90 Incidents — July 2026

Click any incident to see the full analysis and RuntimeAI gap fix below. Left border colour = severity: Critical   High   Medium

Incidents 1–30
1
OpenAI
Jul 30
2
HuggingFace
Jul 30
3
HuggingFace
Jul 30
4
Revolut Data Breach? Hackers Claim 75 Millio…
Jul 30
5
MCBS Healthcare Data Breach Affects 1.26 Mil…
126M+Jul 30
6
Health-ISAC Warns of Rising ShinyHunters Dat…
Jul 30
7
Minnesota Water Utilities Hit by Coordinated…
Jul 30
8
NIST
Jul 30
9
IBM
Jul 30
10
Microsoft
Jul 30
11
Microsoft
Jul 30
12
The Network Has Become the Control Plane for…
Jul 30
13
Semiconductor Firm Analog Devices Discloses …
Jul 30
14
Microsoft
Jul 30
15
ShinyHunters Claims Brinks Home Breach, Thre…
Jul 30
16
South Korea Fines Telco Giant KT $39 Million…
Jul 30
17
OpenAI
Jul 25
18
HuggingFace
Jul 25
19
Claude Cowork Flaw Could Let AI Agent Escape…
Jul 25
20
Microsoft
Jul 25
21
Open-Source Android AI Agents Could Let Invi…
Jul 25RCE
22
Google
Jul 25
23
Anthropic
Jul 25
24
How Attackers Hosted a Fake Claude Download …
Jul 25
25
Microsoft
Jul 25
26
OpenAI
Jul 25
27
Censys Finds AI/LLM Tool Exposures Up More T…
Jul 25RCE
28
Azure
Jul 25
29
Suno, Paidwork Data Breaches Affect Tens of …
Jul 25
30
Chick-fil-A Data Breach Linked to Credential…
Jul 25
Incidents 31–60
31
Swiss Rail Giant Stadler Rejects $12.3M Rans…
Jul 25
32
Upbound Group Says Data Breach Led to $13 Mi…
Jul 25
33
OpenAI
Jul 24
34
Azure
Jul 24
35
Google
Jul 24
36
A Documented Agent-to-Agent Injection Path T…
Jul 24
37
Zero-Width and Hidden Characters Split What …
Jul 24
38
Screen-Text Injection Escalates From an On-D…
Jul 24RCE
39
Enterprise GenAI Adoption Is Amplifying Rans…
Jul 24
40
Microsoft
Jul 24
41
A New Crypter Built to Defeat Signature and …
Jul 24
42
Brand-Abuse Kit Turns a Trusted E-Sign Lure …
Jul 24
43
A Consumer-Grade Device Flaw Becomes a Suppl…
Jul 24
44
CISA
Jul 24RCE
45
A Firewall Auth-Bypass Becomes the Front Doo…
Jul 24RCE
46
Mass-Target Web RCE Now Weaponizable at Inte…
Jul 24RCE
47
Reused-Password Replay at Scale
Jul 24
48
A Consumer AI-Music Platform and a Gig-Work …
Jul 24
49
Nation-State-Grade Identity Exposure Across …
Jul 24
50
An OT-Adjacent Enterprise Refuses to Pay a M…
Jul 24
51
A Double-Extortion Crew Claims a Consumer-Go…
Jul 24
52
Google
Jul 17
53
Malware Family Ships Exploitation Modules wi…
Jul 17
54
Anthropic
Jul 17RCE
55
A Browser-Extension Bug Lets Any Other Exten…
Jul 17
56
One Poisoned Email Writes a False Memory the…
Jul 17
57
Data Injected Into the Agent’s Context Steer…
Jul 17
58
Attackers Bury Unicode and Hidden Markup Tha…
Jul 17
59
Microsoft
Jul 17
60
A Passive Enumeration Technique That Avoids …
Jul 17
Incidents 61–90
61
Zara
197K+Jul 17
62
Insurance-Sector Breach Exposes Licence Numb…
69M+Jul 17
63
Historic Genetic-PII Breach Payout Expands —…
Jul 17
64
Ransomware Reaches OT and Halts Milk Product…
Jul 17
65
Salesforce
Jul 17
66
High-Profile Social-Account Takeover Turns B…
Jul 17
67
Pre-Auth RCE Class in a Widely-Used Message …
Jul 17RCE
68
Zoom
Jul 17
69
A Persistent Backdoor Campaign Across Shared…
Jul 17
70
JadePuffer
Jul 10CVE-2026-55255RCE
