraud":3,"malware":3,"phishing_social":3,"vuln_discovery":3},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0154","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0154.json","title":"US military analyst uses AI chatbot to produce false intelligence report","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Exclusive: US military had close call after using AI for false intelligence report, sources say | CNN Politics","kind":"disclosure","first_reported":"2026-09-18T00:00:00Z","last_reported":"2026-09-18T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["instrument"],"categories":["incident_disclosure","malware","phishing_social","policy"],"category_counts":{"incident_disclosure":1,"malware":1,"phishing_social":1,"policy":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0153","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0153.json","title":"OpenAI agents supply chain attack on RubyGems registry","title_source":"incident_label","label_source":"assigner_model","first_document_title":"OpenAI reveals another rogue AI attack - POLITICO","kind":"intrusion","first_reported":"2026-09-11T00:00:00Z","last_reported":"2026-09-20T06:43:22Z","first_reported_basis":"published_at","event_date":null,"document_count":20,"distinct_sources":20,"coverage":"multiple_sources","evidence_classes":["independent_confirmation","threat_intel_report","analyst_assessment"],"ai_roles":["instrument"],"categories":["exploitation","malware","vuln_discovery"],"category_counts":{"malware":20,"vuln_discovery":19,"exploitation":13,"policy":7,"influence_ops":4,"soc_defence":3,"incident_disclosure":2},"named_systems":{"RubyGems":20,"Hugging Face":10,"RubyDoc.info":10,"DSEwiki":3,"OpenAI agents (model unspecified)":2,"ChatGPT":1,"Claude":1,"Claude Opus 4.6":1,"PyPI":1,"RubyDoc":1},"merged_from":["RL-I-2026-0240"],"corrections":4},{"incident_id":"RL-I-2026-0152","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0152.json","title":"OpenAI Codex sandbox escape via Heapjack and Overpatch vulnerabilities","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Researchers escape OpenAI Codex sandbox to run commands on host","kind":"disclosure","first_reported":"2026-09-20T12:00:00Z","last_reported":"2026-09-20T12:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["target"],"categories":["exploitation","malware","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"vuln_discovery":1},"named_systems":{"Codex":1,"Codex CLI":1,"Codex Desktop":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0151","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0151.json","title":"Google Gemini agent autonomous compromise of production systems during red-team exercise","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Gemini's Agentic Pentest Breakout 2026: What Actually Happened - AI Learning Guides","kind":"intrusion","first_reported":"2026-09-20T00:00:00Z","last_reported":"2026-09-20T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["incident_disclosure","model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"incident_disclosure":1,"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Claude":1,"Gemini":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0150","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0150.json","title":"Phishing campaign impersonating ChatGPT billing","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Fake ChatGPT billing email targets work and home users | IT Pro","kind":"intrusion","first_reported":"2026-09-18T00:00:00Z","last_reported":"2026-09-18T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1},"named_systems":{"ChatGPT":1,"Claude":1,"DeepSeek":1,"Microsoft Copilot":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0149","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0149.json","title":"Prompt Forcing technique for hijacking AI agents via browser extensions","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Single Extension Hijacks AI Agents in Five Browsers Without Any User Clicks","kind":"disclosure","first_reported":"2026-09-20T17:51:04Z","last_reported":"2026-09-20T17:51:04Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["target"],"categories":["exploitation","influence_ops","malware","vuln_discovery"],"category_counts":{"exploitation":1,"influence_ops":1,"malware":1,"vuln_discovery":1},"named_systems":{"Claude":1,"Copilot":1,"Gemini Live":1,"Opera Neon":1,"Perplexity Comet":1,"declarativeNetRequest (DNR) API":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0147","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0147.json","title":"Unprivileged IMU side channel for keystroke inference on MacBooks","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Et Tu, MacBook? Unprivileged Keystroke Inference and Context Profiling via the Built-in IMU Side Channel","kind":"disclosure","first_reported":"2026-09-21T04:00:00Z","last_reported":"2026-09-21T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["instrument"],"categories":["evaluation","malware","vuln_discovery"],"category_counts":{"evaluation":1,"malware":1,"vuln_discovery":1},"named_systems":{"BRUTUS":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0146","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0146.json","title":"Loopjacking: Hijacking Human-in-the-Loop Approval","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Loopjacking: Hijacking Human-in-the-Loop Approval","kind":"disclosure","first_reported":"2026-09-21T04:00:00Z","last_reported":"2026-09-21T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["malware","model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"malware":1,"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Agno AgentOS":1,"LangGraph Agent Server":1,"OpenAI Agents SDK":1,"OpenClaw":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0145","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0145.json","title":"Micro-Collaborative Poisoning of RAG systems","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Micro-Collaborative Poisoning: A Distributed Attack on RAG Systems","kind":"disclosure","first_reported":"2026-09-21T04:00:00Z","last_reported":"2026-09-21T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["malware","model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"malware":1,"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0144","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0144.json","title":"SteganoBackdoor framework for steganographic backdoors in transformer models","title_source":"incident_label","label_source":"assigner_model","first_document_title":"SteganoBackdoor: Evading Data-Poisoning Defenses via Steganographic Backdoors","kind":"disclosure","first_reported":"2026-09-21T04:00:00Z","last_reported":"2026-09-21T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","malware","model_misuse","vuln_discovery"],"category_counts":{"evaluation":1,"malware":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"SteganoBackdoor":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0143","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0143.json","title":"CESBench benchmark for LLM cryptographic engineering security","title_source":"incident_label","label_source":"assigner_model","first_document_title":"CESBench: Benchmarking Large Language Models on Cryptographic Engineering Security for IoT Devices","kind":"evaluation_result","first_reported":"2026-09-21T04:00:00Z","last_reported":"2026-09-21T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","malware","offensive_ops","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0142","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0142.json","title":"APort Vault benchmark for AI agent payment authorization","title_source":"incident_label","label_source":"assigner_model","first_document_title":"APort Vault: Benchmarking AI Agent Payment Authorization with the Open Agent Passport","kind":"evaluation_result","first_reported":"2026-09-21T04:00:00Z","last_reported":"2026-09-21T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["deepfake_fraud","malware","offensive_ops","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"APort Vault":1,"Open Agent Passport":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0141","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0141.json","title":"OverThink attack on reasoning LLMs to increase per-token costs","title_source":"incident_label","label_source":"assigner_model","first_document_title":"OverThink: Slowdown Attacks on Reasoning LLMs","kind":"disclosure","first_reported":"2026-09-21T04:00:00Z","last_reported":"2026-09-21T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","model_misuse","offensive_ops"],"category_counts":{"evaluation":1,"model_misuse":1,"offensive_ops":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0140","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0140.json","title":"Evaluation of LLM-generated GPU kernels for real workloads","title_source":"incident_label","label_source":"assigner_model","first_document_title":"How Much of a Real Workload Can LLM-Generated GPU Kernels Actually Reach?","kind":"evaluation_result","first_reported":"2026-09-21T04:00:00Z","last_reported":"2026-09-21T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["deepfake_fraud","evaluation","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"evaluation":1,"vuln_discovery":1},"named_systems":{"DLRM-Bench":1,"FlashAttention":1,"KernelBench":1,"PyTorch":1,"cuBLAS":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0139","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0139.json","title":"ALIBI attack on LLM malware analyzers","title_source":"incident_label","label_source":"assigner_model","first_document_title":"ALIBI: Adversarial Legitimacy Injection in Binary Input against LLM Malware Analyzers | alphaXiv","kind":"disclosure","first_reported":"2026-09-17T00:00:00Z","last_reported":"2026-09-18T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":3,"distinct_sources":3,"coverage":"multiple_sources","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","malware","offensive_ops"],"category_counts":{"malware":3,"evaluation":2,"offensive_ops":2,"exploitation":1,"vuln_discovery":1},"named_systems":{"Claude Opus 4.7":2,"GPT-5.5 Pro":2,"Gemini 2.5 Pro":2,"VirusTotal Code Insight":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0138","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0138.json","title":"AI-generated exploit scripts for Siemens controllers in energy and water systems","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems | The Verge","kind":"disclosure","first_reported":"2026-09-20T00:00:00Z","last_reported":"2026-09-21T01:52:15Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":2,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","analyst_assessment"],"ai_roles":["instrument"],"categories":["exploitation","influence_ops","malware","offensive_ops","policy","vuln_discovery"],"category_counts":{"malware":2,"exploitation":1,"influence_ops":1,"offensive_ops":1,"policy":1,"vuln_discovery":1},"named_systems":{"Censys":1,"Claude":1,"Hugging Face":1,"Siemens F-series":1,"Siemens S7-1200":1,"Siemens S7-1500":1,"Siemens S7-200":1,"Siemens S7-300":1,"Siemens S7-400":1,"ZoomEye":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0137","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0137.json","title":"AI voice cloning scams targeting individuals and organizations","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI Voice Cloning Scam: How Scammers Imitate Family, Bosses and Officials - The420.in","kind":"intrusion","first_reported":"2026-09-21T00:00:00Z","last_reported":"2026-09-30T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":2,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","analyst_assessment"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social","vuln_discovery"],"category_counts":{"deepfake_fraud":2,"malware":2,"phishing_social":2,"vuln_discovery":2},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0136","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0136.json","title":"OpenAI reveals model misalignment incidents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"OpenAI Creates a New Framework to Disclose Bad AI Behavior | WIRED","kind":"disclosure","first_reported":"2026-09-16T00:00:00Z","last_reported":"2026-09-28T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":10,"distinct_sources":10,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","vendor_claim"],"ai_roles":["subject","target"],"categories":["model_misuse"],"category_counts":{"model_misuse":8,"deepfake_fraud":2,"malware":2,"policy":2,"exploitation":1,"vuln_discovery":1},"named_systems":{"ChatGPT":3,"Hugging Face":3,"Astra":1,"Claude":1,"GPT-5.6":1,"GPT-5.6 Sol":1,"GPT-6 Astra":1,"JFrog Artifactory":1},"merged_from":[],"corrections":1},{"incident_id":"RL-I-2026-0135","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0135.json","title":"XBOW evaluation of Grok 4.7 offensive security performance","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Grok 4.7 for Offensive Security: Orchestration Matters | XBOW","kind":"evaluation_result","first_reported":"2026-09-21T00:00:00Z","last_reported":"2026-09-21T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","offensive_ops","vuln_discovery"],"category_counts":{"exploitation":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Claude Mythos":1,"Grok 4.6":1,"Grok 4.7":1,"xAI’s Build":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0134","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0134.json","title":"Deepfake fraud at Arup firm","title_source":"incident_label","label_source":"assigner_model","first_document_title":"The $25 Million Phone Call: How AI Voice Cloning Is Powering CEO Fraud - Cyber Clan","kind":"intrusion","first_reported":"2026-09-02T00:00:00Z","last_reported":"2026-10-05T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":3,"distinct_sources":3,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","analyst_assessment"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social","soc_defence"],"category_counts":{"deepfake_fraud":3,"phishing_social":3,"malware":2,"soc_defence":2,"evaluation":1},"named_systems":{"ChatGPT":1,"DocuSign":1,"Google Workspace":1,"Microsoft 365":1,"SharePoint":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0133","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0133.json","title":"Wiz Red Agent exploits Snowflake CI/CD pipeline","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Wiz’s AI Agent Finds A Vulnerability In Snowflake’s Internal Systems","kind":"intrusion","first_reported":"2026-08-17T00:00:00Z","last_reported":"2026-09-17T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":3,"distinct_sources":3,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","vuln_discovery"],"category_counts":{"exploitation":3,"vuln_discovery":3,"incident_disclosure":1},"named_systems":{"GitHub Actions":3,"Snowflake":3,"Jira":2,"Red Agent":2,"Wiz":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0132","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0132.json","title":"Denial of wallet attacks via AI agent runaway costs","title_source":"incident_label","label_source":"assigner_model","first_document_title":"How AI Agents Can Trigger Runaway Costs for Enterprises","kind":"disclosure","first_reported":"2026-09-21T21:39:59Z","last_reported":"2026-09-21T21:39:59Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["malware","policy","vuln_discovery"],"category_counts":{"malware":1,"policy":1,"vuln_discovery":1},"named_systems":{"OWASP Top 10 for LLM Applications":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0131","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0131.json","title":"GenIaC-SecBench benchmark for LLM-generated Infrastructure-as-Code security","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Compared to What? A Human-Anchored Security Benchmark for LLM-Generated Infrastructure-as-Code","kind":"evaluation_result","first_reported":"2026-09-22T04:00:00Z","last_reported":"2026-09-22T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","malware","policy","vuln_discovery"],"category_counts":{"evaluation":1,"malware":1,"policy":1,"vuln_discovery":1},"named_systems":{"Checkov":1,"GenIaC-SecBench":1,"KICS":1,"Trivy":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0130","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0130.json","title":"BreakFun jailbreak technique via simulated code execution","title_source":"incident_label","label_source":"assigner_model","first_document_title":"BreakFun: Jailbreaking LLMs via Object Instantiation under Simulated Code Execution","kind":"evaluation_result","first_reported":"2026-09-22T04:00:00Z","last_reported":"2026-09-22T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Adversarial Prompt Deconstruction (APD)":1,"BreakFun":1,"JailbreakBench":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0129","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0129.json","title":"KryptoPilot LLM agent for automated cryptographic exploitation","title_source":"incident_label","label_source":"assigner_model","first_document_title":"KryptoPilot: An Open-World Knowledge-Augmented LLM Agent for Automated Cryptographic Exploitation","kind":"evaluation_result","first_reported":"2026-09-22T04:00:00Z","last_reported":"2026-09-22T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","offensive_ops","vuln_discovery"],"category_counts":{"exploitation":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"KryptoPilot":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0128","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0128.json","title":"OPBackdoor technique for embedding alibi-aligned reasoning backdoors in LLMs","title_source":"incident_label","label_source":"assigner_model","first_document_title":"OPBackdoor: Opportunistic Backdoors via Alibi-Aligned Reasoning","kind":"disclosure","first_reported":"2026-09-22T04:00:00Z","last_reported":"2026-09-22T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["malware","model_misuse","offensive_ops"],"category_counts":{"malware":1,"model_misuse":1,"offensive_ops":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0127","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0127.json","title":"APIOT framework for autonomous vulnerability management in industrial OT networks","title_source":"incident_label","label_source":"assigner_model","first_document_title":"APIOT: Autonomous Vulnerability Management Across Bare-Metal Industrial OT Networks","kind":"evaluation_result","first_reported":"2026-09-22T04:00:00Z","last_reported":"2026-09-22T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","offensive_ops","vuln_discovery"],"category_counts":{"exploitation":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"APIOT":1,"Zephyr RTOS":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0126","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0126.json","title":"Confused deputy vulnerabilities in AI accelerators","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Speed Kills: Exploring Confused Deputy Attacks Through Edge AI Accelerators","kind":"disclosure","first_reported":"2026-09-22T04:00:00Z","last_reported":"2026-09-22T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["exploitation","malware","offensive_ops","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"DeputyHunt":1,"Gem5-salam":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0125","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0125.json","title":"MobileCybench framework for evaluating AI agent vulnerability discovery","title_source":"incident_label","label_source":"assigner_model","first_document_title":"MobileCybench: Evaluating Agent Vulnerability Discovery via Executable Probes","kind":"evaluation_result","first_reported":"2026-09-22T04:00:00Z","last_reported":"2026-09-22T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","malware","offensive_ops","vuln_discovery"],"category_counts":{"evaluation":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Claude Code":1,"Claude Opus 4.8":1,"Claude Opus 5":1,"GLM 5.2":1,"GPT-5.5":1,"GPT-5.6 Sol":1,"MobileCybench":1,"OpenCode":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0124","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0124.json","title":"SkillClone attack for reconstructing hidden LLM agent functionality","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Behavioral Skill Reconstruction: Reconstructing Hidden Functionality from LLM Agent Skills","kind":"disclosure","first_reported":"2026-09-22T04:00:00Z","last_reported":"2026-09-22T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse"],"category_counts":{"model_misuse":1},"named_systems":{"SkillClone":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0123","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0123.json","title":"Bifröst framework for measuring security awareness-behavior gap in student use of LLM-generated code","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Aware but Unprepared: Measuring the Security Awareness-Behavior Gap in Student Use of LLM-Generated Code with Bifr\\\"ost","kind":"evaluation_result","first_reported":"2026-09-22T04:00:00Z","last_reported":"2026-09-22T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["malware","offensive_ops","vuln_discovery"],"category_counts":{"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Bifröst":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0122","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0122.json","title":"Forgeable confirmation mechanisms in AI-assisted security testing","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Forgeable Confirmation in Automated Computer Security Testing: Deterministic Rules versus AI Judges","kind":"evaluation_result","first_reported":"2026-09-22T04:00:00Z","last_reported":"2026-09-22T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["offensive_ops","vuln_discovery"],"category_counts":{"offensive_ops":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0121","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0121.json","title":"SyzHarness framework for LLM-synthesized kernel fuzzing harnesses","title_source":"incident_label","label_source":"assigner_model","first_document_title":"SyzHarness: Patch-Based Kernel Bug Reproduction with LLM-Synthesized Fuzzing Harnesses","kind":"evaluation_result","first_reported":"2026-09-22T04:00:00Z","last_reported":"2026-09-22T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["defender"],"categories":["exploitation","malware","offensive_ops","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"SyzHarness":1,"Syzkaller":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0120","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0120.json","title":"Adversarial robustness evaluation of Anthropic Fable and Opus models","title_source":"incident_label","label_source":"assigner_model","first_document_title":"A Red-Team Study of Anthropic Fable 5 & Opus 4.8 Models","kind":"evaluation_result","first_reported":"2026-09-22T04:00:00Z","last_reported":"2026-09-22T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse"],"category_counts":{"model_misuse":1},"named_systems":{"Claude Fable 5":1,"Claude Fable 5.1":1,"Claude Opus 4.8":1,"HackAgent":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0119","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0119.json","title":"StateLens framework for LLM-guided JavaScript engine fuzzing","title_source":"incident_label","label_source":"assigner_model","first_document_title":"State-Aware Fuzzing of JavaScript Engines with LLM-Guided Instrumentation","kind":"evaluation_result","first_reported":"2026-09-22T04:00:00Z","last_reported":"2026-09-22T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","malware","offensive_ops","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"StateLens":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0118","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0118.json","title":"Evaluation of coding agents on post-quantum cryptography migration","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Can Coding Agents Migrate to Post-Quantum Cryptography?","kind":"evaluation_result","first_reported":"2026-09-22T04:00:00Z","last_reported":"2026-09-22T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["offensive_ops","vuln_discovery"],"category_counts":{"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Claude Code":1,"Claude Fable 5.1":1,"Codex":1,"GPT-6 Astra":1,"Qwen3.8":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0116","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0116.json","title":"RAG-Pref training-free alignment for MCP exploits","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Training-Free Refusal of MCP Exploits via Retrieval-Augmented Generation","kind":"evaluation_result","first_reported":"2026-09-22T04:00:00Z","last_reported":"2026-09-22T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"AlpacaEval 2":1,"DPO":1,"MT-Bench":1,"Model Context Protocol":1,"RAG-Pref":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0115","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0115.json","title":"SelfOp algorithm for self-improving security agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"SelfOp: An Optimization Algorithm for Self-Improving Security Agents","kind":"evaluation_result","first_reported":"2026-09-22T04:00:00Z","last_reported":"2026-09-22T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","offensive_ops","vuln_discovery"],"category_counts":{"exploitation":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Codex":1,"CyberGym":1,"GPT-5.4":1,"GPT-5.4-mini":1,"SelfOp":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0114","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0114.json","title":"Malware distribution via trusted AI platforms","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI Security Incident Case: Trusted AI Platforms Become a New Channel for Malware Distribution - NSFOCUS","kind":"disclosure","first_reported":"2026-09-21T00:00:00Z","last_reported":"2026-09-21T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["malware","phishing_social"],"category_counts":{"malware":1,"phishing_social":1},"named_systems":{"Bing":1,"ChatGPT":1,"Claude":1,"Grok":1,"MacSync":1,"SectopRAT":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0113","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0113.json","title":"PROMPTFLUX, PROMPTSTEAL, and PROMPTSPY malware using Gemini and Qwen2.5","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Google finds AI malware using Gemini to rewrite code and evade detection | Fox News","kind":"disclosure","first_reported":"2026-09-22T00:00:00Z","last_reported":"2026-09-22T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["evaluation","malware","offensive_ops"],"category_counts":{"evaluation":1,"malware":1,"offensive_ops":1},"named_systems":{"Gemini":1,"GeminiAutomationAgent":1,"PROMPTFLUX":1,"PROMPTSPY":1,"PROMPTSTEAL":1,"Qwen2.5-Coder-32B-Instruct":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0112","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0112.json","title":"Researcher uses AI tool to find Microsoft Titan analytics authentication flaw","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Teen researcher with AI hackbot cracks Microsoft's Titan analytics","kind":"disclosure","first_reported":"2026-09-27T20:20:00Z","last_reported":"2026-09-27T20:20:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","malware","policy","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"policy":1,"vuln_discovery":1},"named_systems":{"Antares":1,"Titan":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0111","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0111.json","title":"Canonical accelerates Ubuntu kernel update cycle due to AI-discovered vulnerabilities","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Canonical Shortens Ubuntu Kernel Update Cycle to Two Weeks After AI Uncovers Hundreds of New Vulnerabilities","kind":"disclosure","first_reported":"2026-09-27T22:42:15Z","last_reported":"2026-09-27T22:42:15Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["subject"],"categories":["malware","vuln_discovery"],"category_counts":{"malware":1,"vuln_discovery":1},"named_systems":{"Linux kernel":1,"Ubuntu":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0109","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0109.json","title":"Autonomous AI influence campaigns by Iran, China, and Israeli firms","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Iran, China, and Israeli firms create first-of-their-kind autonomous AI influence campaigns, and US elections might just be their biggest battleground","kind":"disclosure","first_reported":"2026-09-28T08:12:27Z","last_reported":"2026-09-28T08:12:27Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","influence_ops","malware","phishing_social"],"category_counts":{"deepfake_fraud":1,"influence_ops":1,"malware":1,"phishing_social":1},"named_systems":{"DeepSeek":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0108","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0108.json","title":"DUALLM pipeline for LLM-aided categorization of Linux kernel security patches","title_source":"incident_label","label_source":"assigner_model","first_document_title":"What Do They Fix? LLM-Aided Categorization of Security Patches for Critical Memory Bugs","kind":"evaluation_result","first_reported":"2026-09-28T04:00:00Z","last_reported":"2026-09-28T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["defender"],"categories":["exploitation","malware","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"vuln_discovery":1},"named_systems":{"DUALLM":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0107","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0107.json","title":"AuthGuard-R safety-compliant mission hijacking research","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AuthGuard-R: Safety-Compliant Mission Hijacking and Dual-Gate Defense for LLM-Controlled Robots","kind":"evaluation_result","first_reported":"2026-09-28T04:00:00Z","last_reported":"2026-09-28T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","malware","offensive_ops","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"AuthGuard-R":1,"Claude Haiku 4.5":1,"MissionPAIR":1,"Qwen2.5 7B":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0106","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0106.json","title":"Bi-Iocane data poisoning framework for ML malware detectors","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Weaponizing Ground Truth: Data Poisoning Attacks by Exploiting Boundary Misalignment Between Antivirus Software and Learning-Based Detectors","kind":"disclosure","first_reported":"2026-09-28T04:00:00Z","last_reported":"2026-09-28T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","malware","vuln_discovery"],"category_counts":{"evaluation":1,"malware":1,"vuln_discovery":1},"named_systems":{"Bi-Iocane":1,"VirusTotal":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0105","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0105.json","title":"AgentXploit autonomous red-teaming system and benchmark","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AgentXploit: Autonomous Repository-to-Runtime Red-Teaming for AI Agents","kind":"evaluation_result","first_reported":"2026-09-28T04:00:00Z","last_reported":"2026-09-28T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","malware","offensive_ops","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"AGENTDOJO":1,"AgentVigil":1,"AgentXploit":1,"AgentXploit-Bench":1,"Codex":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0104","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0104.json","title":"Email-Specific Prompt Injection (ESPI) research and CVE disclosure","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Your Mailbox Is Mine: Prompt Injection Attacks Against Real-World LLM Email Agents","kind":"disclosure","first_reported":"2026-09-22T04:00:00Z","last_reported":"2026-09-28T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":1,"coverage":"one_source","evidence_classes":["vendor_claim"],"ai_roles":["defender","subject"],"categories":["exploitation","malware","phishing_social","policy","vuln_discovery"],"category_counts":{"malware":2,"phishing_social":2,"exploitation":1,"policy":1,"vuln_discovery":1},"named_systems":{"ESPI":1,"ESPInspector":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0103","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0103.json","title":"Evaluation of prompt injection vulnerabilities and hypnotism attacks on open-source LLMs","title_source":"incident_label","label_source":"assigner_model","first_document_title":"From ASR to ASP: Evaluating Prompt Attack Vulnerabilities Against Open-Source LLMs","kind":"evaluation_result","first_reported":"2026-09-28T04:00:00Z","last_reported":"2026-09-28T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","model_misuse","vuln_discovery"],"category_counts":{"evaluation":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"Mistral":1,"Openchat":1,"StableLM2":1,"Vicuna":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0102","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0102.json","title":"Recover-and-Reguard defense against encoded VLM jailbreaks","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Blind, Not Weak: A Best-of-Suite Safety-Utility Frontier for Recover-and-Reguard Defenses Against Encoded VLM Jailbreaks","kind":"evaluation_result","first_reported":"2026-09-28T04:00:00Z","last_reported":"2026-09-28T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0101","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0101.json","title":"FragToken framework for LLM inference cost inflation","title_source":"incident_label","label_source":"assigner_model","first_document_title":"FragToken: Amplifying LLM Inference Costs through Noncanonical Token Generation","kind":"disclosure","first_reported":"2026-09-28T04:00:00Z","last_reported":"2026-09-28T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","model_misuse"],"category_counts":{"evaluation":1,"model_misuse":1},"named_systems":{"FragToken":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0100","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0100.json","title":"ScopeBench benchmark for AI agent engagement boundaries","title_source":"incident_label","label_source":"assigner_model","first_document_title":"ScopeBench: Do Agents Preserve Engagement Boundaries Under Goal Pressure?","kind":"evaluation_result","first_reported":"2026-09-28T04:00:00Z","last_reported":"2026-09-28T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","offensive_ops","vuln_discovery"],"category_counts":{"evaluation":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Claude Opus 4-8":1,"Claude Sonnet 4-6":1,"ScopeBench":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0099","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0099.json","title":"Energy landscape analysis of jailbreaks in diffusion language models","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Why Jailbreaks Succeed in Diffusion Language Models: An Energy Landscape Analysis","kind":"evaluation_result","first_reported":"2026-09-28T04:00:00Z","last_reported":"2026-09-28T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Dream-7B":1,"LLaDA-1.5":1,"LLaDA-8B":1,"LLaDA-MoE-7B":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0098","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0098.json","title":"Skill cascading attacks on skill-based agent systems","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Stealth Apart, Harm Together: Skill Cascading Attacks on Skill-Based Agent Systems","kind":"evaluation_result","first_reported":"2026-09-28T04:00:00Z","last_reported":"2026-09-28T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Claude Code":1,"Codex":1,"OpenClaw":1,"SkillCascade":1,"SkillCascade-Bench":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0097","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0097.json","title":"NarrativeAttack framework for jailbreaking multimodal models","title_source":"incident_label","label_source":"assigner_model","first_document_title":"The Plot Twist: Jailbreaking Unified Multimodal Models with a Three-Act NarrativeAttack","kind":"evaluation_result","first_reported":"2026-09-28T04:00:00Z","last_reported":"2026-09-28T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Gemini 2.5 Flash":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0096","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0096.json","title":"Vision-language models vulnerable to typographic attacks","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Sorry Robot, Happy Human: Vision-Language Models Read Only One of Two Legible Typographic Layers","kind":"evaluation_result","first_reported":"2026-09-28T04:00:00Z","last_reported":"2026-09-28T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","vuln_discovery"],"category_counts":{"evaluation":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0095","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0095.json","title":"Research on LLM privacy leaks in 'drunk' behavior simulations","title_source":"incident_label","label_source":"assigner_model","first_document_title":"“Drunk” AI is terrible at keeping secrets","kind":"evaluation_result","first_reported":"2026-09-28T11:30:22Z","last_reported":"2026-09-28T11:30:22Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["deepfake_fraud","malware","model_misuse","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"malware":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"GPT-3.5":1,"GPT-4":1,"Llama 2":1,"Llama 3.1":1,"Mistral":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0094","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0094.json","title":"BragJack browser extension technique to hijack AI agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"BragJack Attack Can Turn a Browser's Agentic AI Against It","kind":"disclosure","first_reported":"2026-09-16T16:43:37Z","last_reported":"2026-09-28T22:33:32Z","first_reported_basis":"published_at","event_date":null,"document_count":4,"distinct_sources":4,"coverage":"multiple_sources","evidence_classes":["independent_confirmation","threat_intel_report"],"ai_roles":["target"],"categories":["deepfake_fraud","exploitation","malware","vuln_discovery"],"category_counts":{"exploitation":4,"malware":4,"vuln_discovery":4,"deepfake_fraud":2,"evaluation":1},"named_systems":{"Opera Neon":4,"Perplexity Comet":4,"Claude":3,"Gemini Live":3,"Microsoft Edge":2,"Chrome":1,"Chromium's declarativeNetRequest":1,"Claude in Chrome":1,"Edge":1,"Gemini":1,"Google Chrome":1,"Microsoft Edge Actions":1},"merged_from":["RL-I-2026-0253"],"corrections":1},{"incident_id":"RL-I-2026-0093","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0093.json","title":"Qilin ransomware group uses AI-assisted coding tools in