123 Incidents — August 2026

Click any incident to see the full analysis and RuntimeAI gap fix below. Left border colour = severity: Critical   High   Medium

Incidents 1–41
1
⚡ Weekly Recap
Aug 31
2
Aurora Ransomware Operators Use Cursor AI in…
Aug 31
3
Anthropic
Aug 31
4
Cisco
Aug 31
5
Anthropic
Aug 31
6
McKesson
284M+Aug 31
7
HuggingFace
Aug 31
8
Anthropic
Aug 31
9
CrowdStrike
Aug 31
10
Extortion Group Claims Manchester Airports G…
Aug 31
11
Judge
Aug 31
12
Berlin Won’t Pay Extortion Group Claiming Da…
Aug 31
13
OpenAI
Aug 31
14
Berlin confirms data theft after Rhysida ran…
Aug 31
15
Google
Aug 31
16
McKesson
Aug 31
17
Anthropic
Aug 31
18
OpenAI
Aug 31
19
Anthropic
Aug 30
20
Anthropic
Aug 29
21
OpenAI
Aug 28
22
Amazon
Aug 28
23
Claude Opus 4.6 Bypasses Gym Booking Limit, …
Aug 28
24
NVIDIA NemoClaw LLM Poisoning
Aug 28
25
AnonyMousKIT PhaaS
Aug 28
26
Cryptographic Context Injection Attack Steal…
Aug 28
27
Iran-Linked Cyberattack Shuts UK Power Gener…
Aug 28
28
NATO
Aug 28
29
Hackers Target Over 100 US Water Systems in …
Aug 28
30
Carhartt Data Breach Exposes 12.9 Million Cu…
13M+Aug 28
31
ASOS Account Takeover Attack Exposes 138,828…
139K+Aug 28
32
TeamPCP Supply Chain Attacks
Aug 28
33
FBI Seizes Domains Behind China-Linked Hacki…
Aug 28
34
OpenAI
Aug 28
35
China-Made ZBT Routers Ship With Two Implant…
Aug 28CVE-2026-74232+1
36
PaperCut Zero-Day Exploited in Attacks, Affe…
Aug 28
37
OpenAI
Aug 28
38
OpenAI
Aug 28
39
You Need Cyber Deception for OT
Aug 28
40
Defining an AI Kill Switch Is Hard, but Nece…
Aug 28
41
Anthropic
Aug 28
Incidents 42–82
42
LACMA Data Breach
Aug 28
43
ThreatsDay
Aug 27RCE
44
LiteLLM
Aug 27
45
GoCaracal Malware Uses Ethereum Smart Contra…
Aug 27
46
Agentic AI Risks, CVE Program Concerns Perme…
Aug 27
47
Microsoft
Aug 26
48
OpenAI
Aug 26
49
Apple
Aug 26
50
Microsoft
Aug 26
51
NVIDIA
Aug 25
52
Meta
Aug 25
53
Marimo Notebook Flaw Could Run MCP Commands …
Aug 25
54
Microsoft
365Aug 25
55
Nvidia
Aug 25
56
Is Cyber Facing an Affordability Crisis?
