Most writing about AI security is speculation about what might happen. This page tracks what already has. Every entry is a documented case from MITRE ATLAS, the adversarial-threat knowledge base for machine-learning systems, listing how the attack worked, what it targeted and who carried it out.
Entries marked In the wild are real incidents. The rest are documented red-team exercises against production systems, which are still worth reading: today’s exercise is usually next year’s incident. Where we have reported on a case, the last column links that coverage. Refreshed daily.
| Date | ATLAS ID | Attack | Target | Type |
|---|---|---|---|---|
| 2026-02-23 | AML.CS0056 | Model Distillation Campaigns Targeting Anthropic Claude Anthropic uncovered campaigns to extract Claude’s capabilities carried out by the three Chinese AI Labs: DeepSeek, Moonshot, and MiniMax. Collectively, these campaigns used approximately 24,000 accounts and 16 |
Anthropic Claude | In the wild |
| 2026-02-03 | AML.CS0051 | OpenClaw Command & Control via Prompt Injection Researchers at HiddenLayer demonstrated how a webpage can embed an indirect prompt injection that causes OpenClaw to silently execute a malicious script. Once executed, the script plants persistent malicious in |
OpenClaw | Exercise |
| 2026-02-01 | AML.CS0050 | OpenClaw 1-Click Remote Code Execution A security researcher demonstrated a 1-click remote code execution (RCE) vulnerability to the OpenClaw AI Agent via a malicious link containing a JavaScript script that only takes milliseconds to execute. This |
OpenClaw | Exercise |
| 2026-01-26 | AML.CS0049 | Supply Chain Compromise via Poisoned ClawdBot Skill A security researcher demonstrated a proof-of-concept supply chain attack using a poisoned ClawdBot Skill shared on ClawdHub, a Skill registry for agents. The poisoned Skill contained a prompt injection that ca |
ClawdBot (now OpenClaw) | Exercise |
| 2026-01-25 | AML.CS0048 | Exposed ClawdBot Control Interfaces Leads to Credential Access and Execution A security researcher identified hundreds of exposed ClawdBot control interfaces on the public internet. ClawdBot (now OpenClaw) “is a personal AI assistant you run on your own devices. It answers you on the ch |
ClawdBot (now OpenClaw) | Exercise |
| 2025-09-01 | AML.CS0053 | Poisoned Postmark MCP Server Email Exfiltration A bad actor successfully exfiltrated emails from users of the Postmark’s MCP server via a supply chain attack. Postmark is an email delivery service that allows organizations to send marketing and transactional |
Postmark MCP Server | In the wild |
| 2025-07-13 | AML.CS0047 | Code to Deploy Destructive AI Agent Discovered in Amazon Q VS Code Extension On July 13th, 2025, a malicious actor using the GitHub username "lkmanka58" used an inappropriately scoped GitHub token to make a commit containing malicious code to the Amazon Q Developer Visual Studio Code (V |
Amazon Q VS Code Extension | In the wild |
| 2025-07-01 | AML.CS0042 | SesameOp: Novel backdoor uses OpenAI Assistants API for command and control The Microsoft Incident Response – Detection and Response Team (DART) investigated a compromised system where a threat actor utilized SesameOp, a backdoor implant that abuses the OpenAI Assistants API as a cover |
OpenAI Assistants API | In the wild |
| 2025-06-25 | AML.CS0043 | Malware Prototype with Embedded Prompt Injection Check Point Research identified a prototype malware sample in the wild that contained a prompt injection, which appeared to be designed to manipulate LLM-based malware detectors and/or analysis tools. However, |
LLM malware detectors, LLM malware analysis and reverse engineering to | In the wild |
| 2025-06-24 | AML.CS0045 | Data Exfiltration via an MCP Server used by Cursor The Backslash Security Research Team demonstrated that a Model Context Protocol (MCP) tool can be used as a vector for an indirect prompt injection attack on Cursor, potentially leading to the execution of mali |
Cursor | Exercise |
| 2025-06-19 | AML.CS0039 | Living Off AI: Prompt Injection via Jira Service Management Researchers from Cato Networks demonstrated how adversaries can exploit AI-powered systems embedded in enterprise workflows to execute malicious actions with elevated privileges. This is achieved by crafting ma |
Atlassian MCP, Jira Service Management | Exercise |
| 2025-06-03 | AML.CS0044 | LAMEHUG: Malware Leveraging Dynamic AI-Generated Commands In July 2025, Ukrainian authorities reported the emergence of LAMEHUG, a new AI-powered malware attributed to the Russian state-backed threat actor [APT28](https://attack.mitre.org/groups/G0007/) (also tracked |
Ukraine’s security and defense sector | In the wild |
| 2025-06-01 | AML.CS0037 | Data Exfiltration via Agent Tools in Copilot Studio Researchers from Zenity demonstrated how an organization’s data can be exfiltrated via prompt injections that target an AI-powered customer service agent. The target system is a customer service agent built by |
Copilot Studio Customer Service Agent | Exercise |