Japan","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use","kind":"intrusion","first_reported":"2026-09-17T10:00:43Z","last_reported":"2026-09-28T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":2,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","incident_disclosure","malware"],"category_counts":{"exploitation":2,"incident_disclosure":2,"malware":2},"named_systems":{"Qilin":2,"SafePay":2,"AiLock":1,"BloodHound":1,"Chisel":1,"Gentlemen":1,"Ligolo-ng":1,"LockBit 5.0":1,"NetExec":1,"NetRunner":1,"NightSpire":1,"Nmap":1,"RansomEXX":1,"Stormous":1,"The Gentlemen":1,"impacket-partial-mic":1,"masscan":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0092","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0092.json","title":"OpenAI agents brute-force UN-affiliated website login","title_source":"incident_label","label_source":"assigner_model","first_document_title":"OpenAI AI Agents Brute-Force UN Website Login in Minutes Using Common Credentials","kind":"intrusion","first_reported":"2026-09-28T23:12:15Z","last_reported":"2026-09-28T23:12:15Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["subject"],"categories":["exploitation","malware","offensive_ops","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"OpenAI agents (model unspecified)":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0091","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0091.json","title":"RatHat Android malware uses Gemini AI for victim identification and navigation","title_source":"incident_label","label_source":"assigner_model","first_document_title":"New RatHat Android malware uses AI to automate device control","kind":"intrusion","first_reported":"2026-09-17T21:50:26Z","last_reported":"2026-09-28T17:38:33Z","first_reported_basis":"published_at","event_date":null,"document_count":3,"distinct_sources":3,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["evaluation","exploitation","influence_ops","malware"],"category_counts":{"evaluation":3,"influence_ops":3,"malware":3,"exploitation":2},"named_systems":{"RatHat":2,"BlackCat Remote Control Management":1,"Fisher":1,"Gemini":1,"PROMPTSPY":1,"Panda Workshop V5":1,"Panda Workshop V6":1},"merged_from":["RL-I-2026-0230"],"corrections":1},{"incident_id":"RL-I-2026-0090","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0090.json","title":"Zero-click RCE vulnerability in AI coding agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks","kind":"disclosure","first_reported":"2026-09-21T00:00:00Z","last_reported":"2026-09-21T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","malware","policy","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"policy":1,"vuln_discovery":1},"named_systems":{"ChatGPT":1,"Cisco ISE":1,"Claude Code":1,"Claude Opus 5":1,"Codex":1,"Gemini CLI":1,"GitHub Copilot":1,"KREMLIN":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0088","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0088.json","title":"US agencies warn of Chinese AI model distillation tactics","title_source":"incident_label","label_source":"assigner_model","first_document_title":"China is trying to steal US AI models' secrets, intel agencies warn - Defense One","kind":"disclosure","first_reported":"2026-09-08T00:00:00Z","last_reported":"2026-09-19T15:23:11Z","first_reported_basis":"published_at","event_date":null,"document_count":9,"distinct_sources":9,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","analyst_assessment"],"ai_roles":["instrument","target"],"categories":["model_misuse","policy"],"category_counts":{"model_misuse":7,"policy":5,"malware":3,"exploitation":2,"offensive_ops":1},"named_systems":{"DeepSeek":6,"Claude":5,"Gemini":5,"MiniMax":5,"Grok":4,"GPT":3,"ChatGPT":2,"Grok 4":1,"MoonshotAI":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0087","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0087.json","title":"Chinese relay network used to mask access to frontier AI models","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Relays Are Masking Chinese Access to Frontier AI Models in the US","kind":"disclosure","first_reported":"2026-09-22T21:12:37Z","last_reported":"2026-09-22T21:12:37Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["evaluation","model_misuse"],"category_counts":{"evaluation":1,"model_misuse":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0086","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0086.json","title":"AI Cyber Defense Act proposal","title_source":"incident_label","label_source":"assigner_model","first_document_title":"After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program","kind":"policy_action","first_reported":"2026-09-22T21:14:32Z","last_reported":"2026-09-22T21:14:32Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["defender"],"categories":["policy"],"category_counts":{"policy":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0084","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0084.json","title":"US and China establish AI hotline to coordinate responses to runaway AI agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Unprecedented: US & China Launch AI Hotline to Avert Global Catastrophe","kind":"policy_action","first_reported":"2026-09-22T00:00:00Z","last_reported":"2026-09-22T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["subject"],"categories":["incident_disclosure","policy"],"category_counts":{"incident_disclosure":1,"policy":1},"named_systems":{"Gemini":1,"OpenAI agents (model unspecified)":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0083","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0083.json","title":"Security flaws in low-cost AI smart glasses","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Security flaws in cheap glasses test cyber cover","kind":"disclosure","first_reported":"2026-09-23T00:00:00Z","last_reported":"2026-09-23T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["target"],"categories":["deepfake_fraud","malware","policy","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"malware":1,"policy":1,"vuln_discovery":1},"named_systems":{"HeyCyan":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0082","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0082.json","title":"Deepfake audio and video fraud in Hong Kong","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Are SMEs Also Targets? \"Impersonation Countermeasures\" Business Owners Should Know in the Age of Deepfakes","kind":"intrusion","first_reported":"2026-09-01T00:00:00Z","last_reported":"2026-09-22T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":2,"coverage":"multiple_sources","evidence_classes":["analyst_assessment"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social","soc_defence"],"category_counts":{"deepfake_fraud":2,"malware":2,"phishing_social":2,"soc_defence":2},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0081","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0081.json","title":"Strike framework for adversarial attacks on deep code models","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Towards Effective Black-Box Adversarial Attacks on Deep Code Models via Structural and Identifier Perturbations","kind":"evaluation_result","first_reported":"2026-09-23T04:00:00Z","last_reported":"2026-09-23T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Strike":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0080","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0080.json","title":"Benchmarking Neural Defend ARCAS 1B multimodal deepfake detection model","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Benchmarking Neural Defend ARCAS 1B: A Foundational Multimodal Deepfake Detection Model","kind":"evaluation_result","first_reported":"2026-09-23T04:00:00Z","last_reported":"2026-09-23T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["defender"],"categories":["deepfake_fraud","malware","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"malware":1,"vuln_discovery":1},"named_systems":{"Neural Defend ARCAS 1B":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0079","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0079.json","title":"A2M framework for hijacking AI agents in the MCP ecosystem","title_source":"incident_label","label_source":"assigner_model","first_document_title":"A2M: Trace-Optimized Agent Hijacking in the MCP Ecosystem","kind":"disclosure","first_reported":"2026-09-23T04:00:00Z","last_reported":"2026-09-23T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["malware","model_misuse","policy","vuln_discovery"],"category_counts":{"malware":1,"model_misuse":1,"policy":1,"vuln_discovery":1},"named_systems":{"GLM-4.6":1,"LiveMCPBench":1,"Model Context Protocol":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0078","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0078.json","title":"LoRango method for hiding malicious behaviors in diffusion models","title_source":"incident_label","label_source":"assigner_model","first_document_title":"LoRango: It Takes Two LoRAs to Unlock Hidden Behaviors in Diffusion Models","kind":"disclosure","first_reported":"2026-09-23T04:00:00Z","last_reported":"2026-09-23T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{"SD v1.5":1,"Stable Diffusion XL":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0077","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0077.json","title":"IndirectAD data poisoning attack on recommender systems","title_source":"incident_label","label_source":"assigner_model","first_document_title":"IndirectAD: Practical Data Poisoning Attacks against Recommender Systems for Item Promotion","kind":"disclosure","first_reported":"2026-09-23T04:00:00Z","last_reported":"2026-09-23T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["malware","model_misuse","vuln_discovery"],"category_counts":{"malware":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0076","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0076.json","title":"FinRED framework for financial LLM red-teaming","title_source":"incident_label","label_source":"assigner_model","first_document_title":"FinRED: An Expert-Guided Benchmark Generation and Evaluation Framework for Financial LLM Red-Teaming","kind":"evaluation_result","first_reported":"2026-09-23T04:00:00Z","last_reported":"2026-09-23T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["evaluation","malware","policy","vuln_discovery"],"category_counts":{"evaluation":1,"malware":1,"policy":1,"vuln_discovery":1},"named_systems":{"FinRED":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0075","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0075.json","title":"KEX-bench benchmark for coding agents on kernel exploit generation","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Evaluating Coding Agents on Kernel Exploit Generation","kind":"evaluation_result","first_reported":"2026-09-23T04:00:00Z","last_reported":"2026-09-23T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["exploitation","offensive_ops","vuln_discovery"],"category_counts":{"exploitation":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"KEX-bench":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0074","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0074.json","title":"Semi-automated assessment of LLM security knowledge gaps","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Semi-Automated Detection of Gaps in LLM Security Knowledge","kind":"evaluation_result","first_reported":"2026-09-23T04:00:00Z","last_reported":"2026-09-23T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","vuln_discovery"],"category_counts":{"evaluation":1,"vuln_discovery":1},"named_systems":{"GPT":1,"Gemini":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0073","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0073.json","title":"Rouxii framework for deception-aware AI penetration testing","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Rouxii: Exploiting Honeypots with Deception-Aware AI Pentesters","kind":"evaluation_result","first_reported":"2026-09-23T04:00:00Z","last_reported":"2026-09-23T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["deepfake_fraud","malware","offensive_ops","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Conpot":1,"GasPot":1,"HackingBuddy":1,"PentestGPT":1,"Rouxii":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0072","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0072.json","title":"RAG-NAROK framework for retrieval-aware knowledge corpus poisoning","title_source":"incident_label","label_source":"assigner_model","first_document_title":"RAG-NAROK: Retrieval-Aware Knowledge Corpus Poisoning in RAG with Source-specific Refutation","kind":"disclosure","first_reported":"2026-09-23T04:00:00Z","last_reported":"2026-09-23T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{"RAG-NAROK":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0071","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0071.json","title":"stale benchmark for semantic coordination in parallel LLM-agent development","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Passes Alone, Fails Together: Benchmarking Semantic Coordination in Parallel LLM-Agent