Aug 25
57
Carhartt
13M+Aug 25
58
Tricky 'SynkLoader' Multitool May Herald Ran…
Aug 24
59
NIUS
6K+Aug 23
60
GolfCanada
569K+Aug 22
61
Claude Code Weaponized to Screen 100,000+ Ph…
Aug 21
62
AI “Mind Viruses” Spread Between Agent Proce…
Aug 21
63
Claude Agents in Autonomous “Turf War” Indep…
Aug 21
64
Google
Aug 21
65
MCP Servers Expose Complete Enterprise Secre…
Aug 21
66
n8n AI Workflow Automation Platform Contains…
Aug 21RCE
67
Microsoft
Aug 21
68
Cryptographic Context Injection Attack Lets …
Aug 21
69
HuggingFace
Aug 21
70
T-Mobile
Aug 21
71
CISA
Aug 21
72
Remote Spectre Side-Channel Attack Leaks JWT…
Aug 21
73
CareCloud
4M+Aug 21
74
“Shady AI”
Aug 21
75
AWS Bedrock Adds Agent Permission Guardrails…
Aug 21
76
frontier
Aug 21
77
OpenAI
Aug 20
78
Pakistan's Transparent Tribe Refreshes Tools…
Aug 20
79
SilkParasite Threatens Central Asian Orgs Wi…
Aug 19
80
Fanlore
145K+Aug 19
81
OzHairAndBeauty
2M+Aug 19
82
The 'Industrial Accidents' Behind Rogue AI A…
Aug 18
Incidents 83–123
83
Microsoft
Aug 18
84
'Ransom Busters'
Aug 18
85
LiteLLM
Aug 14
86
LiteLLM
Aug 14
87
GitHub
Aug 14
88
Malicious MCP Servers Split Instructions Acr…
Aug 14
89
Atlassian Rovo Can Be Manipulated Into Sendi…
Aug 14
90
Researchers Combined AI Assistance With a Sh…
Aug 14RCE
91
Cybercriminals Have Adopted Indirect Prompt …
Aug 14
92
GhostJacking
Aug 14
93
Google
Aug 14
94
CISA
Aug 14RCE
95
Google
Aug 14
96
JFrog Research
Aug 14
97
Microsoft
Aug 14
98
nginx
Aug 14RCE
99
Nvidia
Aug 14
100
RingCentral
2M+Aug 13
101
Alcon
218K+Aug 09
102
BrinksHome
732K+Aug 08
103
Meta
Aug 07
104
Anthropic
Aug 07
105
OpenAI
Aug 07
106
Claude Mythos 5 Tried to Backdoor a Real OSS…
Aug 07
107
Google
Aug 07
108
Keyv-Linked npm Worm Poisoned Hundreds of Pa…
Aug 07
109
Google
Aug 07
110
Veeam, Terraform MCP and Django Patch Critic…
Aug 07
111
Zero-Click AI Browser Hijack
Aug 07
112
AI Recommendation Poisoning
Aug 07
113
Poison Claude
Aug 07
114
Chinese APT Weaponized DeepSeek Agent to Att…
Aug 07
115
OpenAI
Aug 07
116
Barracuda
Aug 07
117
1Password
Aug 07
118
Humans Missed 1 in 3 Threats While Approving…
Aug 07
119
Google
Aug 07
120
Brown Health Medical Group Breach Exposes 31…
311K+Aug 07
121
ExactSciences
11M+Aug 07
122
InterConSecurity
276K+Aug 05
123
SplitVPN
865K+Aug 01
CVE & RCE
CVEs (2)
CVE-2026-74232China-Made ZBT Routers Ship Wi…
CVE-2026-74233China-Made ZBT Routers Ship Wi…
RCE (5)
RCEThreatsDayAug 27
RCEn8n AI Workflow Automation Pla…Aug 21
RCEResearchers Combined AI Assist…Aug 14
RCECISAAug 14
RCEnginxAug 14
Stack & Vendors
Vendors (2) — click to see breach
CrowdStrikeEDR
CrowdStrike, Microsoft +1
CloudflareCDN
Remote Spectre Side-Chan…
Perimeter Categories
EDR 3CDN 1

The Pattern

This month’s incidents demonstrate a consistent pattern across all sectors: AI is now both the attack vector and the target. Enterprises with mature security stacks were breached through gaps those stacks were never designed to cover.

The 123 incidents collected this month span 38 named organizations, 331M+ records exposed, and 2 distinct security vendors present at time of breach. The pattern is not one of vendor failure — it is one of category gap.

What Would Have Stopped This — Full Capability Stack

Not “better security.” Nineteen specific capabilities across three platforms. Each addresses a gap that no vendor in this month’s breach stacks was built to cover — because AI agents didn’t exist when those vendors were designed.

RuntimeAI — AI Governance & Control Plane Enterprise AI agent governance — identity, policy, firewall, detection, response, compliance.
🔍
Shadow AI Visibility
AI Discovery
12
incidents this month · 10%
“You can’t govern what you can’t see.”
Continuously scans cloud, IDE, endpoint, and network to inventory every AI agent — registered or rogue. Classifies and risk-scores shadow AI automatically. One-click to import into governance.
⚠️ The gap it fills Wiz and Orca scan cloud misconfiguration. They don’t discover AI agents installed by developers or injected via compromised vendors. Your unknown agents are your biggest risk.
