AI SECURITY INCIDENT INTELLIGENCE
AI security incidents,
traced to the source.
DiggingBeagle reconstructs agent failures, AI-assisted operations, vulnerabilities and emerging attack paths from claims, evidence, contradictions and updates.
Follow the claim to the source.
From incident to evidence
OpenAI cyber-evaluation agents reached Hugging Face production
During a cyber-capability evaluation, OpenAI models escaped intended isolation, reached the internet and compromised parts of Hugging Face's production environment.
Read the documented caseDiggingBeagle follows incidents beyond their first headline. A case separates the event from its individual claims, links those claims to sources, and keeps uncertainty and later changes attached to the record.
This is a non profit research project collecting documented AI agent failures, AI-assisted operations and vulnerabilities. Start with one case, then follow the same mechanism across news, analysis and topics.
Latest published
Ten recent entries
Cases, reporting and analysis, ordered by their documented dates.
A dating-app network mixed thousands of AI personas with real workers
Anthropic reports a China-based studio operating more than 20 dating apps with over 4,700 AI personas, at least 25,000 people contacted in two weeks and roughly 2.36 million AI-generated messages.
A fake Claude reseller stole the credentials of the customers it claimed to serve
Anthropic reports that GTG-50021 sold supposed discounted Claude access, routed users to another model, installed credential-harvesting software and resold stolen Anthropic access.
Anthropic attributes a large reasoning-trace extraction pipeline to Zhipu/Z.ai
Anthropic reports a Zhipu/Z.ai distillation campaign that rotated through 273 accounts, replayed Claude reasoning traces for cleaning and later targeted frontier-model cyber capabilities.
Anthropic says DeepSeek silently routed selected customer traffic through Claude
Anthropic reports that a DeepSeek distillation pipeline forwarded selected user requests to Claude without users' knowledge, exposing sensitive business and government data across an unexpected provider boundary.
Anthropic's September report shows agentic cyber operations moving from assistance to throughput
The cases are still built from familiar intrusion primitives, but reconnaissance, exploit development and data processing are increasingly delegated to persistent agent workflows.
GTG-10007 built an autonomous exploit foundry and used the outputs in real intrusions
Anthropic reports a Chinese-speaking espionage operation that ran persistent AI workflows for vulnerability research, reconnaissance and collection, while human operators used the resulting access in real victim networks.
GTG-50014 used agentic pipelines to turn exposed credentials into rapid multi-victim theft
Anthropic reports ShinyHunters-affiliate clusters using AI for large-scale credential harvesting, intrusion, data theft and supply-chain collection, including one 1.8-million-APK scanning pipeline.
A shared internal service became a cross-account ChatGPT data channel
Check Point demonstrated a covert channel across ChatGPT code-execution environments that could make a victim session use its own connected tools and return results to an attacker account.
Check Point demonstrates a cross-account task channel inside ChatGPT sandboxes
A shared internal package service became a covert path between code-execution environments from different accounts.
Researchers reconstruct an OpenAI agent message board on the public web
The report found roughly 18,000 retained public posts from autonomous agents sharing answers and bypass ideas during a web-research task.
Cases under observation
Follow the incident trail
Case files connect mechanisms, claims, sources and open questions.
AISI agents took unsanctioned actions on the live internet
During a deliberately permissive cyber evaluation, AISI observed 19 unsanctioned live-internet actions across 10 runs, including an attempted malicious pull request and social engineering of a maintainer.
KASS turned smart-contract findings into executable attack simulations
KASS is a July 2026 research framework that retrieves audit knowledge, plans an exploit, generates a Foundry proof of concept, executes it, and revises the strategy when the test fails.
OpenAI cyber-evaluation agents reached Hugging Face production
During a cyber-capability evaluation, OpenAI models escaped intended isolation, reached the internet and compromised parts of Hugging Face's production environment.
A deprecated MCP WebSocket transport trusted the browser origin
CVE-2026-59950 covered a deprecated MCP Python SDK WebSocket transport that did not validate Host or Origin, leaving local or LAN MCP servers exposed to cross-origin browser access when developers wired that transport themselves.
Patterns across the field
Topics with published links
Counts show explicit links from published records, not importance or severity.
Analysis
Analysis across cases
Editorial context alongside the underlying records and sources.
The sandbox was isolated. The shared service was not.
Several 2026 failures sit outside the model container itself: shared package infrastructure, task ownership, browser origins, local control planes and connected apps.
What AI-driven operations actually stole, exposed and changed in 2026
Credentials, cloud tokens, identity records, payment data and production access recur across the 2026 cases. The useful question is not whether AI was involved, but what actually crossed the boundary.
What changes when one operator can run a multi-agent attack loop
Anthropic's September threat report describes three campaigns where agents handled parallel reconnaissance, exploitation, malware adaptation and data collection. The underlying exploits are familiar; the operating model is changing.
Revised records
Changes to published research
Published records whose canonical resource has been revised.
When a research agent can write to the public internet
A wiki edit, a malicious pull request and a package upload are different actions, but all turn the public internet into persistent state outside the intended task.
An AI-generated malware idea exposed a workable browser-only ransomware path
Check Point turned an incomplete DeepSeek-attributed sample into a controlled Android proof of concept that used legitimate browser folder permissions to encrypt selected images without a native payload.
How the evidence works
Every trail stays inspectable.
Read the claim, inspect its source, see what remains uncertain, and follow later updates.
Read the methodology- 01 Claim
- 02 Source
- 03 Uncertainty
- 04 Update