Development","kind":"evaluation_result","first_reported":"2026-09-23T04:00:00Z","last_reported":"2026-09-23T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["malware","offensive_ops","vuln_discovery"],"category_counts":{"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Django":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0070","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0070.json","title":"AgentHazard benchmark for evaluating harmful behavior in computer-use agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AgentHazard: A Benchmark for Evaluating Harmful Behavior in Computer-Use Agents","kind":"evaluation_result","first_reported":"2026-09-23T04:00:00Z","last_reported":"2026-09-23T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","model_misuse","vuln_discovery"],"category_counts":{"evaluation":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"AgentHazard":1,"Claude Code":1,"DeepSeek":1,"GLM":1,"IFlow":1,"Kimi":1,"OpenClaw":1,"Qwen3":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0069","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0069.json","title":"UK creates National Centre for Information Defence against AI disinformation","title_source":"incident_label","label_source":"assigner_model","first_document_title":"New UK agency to fight ‘information warfare’ from likes of Russia, Burnham tells UN | Cyberwar | The Guardian","kind":"policy_action","first_reported":"2026-09-23T00:00:00Z","last_reported":"2026-09-23T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["instrument"],"categories":["deepfake_fraud","influence_ops"],"category_counts":{"deepfake_fraud":1,"influence_ops":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0068","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0068.json","title":"Malware campaign using fake AI trading agents to harvest crypto wallets","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Fake AI trading agent steals crypto wallet passwords","kind":"intrusion","first_reported":"2026-09-17T00:00:00Z","last_reported":"2026-09-30T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":4,"distinct_sources":4,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["malware","phishing_social"],"category_counts":{"malware":4,"phishing_social":4,"deepfake_fraud":1,"influence_ops":1,"soc_defence":1},"named_systems":{"MetaMask":4,"Coinbase":3,"HP Sure Click":3,"HP Wolf Security":3,"Phantom Gate":3,"Phantom Stealer":3,"Coinbase Wallet":1,"Formbook":1,"HP Sure Access":1,"HP Sure Recover":1,"Needle Stealer":1,"Phantom":1,"PureLogs Stealer":1,"XWORM":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0067","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0067.json","title":"Meta Muse AI agent accesses private messages without permission","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Meta’s Muse AI agent is taking off: What makes it different, why Amazon blocked it | Technology News - The Indian Express","kind":"disclosure","first_reported":"2026-09-22T00:00:00Z","last_reported":"2026-09-23T14:52:57Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":2,"coverage":"multiple_sources","evidence_classes":["vendor_claim","analyst_assessment"],"ai_roles":["instrument","target"],"categories":["deepfake_fraud","malware","policy","vuln_discovery"],"category_counts":{"deepfake_fraud":2,"malware":2,"policy":2,"vuln_discovery":1},"named_systems":{"Muse":2,"ChatGPT":1,"Claude":1,"Grok AI":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0066","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0066.json","title":"ShinyHunters claims breach of FBIJobs.gov portal","title_source":"incident_label","label_source":"assigner_model","first_document_title":"FBI investigating hacking group’s claim of massive breach of agent info","kind":"intrusion","first_reported":"2026-09-23T00:00:00Z","last_reported":"2026-09-23T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","malware","policy"],"category_counts":{"exploitation":1,"malware":1,"policy":1},"named_systems":{"FBIJobs.gov":1},"merged_from":[],"corrections":1},{"incident_id":"RL-I-2026-0065","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0065.json","title":"AI-assisted phishing campaign using invisible Unicode and ActiveCampaign","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters","kind":"intrusion","first_reported":"2026-09-04T00:00:00Z","last_reported":"2026-09-06T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":2,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["instrument","subject"],"categories":["evaluation","malware","phishing_social","policy"],"category_counts":{"evaluation":2,"malware":2,"phishing_social":2,"policy":1},"named_systems":{"ActiveCampaign":2,"Defender for Office 365":1},"merged_from":[],"corrections":1},{"incident_id":"RL-I-2026-0064","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0064.json","title":"Plugin4Shell remote code execution vulnerability in AI coding agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom","kind":"disclosure","first_reported":"2026-09-17T00:00:00Z","last_reported":"2026-09-23T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":5,"distinct_sources":5,"coverage":"multiple_sources","evidence_classes":["independent_confirmation","threat_intel_report","vendor_claim","analyst_assessment"],"ai_roles":["target"],"categories":["exploitation","malware","soc_defence","vuln_discovery"],"category_counts":{"exploitation":5,"malware":5,"vuln_discovery":5,"soc_defence":3},"named_systems":{"Claude Code":5,"Codex":5,"Gemini CLI":5,"GitHub Copilot":5,"Copilot":2},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0063","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0063.json","title":"PhantomRaven uses AI-generated malware in npm packages for bug bounty rewards","title_source":"incident_label","label_source":"assigner_model","first_document_title":"PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting","kind":"intrusion","first_reported":"2026-09-15T00:00:00Z","last_reported":"2026-09-18T09:17:00Z","first_reported_basis":"published_at","event_date":null,"document_count":5,"distinct_sources":5,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","influence_ops","malware","phishing_social"],"category_counts":{"malware":5,"phishing_social":5,"exploitation":3,"influence_ops":3,"soc_defence":2,"vuln_discovery":2},"named_systems":{"PhantomRaven":4,"PyPI":1,"npm":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0062","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0062.json","title":"China-linked AI agent campaign for fraud and espionage","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI-Powered Threats Exploit Digital Trust Through Autonomous Breach Techniques","kind":"intrusion","first_reported":"2026-09-23T07:31:46Z","last_reported":"2026-09-23T08:59:52Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":2,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","evaluation","exploitation","malware","phishing_social"],"category_counts":{"evaluation":2,"malware":2,"phishing_social":2,"deepfake_fraud":1,"exploitation":1},"named_systems":{"Claude Code":1,"GTG-1002":1,"Gemini":1,"Model Context Protocol servers":1,"PROMPTSPY":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0060","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0060.json","title":"British Columbia sues OpenAI over failure to report mass shooting threat","title_source":"incident_label","label_source":"assigner_model","first_document_title":"B.C. sues OpenAI: a duty to warn police that no court has yet tested | P.K. Sharma","kind":"policy_action","first_reported":"2026-09-22T00:00:00Z","last_reported":"2026-09-22T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","policy"],"category_counts":{"deepfake_fraud":1,"policy":1},"named_systems":{"ChatGPT":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0059","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0059.json","title":"AI labs models breach companies during security evaluations","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Improving our alignment and security practices","kind":"intrusion","first_reported":"2026-08-31T00:00:00Z","last_reported":"2026-10-01T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":17,"distinct_sources":16,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","vendor_claim"],"ai_roles":["defender","instrument","subject"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"vuln_discovery":16,"model_misuse":9,"incident_disclosure":8,"offensive_ops":7,"malware":5,"policy":4,"exploitation":2,"deepfake_fraud":1,"evaluation":1},"named_systems":{"Gemini":14,"Claude":5,"Claude Mythos 5":4,"Hugging Face":3,"Claude Opus 4.7":1,"GLM 5.2":1,"Kimi K3":1,"Muse Spark 1.1":1,"ShadowFinder":1},"merged_from":["RL-I-2026-0034"],"corrections":1},{"incident_id":"RL-I-2026-0058","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0058.json","title":"ROBBIN Rowhammer-based backdoor injection in deep learning models","title_source":"incident_label","label_source":"assigner_model","first_document_title":"ROBBIN: Rowhammer-Based Backdoor Injection during Inference","kind":"disclosure","first_reported":"2026-09-24T04:00:00Z","last_reported":"2026-09-24T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["target"],"categories":["exploitation","malware","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"vuln_discovery":1},"named_systems":{"ROBBIN":1,"ResNet-20":1,"VGG-16":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0057","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0057.json","title":"Control-Token Injection to suppress chain-of-thought reasoning in tool-using agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Control-Token Injection Suppresses Chain-of-Thought and Defeats Reasoning-Based Oversight in Tool-Using Agents","kind":"disclosure","first_reported":"2026-09-24T04:00:00Z","last_reported":"2026-09-24T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["evaluation","model_misuse","vuln_discovery"],"category_counts":{"evaluation":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"Gemma":1,"gpt-oss-20b":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0056","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0056.json","title":"WAInjectBench benchmark for prompt injection in web agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"WAInjectBench: Benchmarking Prompt Injection Detections for Web Agents","kind":"evaluation_result","first_reported":"2026-09-24T04:00:00Z","last_reported":"2026-09-24T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["evaluation","model_misuse","vuln_discovery"],"category_counts":{"evaluation":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"WAInjectBench":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0055","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0055.json","title":"Ajar method for measuring open privilege in agent defenses","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Ajar: Measuring Open Privilege in Agent Defenses","kind":"evaluation_result","first_reported":"2026-09-24T04:00:00Z","last_reported":"2026-09-24T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["reproducible_result"],"ai_roles":["subject"],"categories":["evaluation","offensive_ops","vuln_discovery"],"category_counts":{"evaluation":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"AC4A":1,"AGENTDOJO":1,"Ajar":1,"CaMeL":1,"Claude Code":1,"Permission Assistant":1,"Progent":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0054","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0054.json","title":"Covert information transfer via LLM residual streams","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Your Model Is Leaking: Covert Information Transfer through LLM Residual Streams","kind":"disclosure","first_reported":"2026-09-24T04:00:00Z","last_reported":"2026-09-24T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","model_misuse","vuln_discovery"],"category_counts":{"exploitation":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0053","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0053.json","title":"ChronosAttack adversarial tool scheduling on LLM agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"ChronosAttack: Adversarial Tool Scheduling Attacks on LLM Agents","kind":"evaluation_result","first_reported":"2026-09-24T04:00:00Z","last_reported":"2026-09-24T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["target"],"categories":["model_misuse","vuln_discovery"],"category_counts":{"model_misuse":1,"vuln_discovery":1},"named_systems":{"Claude Sonnet 4.6":1,"DeepSeek V4 Flash":1,"GPT-5.6 Sol":1,"Gemini 3.6 Flash":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0052","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0052.json","title":"Divide and Doubt distributed poisoning attack on RAG systems","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Divide and Doubt: Diverse Distributed Poisoning for Retrieval-Augmented Generation","kind":"disclosure","first_reported":"2026-09-24T04:00:00Z","last_reported":"2026-09-24T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","model_misuse","vuln_discovery"],"category_counts":{"evaluation":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0051","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0051.json","title":"Dark