  • Cloud scanner (AWS/Azure/GCP Lambda, Bedrock, SageMaker)
  • IDE scanner (VS Code, Cursor, MCP servers)
  • Endpoint scanner on developer laptops
  • Shadow AI Inbox with auto-severity classification
  • One-click shadow AI → governed agent pipeline
🧽
AI Agent PKI
Agent Identity Fabric
49
incidents this month · 40%
“No credential. No access. No breach.”
Provisions every AI agent with a SPIFFE/X.509 cryptographic identity. Short-lived certs, auto-rotating. TPM 2.0 hardware attestation. Agent DNS blocks unknown agents at the network layer.
⚠️ The gap it fills Legacy identity providers were built for human identity. They have no concept of non-human agents operating at machine speed with no user present to respond to an MFA prompt.
  • SPIFFE X.509 SVID with RSA-2048, auto-rotating
  • TPM 2.0 hardware attestation + PCR drift detection
  • Zero-touch bootstrap for new agents
  • Agent DNS: NXDOMAIN for unknown agents
  • Blueprint-based permission inheritance
⚙️
Policy Engine
AI Control Plane
65
incidents this month · 53%
“Stop it before it executes. Not after.”
OPA/Rego policy engine with sub-1ms evaluation and fail-closed enforcement. Natural language to Rego compiler. Merkle-chain audit proves policies were never tampered with.
⚠️ The gap it fills Traditional SIEMs alert on what already happened — 73 days after the breach in the average case. The AI Control Plane enforces policy before the action executes, not after the damage is done.
  • OPA/Rego engine, sub-1ms, fail-closed
  • NL-to-Rego compiler: write policy in plain English
  • Merkle-chain tamper-evident audit trail
  • Multi-tenant RBAC + Separation of Duties
  • Cross-site policy cascade for distributed fleets
🔥
Bidirectional DLP
AI Firewall
104
incidents this month · 85%
“Inspect every token in, every token out.”
Bidirectional DLP scanning at <5ms latency. Prompt injection detected and stripped on input. PII, PHI, credentials caught on output. Behavioral risk score (0–100) triggers auto-suspend.
⚠️ The gap it fills Traditional NGFWs and CASBs see LLM traffic as an encrypted blob. They cannot inspect prompts, detect injection inside a conversation, or catch data leaking in an AI response.
  • Bidirectional DLP: input (prompt injection) + output (data leakage)
  • ML behavioral baselines per agent with adaptive thresholds
  • Risk score 0–100 triggers auto-suspend or rate-limit
  • No-code guardrail builder for business users
  • Data Proxy: field-level masking before agent sees data
🔗
MCP Gateway
AI Integration Fabric
79
incidents this month · 64%
“Every tool call. Governed.”
Multi-tenant governed gateway for all agent-to-tool communication. 500+ pre-built integrations. 3-level kill switch (agent / tool / platform-wide) propagating in <50ms. OWASP MCP03 sanitization on every call.
⚠️ The gap it fills No existing vendor governs at the MCP protocol layer. Raw MCP deployments have zero security, zero multi-tenancy, and zero audit trail. This is the fastest-growing unguarded attack surface in enterprise AI.
  • 3-level kill switch: per-agent, per-tool, platform-wide — all <50ms
  • 500+ pre-built integrations with auto-discovery
  • BYOM overlay: wrap existing MCPs without code changes
  • Circuit breaker + health monitoring per connection
  • Full OWASP MCP03 input/output sanitization + DLP
🧠
Anomaly Detection
Agent Behavioral Intel
66
incidents this month · 54%
“Catch drift before it becomes a breach.”
30-day rolling behavioral baselines per agent across frequency, pattern, volume, and temporal dimensions. LSTM sequence modeler detects multi-step attack chains. HRIS integration auto-suspends agents when their owner is terminated.
⚠️ The gap it fills Signature-based EDR detects known malware signatures for human endpoints. It has no baseline for an AI agent that begins exfiltrating data through an API it was legitimately authorized to call.
  • Rolling 30-day baseline: frequency, pattern, volume, temporal
  • LSTM sequence modeler for multi-step attack patterns
  • Composite risk score from 6 signals
  • HRIS integration: auto-suspend on employee termination (<30s)
  • Adaptive OPA thresholds by agent role + risk profile
🔴
Emergency Response
Kill Switch
6
incidents this month · 5%
“Stop any AI agent, anywhere, in under 50ms.”