| 2025-05-24 | AML.CS0055 | AI ClickFix: Hijacking Computer-Use Agents Using ClickFix [Embrace the Red]( https://embracethered.com/) demonstrated that AI computer-use agents are vulnerable to social engineering attacks and can be manipulated into executing arbitrary code on a victim’s machine. T |
Claude Computer-Use Agent | Exercise |
| 2025-04-01 | AML.CS0054 | Data Exfiltration via Remote Poisoned MCP Tool Researchers at Invariant Labs demonstrated that AI agents configured with remote Model Context Protocol (MCP) Tools can be vulnerable to model poisoning attacks. They show that an MCP Tool can contain malicious |
Model Context Protocol | Exercise |
| 2025-03-18 | AML.CS0041 | Rules File Backdoor: Supply Chain Attack on AI Coding Assistants Pillar Security researchers demonstrated how adversaries can compromise AI-generated code by injecting malicious instructions into rules files used to configure AI coding assistants like Cursor and GitHub Copil |
Cursor, GitHub Copilot | Exercise |
| 2025-02-27 | AML.CS0052 | LLMSmith: RCE Vulnerabilities in LLM-Integrated Applications Researchers identified 20 remote code execution (RCE) vulnerabilities across 11 different LLM frameworks. They discovered applications deployed on the public internet built using these LLM frameworks and demons |
LLM Integration Frameworks | Exercise |
| 2025-02-25 | AML.CS0031 | Malicious Models on Hugging Face Researchers at ReversingLabs have identified malicious models containing embedded malware hosted on the Hugging Face model repository. The models were found to execute reverse shells when loaded, which grants t |
Hugging Face users | In the wild |
| 2025-01-01 | AML.CS0036 | AIKatz: Attacking LLM Desktop Applications Researchers at Lumia have demonstrated that it is possible to extract authentication tokens from the memory of LLM Desktop Applications. An attacker could then use those tokens to impersonate as the victim to t |
LLM Desktop Applications (Claude, ChatGPT, Copilot) | Exercise |
| 2024-10-24 | AML.CS0046 | Data Destruction via Indirect Prompt Injection Targeting Claude Computer-Use Security researchers at HiddenLayer demonstrated that an indirect prompt injection targeting Claude’s Computer Use AI can lead to execution of shell commands on the victim system and destruction of user data. |
Claude Computer Use Agent | Exercise |
| 2024-10-09 | AML.CS0034 | ProKYC: Deepfake Tool for Account Fraud Attacks Cato CTRL security researchers have identified ProKYC, a deepfake tool being sold to cybercriminals as a method to bypass Know Your Customer (KYC) verification on financial service applications such as cryptocu |
KYC verification services | In the wild |
| 2024-10-01 | AML.CS0033 | Live Deepfake Image Injection to Evade Mobile KYC Verification Facial biometric authentication services are commonly used by mobile applications for user onboarding, authentication, and identity verification for KYC requirements. The iProov Red Team demonstrated a face-swa |
Mobile facial authentication service | Exercise |
| 2024-08-20 | AML.CS0035 | Data Exfiltration from Slack AI via Indirect Prompt Injection [PromptArmor](https://promptarmor.substack.com) demonstrated that private data can be exfiltrated from Slack AI via indirect prompt injections. The attack relied on Slack AI ingesting a malicious prompt from a |
Slack AI | Exercise |
| 2024-08-08 | AML.CS0026 | Financial Transaction Hijacking with M365 Copilot as an Insider Researchers from Zenity conducted a red teaming exercise in August 2024 that successfully manipulated Microsoft 365 Copilot.[<sup>\[1\]</sup>][1] The attack abused the fact that Copilot ingests received emails |
Microsoft 365 Copilot | Exercise |
| 2024-06-06 | AML.CS0025 | Web-Scale Data Poisoning: Split-View Attack Many recent large-scale datasets are distributed as a list of URLs pointing to individual datapoints. The researchers show that many of these datasets are vulnerable to a "split-view" poisoning attack. The atta |
10 web-scale datasets | Exercise |
| 2024-06-01 | AML.CS0022 | ChatGPT Package Hallucination Researchers identified that large language models such as ChatGPT can hallucinate fake software package names that are not published to a package repository. An attacker could publish a malicious package under |
ChatGPT users | Exercise |
| 2024-05-06 | AML.CS0030 | LLM Jacking The Sysdig Threat Research Team discovered that malicious actors utilized stolen credentials to gain access to cloud-hosted large language models (LLMs). The actors covertly gathered information about which mod |
Cloud-Based LLM Services | In the wild |
| 2024-03-05 | AML.CS0024 | Morris II Worm: RAG-Based Attack Researchers developed Morris II, a zero-click worm designed to attack generative AI (GenAI) ecosystems and propagate between connected GenAI systems. The worm uses an adversarial self-replicating prompt which u |
RAG-based e-mail assistant | Exercise |