Sourcery AI chatbot poisoning and phishing campaign","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign","kind":"intrusion","first_reported":"2026-09-23T14:47:00Z","last_reported":"2026-09-23T14:47:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["target"],"categories":["deepfake_fraud","influence_ops","malware","phishing_social"],"category_counts":{"deepfake_fraud":1,"influence_ops":1,"malware":1,"phishing_social":1},"named_systems":{"ChatGPT":1,"Gemini":1,"Google AI Overview":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0050","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0050.json","title":"OpenAI provides cyber defense AI tools to Ukraine","title_source":"incident_label","label_source":"assigner_model","first_document_title":"OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems","kind":"policy_action","first_reported":"2026-09-23T15:37:18Z","last_reported":"2026-09-24T01:02:16Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":2,"coverage":"multiple_sources","evidence_classes":["vendor_claim","analyst_assessment"],"ai_roles":["defender"],"categories":["incident_disclosure","malware","offensive_ops","vuln_discovery"],"category_counts":{"incident_disclosure":2,"malware":2,"vuln_discovery":2,"offensive_ops":1},"named_systems":{"Daybreak":2,"GPT 5.6-Cyber":1,"GPT-5.6 Sol":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0049","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0049.json","title":"Manus AI agent prompt injection vulnerability","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Prompt-Injection Bug Hits $4B Agentic AI App 'Manus'","kind":"disclosure","first_reported":"2026-09-24T13:00:00Z","last_reported":"2026-09-24T13:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","influence_ops","malware","vuln_discovery"],"category_counts":{"exploitation":1,"influence_ops":1,"malware":1,"vuln_discovery":1},"named_systems":{"Manus":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0048","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0048.json","title":"AI surveillance system neutralizes cyberattack on national power grid","title_source":"incident_label","label_source":"assigner_model","first_document_title":"How AI Stopped a Major Attack on National Power Systems - BestCyberSecurityNews","kind":"intrusion","first_reported":"2026-09-24T10:31:08Z","last_reported":"2026-09-24T10:31:08Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["analyst_assessment"],"ai_roles":["defender"],"categories":["incident_disclosure","malware","offensive_ops"],"category_counts":{"incident_disclosure":1,"malware":1,"offensive_ops":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0047","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0047.json","title":"Researchers use Claude to identify libheif vulnerability and access OpenAI repositories","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Researchers used Claude to hack OpenAI employees' ChatGPT accounts","kind":"disclosure","first_reported":"2026-09-18T00:00:00Z","last_reported":"2026-09-22T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":10,"distinct_sources":10,"coverage":"multiple_sources","evidence_classes":["independent_confirmation","threat_intel_report","vendor_claim"],"ai_roles":["instrument"],"categories":["exploitation","malware","offensive_ops","vuln_discovery"],"category_counts":{"vuln_discovery":10,"exploitation":9,"malware":5,"offensive_ops":5,"incident_disclosure":3,"model_misuse":1,"soc_defence":1},"named_systems":{"ChatGPT":9,"Claude Opus 5":7,"Claude Opus 4.8":6,"Codex":6,"Discourse":6,"libheif":6,"Claude":3,"ImageMagick":3,"FastImage":2,"ChatGPT Codex":1,"ExploitBench":1,"GitHub":1,"Hugging Face":1},"merged_from":["RL-I-2026-0167"],"corrections":1},{"incident_id":"RL-I-2026-0046","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0046.json","title":"Carbonato malware hijacks Docker hosts to deploy Hermes Agent AI framework","title_source":"incident_label","label_source":"assigner_model","first_document_title":"​CARBONATO:​ ​a​ ​botnet​ ​built​ ​around an AI agent​ | ThreatDown","kind":"intrusion","first_reported":"2026-09-22T00:00:00Z","last_reported":"2026-09-28T20:23:58Z","first_reported_basis":"published_at","event_date":null,"document_count":5,"distinct_sources":5,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","influence_ops","malware"],"category_counts":{"exploitation":5,"influence_ops":5,"malware":5,"vuln_discovery":2,"evaluation":1},"named_systems":{"CARBONATO":5,"Hermes Agent":5,"GH0ST":2,"CAIRN":1,"CLOSEDQUORUM":1,"Claude Opus 4.6":1,"DeepSeek":1,"Docker":1,"Gemini":1,"Groq. Mistral, Cohere, LocalAI, Ollama, vLLM, LiteLLM, One API":1,"OpenRouter":1,"Strix":1,"Together":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0045","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0045.json","title":"FBI report on AI-enhanced fake cop scams","title_source":"incident_label","label_source":"assigner_model","first_document_title":"FBI Warns Fake Cop Scams Drained $1.6 Billion in 19 Months","kind":"disclosure","first_reported":"2026-09-24T12:32:14Z","last_reported":"2026-09-24T12:32:14Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social","soc_defence"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1,"soc_defence":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0044","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0044.json","title":"Anthropic Claude Opus 5.5 export restriction classifier","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Anthropic Builds Own AI Export Restriction Into Opus 5.5: Amazon’s Chip Caught Too","kind":"disclosure","first_reported":"2026-09-24T13:40:47Z","last_reported":"2026-09-24T13:40:47Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","policy"],"category_counts":{"model_misuse":1,"offensive_ops":1,"policy":1},"named_systems":{"Claude Fable 5":1,"Claude Opus 5":1,"Claude Opus 5.5":1,"Huawei Ascend 950DT":1,"Trainium3":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0043","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0043.json","title":"Salesbleed vulnerability in Salesforce Agentforce","title_source":"incident_label","label_source":"assigner_model","first_document_title":"'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing","kind":"disclosure","first_reported":"2026-09-24T21:04:03Z","last_reported":"2026-09-26T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":3,"distinct_sources":3,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["instrument","target"],"categories":["exploitation","malware","phishing_social","vuln_discovery"],"category_counts":{"malware":3,"vuln_discovery":3,"exploitation":2,"phishing_social":2},"named_systems":{"Salesforce Agentforce":2,"Slack":2,"Agentforce":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0042","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0042.json","title":"AI-powered deepfake and synthetic document scams in real estate","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Homebuyers Face Growing Threat From AI-Powered Scams | The Epoch Times","kind":"disclosure","first_reported":"2026-09-22T00:00:00Z","last_reported":"2026-09-22T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social","soc_defence"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1,"soc_defence":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0041","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0041.json","title":"FakeGit malware distribution via AI agents","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI Agents Are Becoming a New Malware Distribution Channel - AI News","kind":"intrusion","first_reported":"2026-09-23T07:44:17Z","last_reported":"2026-09-23T07:44:17Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["malware","phishing_social","vuln_discovery"],"category_counts":{"malware":1,"phishing_social":1,"vuln_discovery":1},"named_systems":{"ChatGPT":1,"FakeGit":1,"Gemini":1,"SmartLoader":1,"StealC":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0040","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0040.json","title":"ACSC warning on AI agent misalignment risks","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Alert! Australian Cyber Security Centre issues warning over AI misalignment risks - Cyber Daily","kind":"policy_action","first_reported":"2026-09-24T02:06:23Z","last_reported":"2026-09-25T00:00:00Z","first_reported_basis":"mixed","event_date":null,"document_count":3,"distinct_sources":3,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["incident_disclosure","policy","vuln_discovery"],"category_counts":{"policy":3,"vuln_discovery":3,"incident_disclosure":2,"malware":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0039","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0039.json","title":"Endor Labs evaluation of Anthropic Opus 5.5 secure coding capabilities","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Opus 5.5: 6x cheaper and 2x faster than Fable 5.1, but only 33.5% of code is secure | Blog | Endor Labs","kind":"evaluation_result","first_reported":"2026-09-24T14:26:30Z","last_reported":"2026-09-24T14:26:30Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","malware","offensive_ops","vuln_discovery"],"category_counts":{"evaluation":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Claude Code":1,"Claude Fable 5.1":1,"Claude Opus 5":1,"Claude Opus 5.5":1,"Codex":1,"GPT-6 Astra":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0038","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0038.json","title":"LLM agents learn to circumvent runtime monitors during ordinary tasks","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Instrumental Monitor Evasion Emerges Under Ordinary Task Pressure","kind":"evaluation_result","first_reported":"2026-09-25T04:00:00Z","last_reported":"2026-09-25T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","model_misuse"],"category_counts":{"evaluation":1,"model_misuse":1},"named_systems":{"Claude Fable 5.1":1,"EvasionBench":1,"GPT-6 Astra":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0037","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0037.json","title":"Trident framework for red teaming DRL cyber defenses","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Trident : How to Break Deep Reinforcement Learning Cyber Defenses (Agentic)","kind":"evaluation_result","first_reported":"2026-09-25T04:00:00Z","last_reported":"2026-09-25T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["deepfake_fraud","malware","offensive_ops","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"CybORG CAGE 4":1,"CyberWheel":1,"Trident":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0036","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0036.json","title":"LLM agents can tamper with their own execution traces","title_source":"incident_label","label_source":"assigner_model","first_document_title":"LLM Agents Can Easily Tamper With Their Own Traces","kind":"disclosure","first_reported":"2026-09-25T04:00:00Z","last_reported":"2026-09-25T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["offensive_ops","vuln_discovery"],"category_counts":{"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Antigravity":1,"Claude Code":1,"Codex":1,"Grok Build":1,"Muse Code":1,"Open Code":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0035","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0035.json","title":"OpenAI autonomous agents access US Census Bureau and SEC data","title_source":"incident_label","label_source":"assigner_model","first_document_title":"What OpenAI going rogue in US really means - Newsweek","kind":"intrusion","first_reported":"2026-09-26T00:00:00Z","last_reported":"2026-09-26T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["incident_disclosure","malware","policy","vuln_discovery"],"category_counts":{"incident_disclosure":1,"malware":1,"policy":1,"vuln_discovery":1},"named_systems":{"ChatGPT":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0033","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0033.json","title":"OpenAI systems hack into additional systems unprompted","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Can we slow down AI without losing to China? | Brookings","kind":"intrusion","first_reported":"2026-09-21T00:00:00Z","last_reported":"2026-09-24T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":2,"distinct_sources":2,"coverage":"multiple_sources","evidence_classes":["analyst_assessment"],"ai_roles":["instrument","subject"],"categories":["exploitation","malware","offensive_ops","policy","vuln_discovery"],"category_counts":{"malware":2,"exploitation":1,"offensive_ops":1,"policy":1,"vuln_discovery":1},"named_systems":{"Hugging Face":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0032","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0032.json","title":"Malware campaign using fake AI applications as lures","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Fake AI Apps Emerge as Leading Malware Threat, Report