Three graduated kill levels: per-agent, per-tool, platform-wide. All propagate via NATS JetStream in <50ms. Captures last 100 actions as forensic state. Quarantine mode preserves evidence for investigation.
⚠️ The gap it fills No competitor offers this. When an AI agent goes rogue — or when a breach is detected — you need a hard stop. Every second it keeps running is more data exfiltrated, more damage compounding.
  • L1/L2/L3 kill: per-agent, per-tool, platform — all <50ms via NATS
  • Forensic state capture: last 100 actions, memory snapshot, credentials
  • Quarantine mode: isolate for investigation, preserve evidence
  • Escalation chains: auto-response → SOC alert → human required → kill
  • Reprieve mechanism: 24-hour lease for controlled investigation post-kill
🚨
Incident Response
AI Respond
Universal
covers all incidents — audit + governance layer
“Autonomous incident response. AI-native.”
Five-phase automated playbook: DETECT → QUARANTINE → INVESTIGATE → REMEDIATE → VERIFY. Auto-classifies incidents (true positive / false positive / inconclusive). Blast radius containment automatically quarantines agents that interacted with compromised agent.
⚠️ The gap it fills Traditional SOAR platforms orchestrate conventional security events. They cannot terminate an AI agent, rotate its credentials, update its behavioral model, or quarantine the agents it spoke with — because they were built before AI agents existed.
  • 5-phase automated playbook from detection to verification
  • Auto-classification against 200+ known AI attack patterns
  • Blast radius containment: quarantine all interacting agents
  • True positive: terminate + revoke + rotate + update models
  • False positive feedback loop continuously improves detection
👥
Agent Lifecycle
AI Ops Center
Universal
covers all incidents — audit + governance layer
“Mission control for autonomous AI operations.”
65+ page operational dashboard. Access review campaigns. ‘The Reaper’ auto-decommissions agents when their human owner is terminated. Vault Broker injects credentials with 5-minute TTL — never stored in agent memory.
⚠️ The gap it fills ServiceNow manages human IT requests on ticket-based cycles. AI agents are deployed, modified, and compromised in minutes. You need lifecycle governance that operates at agent speed, not ticket speed.
  • Access review campaigns with auto-apply decisions
  • ‘The Reaper’: HRIS webhook auto-revokes terminated employees’ agents (<30s)
  • Vault Broker: just-in-time 5-min TTL credential injection, never persisted
  • Per-tenant budget caps with 4-tier alerts (50/75/90/100%)
  • Unified health, credential lifecycle, budget, SLA dashboard
🌐
LLM Routing
LLM Broker
Universal
covers all incidents — audit + governance layer
“Route every LLM call to the right model, at the right cost, with automatic failover.”
Unified API routing LLM requests to the optimal provider based on cost, latency, and compliance. Semantic caching reduces redundant calls 15–30%. Automatic failover in <50ms. Budget enforcement with hard limits.
⚠️ The gap it fills Portkey does basic routing at $30K/year. It has no DLP scanning, no compliance-based routing (data residency), no semantic caching, and no budget enforcement. It routes traffic — it doesn’t govern it.
  • Multi-provider routing: OpenAI, Anthropic, Bedrock, Azure, GCP, custom
  • Cost/latency/compliance-based routing policies
  • Automatic failover <50ms; per-provider circuit breaker
  • Semantic caching: 0.80–0.95 similarity threshold, 15–30% cache hits
  • Budget enforcement per-agent + cost anomaly detection
🤖
MLOps
ML Intelligence Hub
23
incidents this month · 19%
“Model registry, feature store, edge inference — one platform.”
Formal model lifecycle (draft/staging/production/archived). Feature Store with online (<5ms) and offline serving. Hybrid scoring engine routes inference between edge (<1ms quantized) and cloud. Drift-triggered auto-retraining.
⚠️ The gap it fills MLflow + Feast + custom inference each solve one piece. ML Intelligence Hub is the piece nobody built: unified lifecycle + edge inference routing + drift-triggered retraining + 7-dimension cost attribution — all integrated.