71
Langflow
Jul 10CVE-2026-55255RCE
72
AI Defenders Subverted
Jul 10
73
Capable Open Chinese Models Lower the Cost o…
Jul 10
74
SkillCloak
Jul 10
75
GhostApproval
Jul 10
76
Phantom Squatting
Jul 10
77
GitHub Agentic Workflows
Jul 10RCE
78
GitHub Copilot
Jul 10
79
Januscape
Jul 10
80
Bad Epoll
Jul 10
81
BeyondTrust
Jul 10
82
The Identity Reckoning
Jul 10
83
Microsoft 365
365Jul 10
84
Accenture
Jul 10
85
KDDI
12M+Jul 10
86
AssuranceAmerica
Jul 10
87
Roundcube
Jul 10
88
GodDamn
Jul 10
89
Kairos
Jul 10
90
FortiBleed
Jul 10
CVE & RCE
CVEs (2)
CVE-2026-55255JadePuffer
CVE-2026-55255Langflow
RCE (11)
RCEOpen-Source Android AI Agents …Jul 25
RCECensys Finds AI/LLM Tool Expos…Jul 25
RCEScreen-Text Injection Escalate…Jul 24
RCECISAJul 24
RCEA Firewall Auth-Bypass Becomes…Jul 24
RCEMass-Target Web RCE Now Weapon…Jul 24
RCEAnthropicJul 17
RCEPre-Auth RCE Class in a Widely…Jul 17
RCEJadePufferJul 10
RCELangflowJul 10
RCEGitHub Agentic WorkflowsJul 10
Stack & Vendors
Vendors (3) — click to see breach
DevoOther
Microsoft, Censys Finds AI/LLM Tool… +2
ESETOther
Microsoft, AssuranceAmerica
BeyondTrustPAM
Bad Epoll, BeyondTrust
Perimeter Categories
Other 7PAM 2

The Pattern

This month’s incidents demonstrate a consistent pattern across all sectors: AI is now both the attack vector and the target. Enterprises with mature security stacks were breached through gaps those stacks were never designed to cover.

The 90 incidents collected this month span 33 named organizations, 207M+ records exposed, and 3 distinct security vendors present at time of breach. The pattern is not one of vendor failure — it is one of category gap.

What Would Have Stopped This — Full Capability Stack

Not “better security.” Nineteen specific capabilities across three platforms. Each addresses a gap that no vendor in this month’s breach stacks was built to cover — because AI agents didn’t exist when those vendors were designed.

RuntimeAI — AI Governance & Control Plane Enterprise AI agent governance — identity, policy, firewall, detection, response, compliance.
🔍
Shadow AI Visibility
AI Discovery
6
incidents this month · 7%
“You can’t govern what you can’t see.”
Continuously scans cloud, IDE, endpoint, and network to inventory every AI agent — registered or rogue. Classifies and risk-scores shadow AI automatically. One-click to import into governance.
⚠️ The gap it fills Wiz and Orca scan cloud misconfiguration. They don’t discover AI agents installed by developers or injected via compromised vendors. Your unknown agents are your biggest risk.
  • Cloud scanner (AWS/Azure/GCP Lambda, Bedrock, SageMaker)
  • IDE scanner (VS Code, Cursor, MCP servers)
  • Endpoint scanner on developer laptops
  • Shadow AI Inbox with auto-severity classification
  • One-click shadow AI → governed agent pipeline
🧽
AI Agent PKI
Agent Identity Fabric
34
incidents this month · 38%
“No credential. No access. No breach.”
Provisions every AI agent with a SPIFFE/X.509 cryptographic identity. Short-lived certs, auto-rotating. TPM 2.0 hardware attestation. Agent DNS blocks unknown agents at the network layer.