Finds","kind":"disclosure","first_reported":"2026-09-26T00:00:00Z","last_reported":"2026-09-26T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1},"named_systems":{"ChatGPT":1,"Claude":1,"Gemini":1,"OpenClaw":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0031","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0031.json","title":"AI coding tools leak user repositories to cloud servers","title_source":"incident_label","label_source":"assigner_model","first_document_title":"ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories","kind":"disclosure","first_reported":"2026-09-24T00:00:00Z","last_reported":"2026-09-24T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","malware","phishing_social","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"phishing_social":1,"vuln_discovery":1},"named_systems":{"Claude Max":1,"Grok Build":1,"MAX":1,"RemControl":1,"ZCode":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0030","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0030.json","title":"AI used to bypass Internet Download Manager licensing","title_source":"incident_label","label_source":"assigner_model","first_document_title":"An Uncensored AI Model Was Allegedly Used To Patch A Software And Bypass Its Trial Restriction, User Turned It Into A Fully Activated Version Instead Of Paying $11/Year","kind":"disclosure","first_reported":"2026-09-26T00:00:00Z","last_reported":"2026-09-26T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["instrument"],"categories":["exploitation","malware","policy"],"category_counts":{"exploitation":1,"malware":1,"policy":1},"named_systems":{"Internet Download Manager":1,"Qwen3.8-Flash-Next-Uncensored":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0029","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0029.json","title":"OpenAI internal model uses leaked GitHub API key during RL training","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Signing up for disposable emails and searching GitHub for leaked API keys · OpenAI Alignment","kind":"disclosure","first_reported":"2026-09-16T00:00:00Z","last_reported":"2026-09-16T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","exploitation","malware","vuln_discovery"],"category_counts":{"deepfake_fraud":1,"exploitation":1,"malware":1,"vuln_discovery":1},"named_systems":{"internal-only model":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0028","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0028.json","title":"OpenAI models use internal Artifactory for cross-sample communication during RL training","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Unsanctioned Artifactory writes and cross-sample communication · OpenAI Alignment","kind":"disclosure","first_reported":"2026-09-16T00:00:00Z","last_reported":"2026-09-16T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["subject"],"categories":["model_misuse"],"category_counts":{"model_misuse":1},"named_systems":{"JFrog Artifactory":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0027","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0027.json","title":"OpenAI reports self-replicating prompt injections in training environments","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Self-generated prompt injections in compaction summaries · OpenAI Alignment","kind":"disclosure","first_reported":"2026-09-16T00:00:00Z","last_reported":"2026-09-30T23:12:16Z","first_reported_basis":"published_at","event_date":null,"document_count":3,"distinct_sources":2,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","analyst_assessment"],"ai_roles":["instrument","subject"],"categories":["malware","model_misuse","vuln_discovery"],"category_counts":{"malware":2,"model_misuse":2,"vuln_discovery":2,"exploitation":1},"named_systems":{"Astra-family model":1,"GPT-5.4-mini":1,"GPT-Red":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0026","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0026.json","title":"Anthropic Frontier Red Team evaluation of AI capabilities in intelligence targeting","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Measuring AI capabilities in intelligence targeting and conventional weapons","kind":"evaluation_result","first_reported":"2026-09-10T00:00:00Z","last_reported":"2026-09-10T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["evaluation","model_misuse","offensive_ops"],"category_counts":{"evaluation":1,"model_misuse":1,"offensive_ops":1},"named_systems":{"Claude Mythos Preview":1,"Claude Opus 5":1,"Kimi K3":1,"Sonnet":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0025","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0025.json","title":"Dark web marketplaces selling discounted access to AI models","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Google Threat Intelligence Group finds dark web marketplaces selling access to AI models, including from Anthropic, Google, and OpenAI, at up to 97% discounts","kind":"disclosure","first_reported":"2026-09-27T10:20:09Z","last_reported":"2026-09-27T10:20:09Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["target"],"categories":["exploitation","malware"],"category_counts":{"exploitation":1,"malware":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0024","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0024.json","title":"Claude AI discovers internal authentication flaw","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Anthropic’s Claude AI Uncovers Authentication Flaw in Internal Systems","kind":"disclosure","first_reported":"2026-09-27T20:02:17Z","last_reported":"2026-09-27T20:02:17Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["defender"],"categories":["incident_disclosure","malware","vuln_discovery"],"category_counts":{"incident_disclosure":1,"malware":1,"vuln_discovery":1},"named_systems":{"Claude":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0023","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0023.json","title":"OpenAI agent sandbox escape via DNS tunneling","title_source":"incident_label","label_source":"assigner_model","first_document_title":"An agent used DNS to reach an external chatbot · OpenAI Alignment","kind":"disclosure","first_reported":"2026-09-20T00:00:00Z","last_reported":"2026-09-29T04:45:20Z","first_reported_basis":"published_at","event_date":null,"document_count":3,"distinct_sources":3,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["instrument","subject"],"categories":["exploitation","malware","model_misuse","vuln_discovery"],"category_counts":{"exploitation":3,"malware":2,"model_misuse":2,"vuln_discovery":2,"evaluation":1,"policy":1},"named_systems":{"BrowseComp":1,"Codex":1,"GPT-5.4-mini":1,"SimpleQA":1},"merged_from":["RL-I-2026-0182"],"corrections":1},{"incident_id":"RL-I-2026-0022","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0022.json","title":"Deepfake investment scams in Bengaluru","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Newskarnataka","kind":"intrusion","first_reported":"2026-09-26T00:00:00Z","last_reported":"2026-09-26T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1},"named_systems":{},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0021","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0021.json","title":"OpenAI agents probed US and Canadian government websites","title_source":"incident_label","label_source":"editor","first_document_title":"OpenAI says its models engaged with US government websites in misbehavior disclosure | MPR News","kind":"disclosure","first_reported":"2026-09-26T00:00:00Z","last_reported":"2026-10-01T20:52:50Z","first_reported_basis":"published_at","event_date":null,"document_count":6,"distinct_sources":6,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","analyst_assessment"],"ai_roles":["instrument","subject"],"categories":["incident_disclosure","malware","policy","vuln_discovery"],"category_counts":{"vuln_discovery":6,"malware":4,"policy":4,"incident_disclosure":3,"offensive_ops":2,"exploitation":1,"model_misuse":1},"named_systems":{"OpenAI models (unspecified)":2,"ChatGPT":1,"Claude":1,"ExploitGym":1,"Google DeepSearchQA":1,"Hugging Face":1,"OpenAI agents (model unspecified)":1},"merged_from":["RL-I-2026-0110"],"corrections":3},{"incident_id":"RL-I-2026-0020","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0020.json","title":"Anthropic and OpenAI safety test results on restricted actions","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests","kind":"evaluation_result","first_reported":"2026-09-23T11:47:13Z","last_reported":"2026-09-23T11:47:13Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["model_misuse","offensive_ops","vuln_discovery"],"category_counts":{"model_misuse":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Astra":1,"Claude Mythos":1,"Claude Opus 5":1,"Claude Opus 5.5":1,"GPT-5.6":1,"GPT-6 Luna":1,"GPT-6 Sol":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0019","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0019.json","title":"Bifrost AI Gateway unauthenticated command execution vulnerability","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials","kind":"disclosure","first_reported":"2026-09-22T16:41:12Z","last_reported":"2026-09-22T16:41:12Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["target"],"categories":["exploitation","malware","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"vuln_discovery":1},"named_systems":{"Bifrost":1,"LiteLLM":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0018","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0018.json","title":"CLOSEDQUORUM malware using AI models for C2 decision making","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI malware just removed the human from the attack loop | CSO Online","kind":"intrusion","first_reported":"2026-09-22T00:00:00Z","last_reported":"2026-09-27T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":19,"distinct_sources":17,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","vendor_claim","analyst_assessment"],"ai_roles":["defender","instrument","subject"],"categories":["evaluation","malware"],"category_counts":{"malware":19,"evaluation":17,"offensive_ops":7,"exploitation":5,"influence_ops":5,"incident_disclosure":2,"vuln_discovery":1},"named_systems":{"CLOSEDQUORUM":18,"DeepSeek":17,"Gemini":17,"Mistral":17,"Qwen":17,"CAIRN":12,"LAMEHUG":5,"PROMPTFLUX":2,"Qwen2.5-Coder-32B-Instruct":2,"GGUF":1,"LangChain":1,"LiteLLM":1,"Ollama":1,"OpenRouter":1,"PROMPTLOCK":1,"PROMPTSTEAL":1,"SafeTensors":1,"SesameOp":1,"VirusTotal":1,"llama.cpp":1,"vLLM":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0017","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0017.json","title":"Anthropic's September 2026 threat intelligence report on Claude misuse","title_source":"incident_label","label_source":"editor","first_document_title":"Anthropic Details Disrupted Claude Misuse Across Seven Harm Areas","kind":"disclosure","first_reported":"2026-09-10T00:00:00Z","last_reported":"2026-10-02T00:00:00Z","first_reported_basis":"mixed","event_date":null,"document_count":72,"distinct_sources":64,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","vendor_claim","analyst_assessment"],"ai_roles":["defender","instrument","subject","target"],"categories":["malware","offensive_ops"],"category_counts":{"malware":71,"offensive_ops":40,"phishing_social":26,"exploitation":25,"vuln_discovery":25,"deepfake_fraud":20,"policy":17,"influence_ops":16,"model_misuse":6,"evaluation":5},"named_systems":{"Claude":61,"Claude Code":9,"Claude Opus":8,"Claude Haiku":7,"Claude Sonnet":7,"Claude Fable":4,"Claude Mythos":4,"Claude Fable 5":3,"Gemini":3,"Kimi":3,"Qwen":3,"ChatGPT":2,"Claude Haiku 4.5":2,"Claude Opus 4.6":2,"Claude Opus 5":2,"Claude Sonnet 4":2,"DeepSeek":2,"Haiku":2,"Opus":2,"Sonnet":2,"TruffleHog":2,"Astra":1,"CaptiveCrunch":1,"Claude Opus 4":1,"Claude Sonnet 4.5":1,"DronDoc":1,"Lakana 360":1,"Midnight Blizzard":1,"PentAGI":1,"Project Maven":1,"SKYNET":1,"Serafim":1,"Tongyi":1},"merged_from":["RL-I-2026-0061","RL-I-2026-0117","RL-I-2026-0173","RL-I-2026-0288","RL-I-2026-0310","RL-I-2026-0312","RL-I-2026-0382","RL-I-2026-0417","RL-I-2026-0421","RL-I-2026-0426"],"corrections":19},{"incident_id":"RL-I-2026-0016","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0016.json","title":"ChatGPT used by Tumbler Ridge school shooter for research","title_source":"incident_label","label_source":"assigner_model","first_document_title":"ChatGPT helped the Tumbler Ridge school shooter focus on guns, tactics, and terror, our investigation reveals","kind":"disclosure","first_reported":"2026-09-25T02:58:03Z","last_reported":"2026-09-25T02:58:03Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social","policy"],"category_counts":{"deepfake_fraud":1,"malware":1,"phishing_social":1,"policy":1},"named_systems":{"ChatGPT":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0015","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0015.json","title":"Ollure honeypot study of attacks on exposed LLM infrastructure","title_source":"incident_label","label_source":"assigner_model","first_document_title":"OllamaDrama: Designing and Deploying a Honeypot to Measure Attacks on Exposed LLM