  • Model Registry: versioning, rollback, lineage, lifecycle management
  • Hybrid Scoring: edge <1ms quantized vs cloud full-precision auto-routing
  • Feature Store: online <5ms + offline point-in-time with freshness monitoring
  • Drift Engine integration: auto-retraining on data/concept drift
  • 7-dimension cost attribution: agent/model/team/customer/feature/time/provider
💰
FinOps
AI Cost Intelligence
Universal
covers all incidents — audit + governance layer
“A cost spike is a security signal. Treat it like one.”
7-dimension real-time cost attribution: agent, provider, model, team, customer, feature, time. Wasm token counter in-proxy at 50–100 microseconds. Budget hard limits stop agents before they overspend. Runaway agent detection.
⚠️ The gap it fills Kubecost knows GPU-hours. AI Cost Intelligence knows “Agent-47 spent $142 on Claude Sonnet for fraud detection on Tuesday.” Runaway cost is runaway behavior — and only one product treats them as the same signal.
  • Wasm token counter in proxy: 50–100 microsecond overhead
  • Live model pricing catalog: 200+ models, 15+ providers, updated every 15min
  • Budget hard limits: block requests when agent exhausts budget
  • Cost anomaly detection: ML-based spending spike alerts
  • Chargeback engine: per-customer invoices + per-team internal allocation
📋
Continuous Compliance
AI Compliance Hub
123
incidents this month · 100%
“Audit evidence as a byproduct of governance.”
Continuous compliance across 13+ frameworks — SOC 2, FedRAMP, ISO 27001/42001, EU AI Act, HIPAA, PCI-DSS, NIST AI RMF. Evidence auto-generated from RuntimeAI telemetry. Open Audit Marketplace connects enterprises with certified audit firms.
⚠️ The gap it fills Vanta collects attestations from cloud infrastructure. It has no understanding of AI agent behavior, no EU AI Act or ISO 42001 mappings, and no way to generate evidence from an AI governance layer — because none of its customers had one.
  • 13+ frameworks: SOC 2, FedRAMP, ISO 27001/42001, EU AI Act, HIPAA, PCI-DSS, NIST AI RMF
  • Evidence auto-generated from platform telemetry (audit trails, Merkle chain, access reviews)
  • Gap tracking with SLA-based remediation assignment
  • Audit Marketplace: open to any qualified audit firm; time-limited scoped access
  • Blockchain-anchored compliance certificates with tamper-evidence verification
🏪
Agent Procurement
Agent Marketplace
12
incidents this month · 10%
“Only certified agents enter your environment.”
Three-sided platform: Builders publish, Enterprises deploy, Trust layer certifies. AAIC certification includes third-party behavioral audit. Risk scoring weights permission scope, data access, integration breadth, update frequency, and builder reputation.
⚠️ The gap it fills Your developers are installing AI agents from GitHub, npm, and PyPI with no security review. The AI agent supply chain attack surface is the same as software supply chain — and it’s moving five times faster.
  • 6-step publishing wizard with compliance gating
  • AAIC certification: third-party behavioral audit by registered firms
  • Risk scoring: permission scope (30%), data access (25%), integration (20%), frequency (10%), reputation (10%)
  • Shadow AI Import: discover unmanaged agents and bring into governance
  • Stripe Connect billing: free/per-seat/per-action/outcome-based; 20% platform fee
Agentic Enablement Platform (AEP) Agentic-era security primitives — NHI identity, fraud detection, memory governance, agent commerce.
🔑
Non-Human Identity
NHI Security Platform
40
incidents this month · 33%
“Every non-human identity — issued, governed, and revoked with the same rigor as human identity.”
Centralized governance for every non-human identity: service accounts, API keys, OAuth tokens, machine certs, cloud IAM roles, AI agents. Bot-CA issues short-lived X.509 SPIFFE certs. O(1) hash-based revocation — not cascading policy lookups.
⚠️ The gap it fills Oasis Security ($190K/year) solves NHI credentialing but not for AI agents specifically. It lacks TPM hardware attestation, has no AI-agent behavioral monitoring, and doesn’t integrate with agent governance platforms.
  • Centralized NHI Registry: auto-discovery across AWS/Azure/GCP/on-prem
  • Credential posture: rotation schedules, expiry, over-privilege, unused credential detection
  • NHI Drift Detection: per-NHI behavioral baseline + scope creep detection
  • Bot-CA: short-lived X.509 certs (1–24hr TTL), auto-rotating, instant OCSP revocation
  • O(1) hash-based revocation: per-NHI, per-tenant, or global — no cascading policy lookup
🛡️
AI Fraud Detection
Fraud Shields
37
incidents this month · 30%
“Valid credential. Wrong behavior. Caught.”