⚠️ The gap it fills Legacy identity providers were built for human identity. They have no concept of non-human agents operating at machine speed with no user present to respond to an MFA prompt.
  • SPIFFE X.509 SVID with RSA-2048, auto-rotating
  • TPM 2.0 hardware attestation + PCR drift detection
  • Zero-touch bootstrap for new agents
  • Agent DNS: NXDOMAIN for unknown agents
  • Blueprint-based permission inheritance
⚙️
Policy Engine
AI Control Plane
51
incidents this month · 57%
“Stop it before it executes. Not after.”
OPA/Rego policy engine with sub-1ms evaluation and fail-closed enforcement. Natural language to Rego compiler. Merkle-chain audit proves policies were never tampered with.
⚠️ The gap it fills Traditional SIEMs alert on what already happened — 73 days after the breach in the average case. The AI Control Plane enforces policy before the action executes, not after the damage is done.
  • OPA/Rego engine, sub-1ms, fail-closed
  • NL-to-Rego compiler: write policy in plain English
  • Merkle-chain tamper-evident audit trail
  • Multi-tenant RBAC + Separation of Duties
  • Cross-site policy cascade for distributed fleets
🔥
Bidirectional DLP
AI Firewall
68
incidents this month · 76%
“Inspect every token in, every token out.”
Bidirectional DLP scanning at <5ms latency. Prompt injection detected and stripped on input. PII, PHI, credentials caught on output. Behavioral risk score (0–100) triggers auto-suspend.
⚠️ The gap it fills Traditional NGFWs and CASBs see LLM traffic as an encrypted blob. They cannot inspect prompts, detect injection inside a conversation, or catch data leaking in an AI response.
  • Bidirectional DLP: input (prompt injection) + output (data leakage)
  • ML behavioral baselines per agent with adaptive thresholds
  • Risk score 0–100 triggers auto-suspend or rate-limit
  • No-code guardrail builder for business users
  • Data Proxy: field-level masking before agent sees data
🔗
MCP Gateway
AI Integration Fabric
53
incidents this month · 59%
“Every tool call. Governed.”
Multi-tenant governed gateway for all agent-to-tool communication. 500+ pre-built integrations. 3-level kill switch (agent / tool / platform-wide) propagating in <50ms. OWASP MCP03 sanitization on every call.
⚠️ The gap it fills No existing vendor governs at the MCP protocol layer. Raw MCP deployments have zero security, zero multi-tenancy, and zero audit trail. This is the fastest-growing unguarded attack surface in enterprise AI.
  • 3-level kill switch: per-agent, per-tool, platform-wide — all <50ms
  • 500+ pre-built integrations with auto-discovery
  • BYOM overlay: wrap existing MCPs without code changes
  • Circuit breaker + health monitoring per connection
  • Full OWASP MCP03 input/output sanitization + DLP
🧠
Anomaly Detection
Agent Behavioral Intel
52
incidents this month · 58%
“Catch drift before it becomes a breach.”
30-day rolling behavioral baselines per agent across frequency, pattern, volume, and temporal dimensions. LSTM sequence modeler detects multi-step attack chains. HRIS integration auto-suspends agents when their owner is terminated.
⚠️ The gap it fills Signature-based EDR detect known malware signatures for human endpoints. They have no baseline for an AI agent that begins exfiltrating data through an API it was legitimately authorized to call.
  • Rolling 30-day baseline: frequency, pattern, volume, temporal
  • LSTM sequence modeler for multi-step attack patterns
  • Composite risk score from 6 signals
  • HRIS integration: auto-suspend on employee termination (<30s)
  • Adaptive OPA thresholds by agent role + risk profile
🔴
Emergency Response
Kill Switch
16
incidents this month · 18%
“Stop any AI agent, anywhere, in under 50ms.”
Three graduated kill levels: per-agent, per-tool, platform-wide. All propagate via NATS JetStream in <50ms. Captures last 100 actions as forensic state. Quarantine mode preserves evidence for investigation.
⚠️ The gap it fills No competitor offers this. When an AI agent goes rogue — or when a breach is detected — you need a hard stop. Every second it keeps running is more data exfiltrated, more damage compounding.