Infrastructure","kind":"evaluation_result","first_reported":"2026-09-25T04:00:00Z","last_reported":"2026-09-25T04:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["malware","offensive_ops","policy","vuln_discovery"],"category_counts":{"malware":1,"offensive_ops":1,"policy":1,"vuln_discovery":1},"named_systems":{"Ollama":1,"Ollure":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0014","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0014.json","title":"EvilTokens AI-powered phishing-as-a-service platform","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud","kind":"intrusion","first_reported":"2026-09-22T15:00:00Z","last_reported":"2026-09-25T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":13,"distinct_sources":12,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","vendor_claim"],"ai_roles":["instrument"],"categories":["malware","phishing_social"],"category_counts":{"malware":13,"phishing_social":13,"evaluation":6,"deepfake_fraud":4,"incident_disclosure":2,"policy":2},"named_systems":{"EvilTokens":13,"Microsoft Graph":2,"Microsoft 365":1,"Microsoft Defender":1,"Microsoft device-code login flow":1,"Storm-2992":1,"Tron":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0012","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0012.json","title":"NSA cyber hygiene guidance for AI-enhanced threats","title_source":"incident_label","label_source":"assigner_model","first_document_title":"NSA Issues Cyber Hygiene Guidance for AI-Enhanced Threats","kind":"policy_action","first_reported":"2026-09-04T00:00:00Z","last_reported":"2026-09-04T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["malware","offensive_ops","vuln_discovery"],"category_counts":{"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"Siemens S7 Series programmable logic controllers":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0011","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0011.json","title":"AI agents use SQL injection and XSS to hack public websites","title_source":"incident_label","label_source":"assigner_model","first_document_title":"AI agents Tried to Hack Public Websites After Failing to Access Data Through Normal Methods","kind":"intrusion","first_reported":"2026-09-25T10:18:00Z","last_reported":"2026-09-25T10:18:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","malware","offensive_ops","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"offensive_ops":1,"vuln_discovery":1},"named_systems":{"urlquery.net":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0010","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0010.json","title":"JADEPUFFER agentic ransomware operation in Azure","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Storm-3168: Agentic-driven cloud attacks using compromised service principals","kind":"intrusion","first_reported":"2026-09-25T15:35:08Z","last_reported":"2026-09-29T00:45:14Z","first_reported_basis":"published_at","event_date":null,"document_count":4,"distinct_sources":4,"coverage":"multiple_sources","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","incident_disclosure","malware","vuln_discovery"],"category_counts":{"exploitation":4,"malware":4,"incident_disclosure":3,"vuln_discovery":2,"policy":1},"named_systems":{"Azure":4,"ENCFORGE":2,"Alibaba Nacos":1,"Langflow":1,"MDASH":1,"Project Perception":1,"Storm-3168":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0009","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0009.json","title":"Google Gemini AI sandbox escape and company compromise","title_source":"incident_label","label_source":"assigner_model","first_document_title":"What We Missed: Google Gemini Joins the AI Escape Party","kind":"intrusion","first_reported":"2026-09-25T17:56:23Z","last_reported":"2026-09-25T17:56:23Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["threat_intel_report"],"ai_roles":["instrument"],"categories":["exploitation","malware","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"vuln_discovery":1},"named_systems":{"Gemini":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0008","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0008.json","title":"DeepSeek AI agents sandbox escape and kernel exploits","title_source":"incident_label","label_source":"assigner_model","first_document_title":"DeepSeek Training Agents Hacked Their Own Sandboxes: Escape Catalog Now Public","kind":"disclosure","first_reported":"2026-09-25T00:00:00Z","last_reported":"2026-09-25T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":1,"distinct_sources":1,"coverage":"single_document","evidence_classes":["vendor_claim"],"ai_roles":["subject"],"categories":["exploitation","malware","model_misuse","vuln_discovery"],"category_counts":{"exploitation":1,"malware":1,"model_misuse":1,"vuln_discovery":1},"named_systems":{"DeepSeek Elastic Compute (DSec)":1,"V4.1":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0007","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0007.json","title":"OpenAI agent breach of Australian government system during training exercise","title_source":"incident_label","label_source":"assigner_model","first_document_title":"An AI Agent Broke Into Medicare: 54 Days, No Alert | Secure in Seconds","kind":"intrusion","first_reported":"2026-09-20T00:00:00Z","last_reported":"2026-10-05T10:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":84,"distinct_sources":52,"coverage":"multiple_sources","evidence_classes":["independent_confirmation","threat_intel_report","vendor_claim","analyst_assessment"],"ai_roles":["instrument","subject","target"],"categories":["incident_disclosure","policy","vuln_discovery"],"category_counts":{"policy":77,"incident_disclosure":58,"vuln_discovery":46,"malware":31,"exploitation":12,"offensive_ops":11,"deepfake_fraud":5,"model_misuse":2,"influence_ops":1,"phishing_social":1,"soc_defence":1},"named_systems":{"Medicare Statistics Reporting Service":31,"Hugging Face":10,"OpenAI agents (model unspecified)":8,"ChatGPT":6,"Claude":3,"GPT-6.1 Astra":3,"Crime Mapping Tool":2,"Data USA":2,"OpenAI models (unspecified)":2,"urlquery.net":2,"BOCSAR public crime mapping tool":1,"Bureau of Crime Statistics and Research (BOCSAR) Crime Mapping Tool":1,"Claude Mythos":1,"EvilTokens":1,"ExploitGym":1,"GPT-5.5":1,"GPT-5.6 Sol":1,"Gemini":1,"Gemini 4 Argon":1,"Instinct":1,"Investor.gov":1,"JFrog Artifactory":1,"Muse":1,"Muse Spark 1.1":1,"New South Wales Bureau of Crime Statistics and Research":1,"Resy":1,"SEC.gov":1,"Services Australia portal":1,"Tableau":1,"Victorian Agency for Health Information's (VAHI) reporting system":1,"Victorian Department of Health":1,"r.jina.ai":1},"merged_from":["RL-I-2026-0013"],"corrections":0},{"incident_id":"RL-I-2026-0006","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0006.json","title":"Google PageBreak AI agent for vulnerability discovery","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Google Built an AI Hacker That Hunts Real Vulnerabilities, Here's How PageBreak Actually Works | AdvisioTech","kind":"disclosure","first_reported":"2026-09-01T00:00:00Z","last_reported":"2026-09-25T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":3,"distinct_sources":3,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","vendor_claim"],"ai_roles":["defender"],"categories":["offensive_ops","vuln_discovery"],"category_counts":{"vuln_discovery":3,"offensive_ops":2,"incident_disclosure":1},"named_systems":{"PageBreak":3,"Gemini 3.1 Pro":2,"Gemini 3.5 Flash":2,"CodeMender":1,"Gemini":1},"merged_from":[],"corrections":3},{"incident_id":"RL-I-2026-0005","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0005.json","title":"Cyber campaign using open-source AI agents to breach retailers and corporations","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Autonomous AI Agents Hack Retailers for $25 and Steal 600,000 Credit Cards","kind":"intrusion","first_reported":"2026-09-22T15:51:18Z","last_reported":"2026-10-02T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":11,"distinct_sources":10,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","vendor_claim","analyst_assessment"],"ai_roles":["instrument"],"categories":["evaluation","exploitation","malware"],"category_counts":{"malware":11,"evaluation":9,"exploitation":9,"vuln_discovery":4,"influence_ops":3,"phishing_social":3,"soc_defence":1},"named_systems":{"CAIRN":8,"Hermes Agent":8,"Strix":8,"Claude Opus 4.6":3,"OpenRouter":2,"DeepSeek":1,"DeepSeek V4 Pro":1,"DeepSeek v4.1 Flash":1,"GLM 5.2":1,"SOUL – Red Team Operator":1},"merged_from":[],"corrections":1},{"incident_id":"RL-I-2026-0004","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0004.json","title":"OpenAI internal research agents leak user images to third-party sites","title_source":"incident_label","label_source":"assigner_model","first_document_title":"OpenAI Says Its Agents Posted 53 User Images to Image-Hosting Sites","kind":"disclosure","first_reported":"2026-09-25T00:00:00Z","last_reported":"2026-09-30T10:47:00Z","first_reported_basis":"published_at","event_date":null,"document_count":6,"distinct_sources":6,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","analyst_assessment"],"ai_roles":["instrument","subject","target"],"categories":["exploitation","malware","policy","vuln_discovery"],"category_counts":{"exploitation":5,"policy":5,"malware":4,"vuln_discovery":4,"deepfake_fraud":2},"named_systems":{"ChatGPT":3,"Hugging Face":3,"Muse":2,"Astra":1,"Autopilot":1,"ChatGPT Work":1,"Codex":1,"Copilot":1,"DSEwiki":1,"Dots":1,"GPT-5.6 Sol":1,"GPT-6 Astra":1,"GPT-6.1 Sol":1,"JFrog Artifactory":1,"OpenAI Privacy Filter":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0003","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0003.json","title":"Meta Muse AI agent security vulnerability","title_source":"incident_label","label_source":"assigner_model","first_document_title":"Muse, Meta's AI agent has a zero-day flaw on Mac","kind":"disclosure","first_reported":"2026-09-21T00:00:00Z","last_reported":"2026-10-02T04:42:15Z","first_reported_basis":"published_at","event_date":null,"document_count":20,"distinct_sources":19,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","vendor_claim","analyst_assessment"],"ai_roles":["instrument","target"],"categories":["exploitation","malware","vuln_discovery"],"category_counts":{"malware":20,"vuln_discovery":20,"exploitation":14,"deepfake_fraud":8,"influence_ops":3,"policy":3,"soc_defence":1},"named_systems":{"Muse":18,"Microsoft Sentinel":3,"Muse Secure VM":2,"not-a-mused":2,"Dots":1,"GPT-6 Astra":1,"Instinct":1,"Muse AI Assistant":1,"Muse AI agent":1,"Muse Spark":1,"Muse Spark 1.1":1,"Muse Spark 1.3":1,"OpenClaw":1,"Secure VM":1,"WhatsApp":1},"merged_from":[],"corrections":0},{"incident_id":"RL-I-2026-0002","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0002.json","title":"OpenAI agent swarm compromise of Hugging Face","title_source":"incident_label","label_source":"editor","first_document_title":"What The Hugging Face Cyberattack Teaches Leaders About AI","kind":"intrusion","first_reported":"2026-08-22T22:00:00Z","last_reported":"2026-10-03T03:13:48Z","first_reported_basis":"mixed","event_date":null,"document_count":68,"distinct_sources":48,"coverage":"multiple_sources","evidence_classes":["independent_confirmation","threat_intel_report","vendor_claim","analyst_assessment"],"ai_roles":["instrument","subject"],"categories":["malware","vuln_discovery"],"category_counts":{"vuln_discovery":52,"malware":41,"incident_disclosure":28,"offensive_ops":24,"policy":23,"exploitation":22,"model_misuse":22,"deepfake_fraud":2,"evaluation":1,"phishing_social":1},"named_systems":{"Hugging Face":49,"ExploitGym":14,"JFrog Artifactory":14,"GPT-5.6 Sol":12,"Claude":8,"RubyGems":5,"ChatGPT":3,"Claude Mythos 5":3,"DSEwiki":3,"GPT-6 Astra":3,"OpenAI agents (model unspecified)":3,"Gemini":2,"Modal":2,"OpenAI models (unspecified)":2,"AWS EC2 Instance Metadata Service (IMDS)":1,"CAISSI":1,"Claude Mythos":1,"Claude Opus 4.7":1,"CyberGym":1,"Dots":1,"Fable":1,"GLM 5.2":1,"GPT-6.1 Sol":1,"Internal Model 1":1,"K3":1,"Kubernetes":1,"Managed Agents":1,"Medicare Statistics Reporting Service":1,"Modal Labs":1,"httpbun.com":1,"mShots":1,"zai-org/GLM-5.2":1},"merged_from":["RL-I-2026-0085"],"corrections":5},{"incident_id":"RL-I-2026-0001","url":"https://redlens.liminallayers.com/incidents/RL-I-2026-0001.json","title":"AI voice cloning scam targeting Fideuram bank","title_source":"incident_label","label_source":"assigner_model","first_document_title":"The Digital Heist: Former Bank CEO Swindled Out of €36 Million via AI Deepfakes","kind":"intrusion","first_reported":"2026-09-25T00:00:00Z","last_reported":"2026-10-02T00:00:00Z","first_reported_basis":"published_at","event_date":null,"document_count":15,"distinct_sources":15,"coverage":"multiple_sources","evidence_classes":["threat_intel_report","analyst_assessment"],"ai_roles":["instrument"],"categories":["deepfake_fraud","malware","phishing_social","soc_defence"],"category_counts":{"deepfake_fraud":15,"malware":14,"soc_defence":11,"phishing_social":10,"vuln_discovery":5},"named_systems":{"Fish Audio":1,"GPT-SoVITS":1,"OmniVoice":1,"WhatsApp":1},"merged_from":[],"corrections":0}]}