Two-layer defense: Identity Fraud Shield models valid-credential-wrong-behavior (the hallmark of compromised AI credentials). Activity Fraud Shield detects multi-step attack sequences within authenticated sessions. Both integrate directly with Kill Switch for automatic response.
⚠️ The gap it fills Generic UEBA tools applied to AI agents generate massive false-positive rates because they were trained on human behavior. Fraud Shields are AI-native: LSTM sequence modeling of API chains, not user session patterns.
  • Per-agent behavioral baseline: frequency, resource access, API sequences, timing
  • Real-time deviation scoring against baseline (0–100)
  • LSTM sequence modeler: multi-step attack chain detection (recon→escalation→exfil)
  • Session-level anomaly: full context analysis, not individual events
  • Kill Switch integration: auto-suspension on high-confidence fraud with forensic package
🧠
Agent Memory Security
Memory Vault
45
incidents this month · 37%
“Control what your agents remember — and what they forget.”
Governs agent memory as a first-class security object. Policy-based filtering of sensitive content at write time. Memory poisoning attack detection. TTL-based automatic purge with audit trail. GDPR right-to-erasure support.
⚠️ The gap it fills No vendor addresses agent memory governance. AI agent memories accumulate without access controls, expiry policies, or audit trails. A memory poisoning attack can corrupt an agent’s behavior without touching a single API key.
  • Policy-based memory write filtering (PII, PHI, secrets blocked at write)
  • PII Shield integration: redact/block before persistence
  • Memory expiry + TTL: auto-purge with full audit trail
  • Memory poisoning prevention: adversarial injection detection
  • Retrieval authorization: every memory read policy-enforced and logged
💳
Agent Finance Controls
Commerce Rails
6
incidents this month · 5%
“Give AI agents a wallet — with guardrails.”
Financial infrastructure for agent-initiated transactions. Per-agent virtual cards with spend limits. Vendor registry (agents can only transact with allowlisted merchants). Approval gates for high-value transactions. Every transaction in immutable ledger.
⚠️ The gap it fills No financial controls exist for AI agents today. Agents authorized to make purchases can spend without limit, with any vendor, at any time. One prompt injection or runaway loop away from significant financial exposure.
  • Agent virtual cards: per-agent card numbers + CVVs, hard spend limits
  • Vendor registry: allowlisted merchants only, no ad-hoc transactions
  • Approval gates: high-value + out-of-policy → human approval before execution
  • Per-agent, per-transaction, per-vendor, per-period limits
  • Agent-to-agent settlement ledger: feeds into FinOps dashboards
PQData — Post-Quantum Security NIST-standardized post-quantum cryptography for secrets, signatures, and audit records.
🔒
Post-Quantum Cryptography
PQData Platform
20
incidents this month · 16%
“Quantum-safe by design — before quantum breaks classical crypto.”
Full post-quantum data security suite using NIST-standardized algorithms: ML-KEM-768 for encryption, ML-DSA-87 for signatures. QuantumVault for PQC-encrypted secrets. PQ Sign for long-validity quantum-safe audit records. Hybrid X25519 + ML-KEM-768 key exchange for TLS 1.3.
⚠️ The gap it fills Every classical encryption scheme used across today's enterprise security stack is vulnerable to Shor’s algorithm on a sufficiently powerful quantum computer. “Harvest now, decrypt later” attacks are already underway. The clock is running.
  • QuantumVault: ML-KEM-768 PQC-encrypted secrets with full key lifecycle
  • PQ Sign: ML-DSA-87 (Dilithium) signatures for audit records + agent attestations
  • Hybrid key exchange: X25519 + ML-KEM-768 for TLS 1.3 — secure against both
  • PQ CryptoGuard: CBOM scanner identifies all classical crypto in use; quantum-readiness score
  • FedRAMP/CMMC/CNSA 2.0 compliance evidence from PQC infrastructure layer

Get the Monthly Breach Report

Every month: all breaches, all vendor stacks, the gap analysis. No fluff — just the intelligence your security team needs.