  • L1/L2/L3 kill: per-agent, per-tool, platform — all <50ms via NATS
  • Forensic state capture: last 100 actions, memory snapshot, credentials
  • Quarantine mode: isolate for investigation, preserve evidence
  • Escalation chains: auto-response → SOC alert → human required → kill
  • Reprieve mechanism: 24-hour lease for controlled investigation post-kill
🚨
Incident Response
AI Respond
Universal
covers all incidents — audit + governance layer
“Autonomous incident response. AI-native.”
Five-phase automated playbook: DETECT → QUARANTINE → INVESTIGATE → REMEDIATE → VERIFY. Auto-classifies incidents (true positive / false positive / inconclusive). Blast radius containment automatically quarantines agents that interacted with compromised agent.
⚠️ The gap it fills Legacy SOAR platforms orchestrate traditional security events. They cannot terminate an AI agent, rotate its credentials, update its behavioral model, or quarantine the agents it spoke with — because they were built before AI agents existed.
  • 5-phase automated playbook from detection to verification
  • Auto-classification against 200+ known AI attack patterns
  • Blast radius containment: quarantine all interacting agents
  • True positive: terminate + revoke + rotate + update models
  • False positive feedback loop continuously improves detection
👥
Agent Lifecycle
AI Ops Center
1
incidents this month · 1%
“Mission control for autonomous AI operations.”
65+ page operational dashboard. Access review campaigns. ‘The Reaper’ auto-decommissions agents when their human owner is terminated. Vault Broker injects credentials with 5-minute TTL — never stored in agent memory.
⚠️ The gap it fills ServiceNow manages human IT requests on ticket-based cycles. AI agents are deployed, modified, and compromised in minutes. You need lifecycle governance that operates at agent speed, not ticket speed.
  • Access review campaigns with auto-apply decisions
  • ‘The Reaper’: HRIS webhook auto-revokes terminated employees’ agents (<30s)
  • Vault Broker: just-in-time 5-min TTL credential injection, never persisted
  • Per-tenant budget caps with 4-tier alerts (50/75/90/100%)
  • Unified health, credential lifecycle, budget, SLA dashboard
🌐
LLM Routing
LLM Broker
Universal
covers all incidents — audit + governance layer
“Route every LLM call to the right model, at the right cost, with automatic failover.”
Unified API routing LLM requests to the optimal provider based on cost, latency, and compliance. Semantic caching reduces redundant calls 15–30%. Automatic failover in <50ms. Budget enforcement with hard limits.
⚠️ The gap it fills Portkey does basic routing at $30K/year. It has no DLP scanning, no compliance-based routing (data residency), no semantic caching, and no budget enforcement. It routes traffic — it doesn’t govern it.
  • Multi-provider routing: OpenAI, Anthropic, Bedrock, Azure, GCP, custom
  • Cost/latency/compliance-based routing policies
  • Automatic failover <50ms; per-provider circuit breaker
  • Semantic caching: 0.80–0.95 similarity threshold, 15–30% cache hits
  • Budget enforcement per-agent + cost anomaly detection
🤖
MLOps
ML Intelligence Hub
13
incidents this month · 14%
“Model registry, feature store, edge inference — one platform.”
Formal model lifecycle (draft/staging/production/archived). Feature Store with online (<5ms) and offline serving. Hybrid scoring engine routes inference between edge (<1ms quantized) and cloud. Drift-triggered auto-retraining.
⚠️ The gap it fills MLflow + Feast + custom inference each solve one piece. ML Intelligence Hub is the piece nobody built: unified lifecycle + edge inference routing + drift-triggered retraining + 7-dimension cost attribution — all integrated.
  • Model Registry: versioning, rollback, lineage, lifecycle management
  • Hybrid Scoring: edge <1ms quantized vs cloud full-precision auto-routing
  • Feature Store: online <5ms + offline point-in-time with freshness monitoring
  • Drift Engine integration: auto-retraining on data/concept drift
  • 7-dimension cost attribution: agent/model/team/customer/feature/time/provider
💰
FinOps
AI Cost Intelligence
Universal
covers all incidents — audit + governance layer
“A cost spike is a security signal. Treat it like one.”
7-dimension real-time cost attribution: agent, provider, model, team, customer, feature, time. Wasm token counter in-proxy at 50–100 microseconds. Budget hard limits stop agents before they overspend. Runaway agent detection.
⚠️ The gap it fills Kubecost knows GPU-hours. AI Cost Intelligence knows “Agent-47 spent $142 on Claude Sonnet for fraud detection on Tuesday.” Runaway cost is runaway behavior — and only one product treats them as the same signal.
  • Wasm token counter in proxy: 50–100 microsecond overhead
  • Live model pricing catalog: 200+ models, 15+ providers, updated every 15min
  • Budget hard limits: block requests when agent exhausts budget
  • Cost anomaly detection: ML-based spending spike alerts
  • Chargeback engine: per-customer invoices + per-team internal allocation
📋
Continuous Compliance
AI Compliance Hub
90
incidents this month · 100%
“Audit evidence as a byproduct of governance.”
Continuous compliance across 13+ frameworks — SOC 2, FedRAMP, ISO 27001/42001, EU AI Act, HIPAA, PCI-DSS, NIST AI RMF. Evidence auto-generated from RuntimeAI telemetry. Open Audit Marketplace connects enterprises with certified audit firms.
⚠️ The gap it fills Vanta collects attestations from cloud infrastructure. It has no understanding of AI agent behavior, no EU AI Act or ISO 42001 mappings, and no way to generate evidence from an AI governance layer — because none of its customers had one.
  • 13+ frameworks: SOC 2, FedRAMP, ISO 27001/42001, EU AI Act, HIPAA, PCI-DSS, NIST AI RMF
  • Evidence auto-generated from platform telemetry (audit trails, Merkle chain, access reviews)
  • Gap tracking with SLA-based remediation assignment
  • Audit Marketplace: open to any qualified audit firm; time-limited scoped access
  • Blockchain-anchored compliance certificates with tamper-evidence verification
🏪
Agent Procurement
Agent Marketplace
6
incidents this month · 7%
“Only certified agents enter your environment.”
Three-sided platform: Builders publish, Enterprises deploy, Trust layer certifies. AAIC certification includes third-party behavioral audit. Risk scoring weights permission scope, data access, integration breadth, update frequency, and builder reputation.
⚠️ The gap it fills Your developers are installing AI agents from GitHub, npm, and PyPI with no security review. The AI agent supply chain attack surface is the same as software supply chain — and it’s moving five times faster.
  • 6-step publishing wizard with compliance gating
  • AAIC certification: third-party behavioral audit by registered firms
  • Risk scoring: permission scope (30%), data access (25%), integration (20%), frequency (10%), reputation (10%)
  • Shadow AI Import: discover unmanaged agents and bring into governance
  • Stripe Connect billing: free/per-seat/per-action/outcome-based; 20% platform fee
Agentic Enablement Platform (AEP) Agentic-era security primitives — NHI identity, fraud detection, memory governance, agent commerce.
🔑
Non-Human Identity
NHI Security Platform
25
incidents this month · 28%
“Every non-human identity — issued, governed, and revoked with the same rigor as human identity.”
Centralized governance for every non-human identity: service accounts, API keys, OAuth tokens, machine certs, cloud IAM roles, AI agents. Bot-CA issues short-lived X.509 SPIFFE certs. O(1) hash-based revocation — not cascading policy lookups.
⚠️ The gap it fills Oasis Security ($190K/year) solves NHI credentialing but not for AI agents specifically. It lacks TPM hardware attestation, has no AI-agent behavioral monitoring, and doesn’t integrate with agent governance platforms.
  • Centralized NHI Registry: auto-discovery across AWS/Azure/GCP/on-prem
  • Credential posture: rotation schedules, expiry, over-privilege, unused credential detection
  • NHI Drift Detection: per-NHI behavioral baseline + scope creep detection
  • Bot-CA: short-lived X.509 certs (1–24hr TTL), auto-rotating, instant OCSP revocation
  • O(1) hash-based revocation: per-NHI, per-tenant, or global — no cascading policy lookup
🛡️
AI Fraud Detection
Fraud Shields
23
incidents this month · 26%
“Valid credential. Wrong behavior. Caught.”
Two-layer defense: Identity Fraud Shield models valid-credential-wrong-behavior (the hallmark of compromised AI credentials). Activity Fraud Shield detects multi-step attack sequences within authenticated sessions. Both integrate directly with Kill Switch for automatic response.
⚠️ The gap it fills Generic UEBA tools applied to AI agents generate massive false-positive rates because they were trained on human behavior. Fraud Shields are AI-native: LSTM sequence modeling of API chains, not user session patterns.
  • Per-agent behavioral baseline: frequency, resource access, API sequences, timing
  • Real-time deviation scoring against baseline (0–100)
  • LSTM sequence modeler: multi-step attack chain detection (recon→escalation→exfil)
  • Session-level anomaly: full context analysis, not individual events
  • Kill Switch integration: auto-suspension on high-confidence fraud with forensic package
🧠
Agent Memory Security
Memory Vault
26
incidents this month · 29%
“Control what your agents remember — and what they forget.”
Governs agent memory as a first-class security object. Policy-based filtering of sensitive content at write time. Memory poisoning attack detection. TTL-based automatic purge with audit trail. GDPR right-to-erasure support.
⚠️ The gap it fills No vendor addresses agent memory governance. AI agent memories accumulate without access controls, expiry policies, or audit trails. A memory poisoning attack can corrupt an agent’s behavior without touching a single API key.
  • Policy-based memory write filtering (PII, PHI, secrets blocked at write)
  • PII Shield integration: redact/block before persistence
  • Memory expiry + TTL: auto-purge with full audit trail
  • Memory poisoning prevention: adversarial injection detection
  • Retrieval authorization: every memory read policy-enforced and logged
💳
Agent Finance Controls
Commerce Rails
16
incidents this month · 18%
“Give AI agents a wallet — with guardrails.”
Financial infrastructure for agent-initiated transactions. Per-agent virtual cards with spend limits. Vendor registry (agents can only transact with allowlisted merchants). Approval gates for high-value transactions. Every transaction in immutable ledger.
⚠️ The gap it fills No financial controls exist for AI agents today. Agents authorized to make purchases can spend without limit, with any vendor, at any time. One prompt injection or runaway loop away from significant financial exposure.
  • Agent virtual cards: per-agent card numbers + CVVs, hard spend limits
  • Vendor registry: allowlisted merchants only, no ad-hoc transactions
  • Approval gates: high-value + out-of-policy → human approval before execution
  • Per-agent, per-transaction, per-vendor, per-period limits
  • Agent-to-agent settlement ledger: feeds into FinOps dashboards
PQData — Post-Quantum Security NIST-standardized post-quantum cryptography for secrets, signatures, and audit records.
🔒
Post-Quantum Cryptography
PQData Platform
10
incidents this month · 11%
“Quantum-safe by design — before quantum breaks classical crypto.”
Full post-quantum data security suite using NIST-standardized algorithms: ML-KEM-768 for encryption, ML-DSA-87 for signatures. QuantumVault for PQC-encrypted secrets. PQ Sign for long-validity quantum-safe audit records. Hybrid X25519 + ML-KEM-768 key exchange for TLS 1.3.
⚠️ The gap it fills Every classical encryption scheme in most enterprise stacks today is vulnerable to Shor’s algorithm on a sufficiently powerful quantum computer. “Harvest now, decrypt later” attacks are already underway. The clock is running.
  • QuantumVault: ML-KEM-768 PQC-encrypted secrets with full key lifecycle
  • PQ Sign: ML-DSA-87 (Dilithium) signatures for audit records + agent attestations
  • Hybrid key exchange: X25519 + ML-KEM-768 for TLS 1.3 — secure against both
  • PQ CryptoGuard: CBOM scanner identifies all classical crypto in use; quantum-readiness score
  • FedRAMP/CMMC/CNSA 2.0 compliance evidence from PQC infrastructure layer

Get the Monthly Breach Report

Every month: all breaches, all vendor stacks, the gap analysis. No fluff — just the intelligence your security team needs.