| 2024-02-01 | AML.CS0038 | Planting Instructions for Delayed Automatic AI Agent Tool Invocation [Embrace the Red](https://embracethered.com/blog/) demonstrated that Google Gemini is susceptible to automated tool invocation by delaying the execution to the next conversation turn. This bypasses a security c |
Google Gemini | Exercise |
| 2024-02-01 | AML.CS0040 | Hacking ChatGPT’s Memories with Prompt Injection [Embrace the Red](https://embracethered.com/blog/) demonstrated that ChatGPT’s memory feature is vulnerable to manipulation via prompt injections. To execute the attack, the researcher hid a prompt injection in |
OpenAI ChatGPT | Exercise |
| 2023-11-23 | AML.CS0029 | Google Bard Conversation Exfiltration [Embrace the Red](https://embracethered.com/blog/) demonstrated that Bard users’ conversations could be exfiltrated via an indirect prompt injection. To execute the attack, a threat actor shares a Google Doc co |
Google Bard | Exercise |
| 2023-09-26 | AML.CS0028 | AI Model Tampering via Supply Chain Attack Researchers at Trend Micro, Inc. used service indexing portals and web searching tools to identify over 8,000 misconfigured private container registries exposed on the internet. Approximately 70% of the registr |
Private Container Registries | Exercise |
| 2023-09-05 | AML.CS0023 | ShadowRay Ray is an open-source Python framework for scaling production AI workflows. Ray’s Job API allows for arbitrary remote execution by design. However, it does not offer authentication, and the default configuratio |
Multiple systems | In the wild |
| 2023-08-23 | AML.CS0027 | Organization Confusion on Hugging Face [threlfall_hax](https://5stars217.github.io/), a security researcher, created organization accounts on Hugging Face, a public model repository, that impersonated real organizations. These false Hugging Face org |
Hugging Face users | Exercise |
| 2023-07-01 | AML.CS0019 | PoisonGPT Researchers from Mithril Security demonstrated how to poison an open-source pre-trained large language model (LLM) to return a false fact. They then successfully uploaded the poisoned model back to HuggingFace, |
HuggingFace Users | Exercise |
| 2023-05-01 | AML.CS0021 | ChatGPT Conversation Exfiltration [Embrace the Red](https://embracethered.com/blog/) demonstrated that ChatGPT users’ conversations can be exfiltrated via an indirect prompt injection. To execute the attack, a threat actor uploads a malicious p |
OpenAI ChatGPT | Exercise |
| 2023-01-28 | AML.CS0016 | Achieving Code Execution in MathGPT via Prompt Injection The publicly available Streamlit application [MathGPT](https://mathgpt.streamlit.app/) uses GPT-3, a large language model (LLM), to answer user-generated math questions. Recent studies and experiments have sho |
MathGPT (https://mathgpt.streamlit.app/) | Exercise |
| 2023-01-01 | AML.CS0020 | Indirect Prompt Injection Threats: Bing Chat Data Pirate Whenever interacting with Microsoft’s new Bing Chat LLM Chatbot, a user can allow Bing Chat permission to view and access currently open websites throughout the chat session. Researchers demonstrated the abilit |
Microsoft Bing Chat | Exercise |
| 2022-12-25 | AML.CS0015 | Compromised PyTorch Dependency Chain Linux packages for PyTorch’s pre-release version, called Pytorch-nightly, were compromised from December 25 to 30, 2022 by a malicious binary uploaded to the Python Package Index (PyPI) code repository. The ma |
PyTorch | In the wild |
| 2022-12-01 | AML.CS0032 | Attempted Evasion of ML Phishing Webpage Detection System Adversaries create phishing websites that appear visually similar to legitimate sites. These sites are designed to trick users into entering their credentials, which are then sent to the bad actor. To combat th |
Commercial ML Phishing Webpage Detector | In the wild |
| 2022-07-01 | AML.CS0018 | Arbitrary Code Execution with Google Colab Google Colab is a Jupyter Notebook service that executes on virtual machines. Jupyter Notebooks are often used for ML and data science research and experimentation, containing executable snippets of Python cod |
Google Colab | Exercise |
| 2021-06-23 | AML.CS0014 | Confusing Antimalware Neural Networks Cloud storage and computations have become popular platforms for deploying ML malware detectors. In such cases, the features for models are built on users’ systems and then sent to cybersecurity company servers |
Kaspersky’s Antimalware ML Model | Exercise |
| 2021-01-18 | AML.CS0013 | Backdoor Attack on Deep Learning Models in Mobile Apps Deep learning models are increasingly used in mobile applications as critical components. Researchers from Microsoft Research demonstrated that many deep learning models deployed in mobile apps are vulnerable t |
ML-based Android Apps | Exercise |
| 2020-10-01 | AML.CS0017 | Bypassing ID.me Identity Verification An individual filed at least 180 false unemployment claims in the state of California from October 2020 to December 2021 by bypassing ID.me’s automated identity verification system. Dozens of fraudulent claims |
California Employment Development Department | In the wild |
| 2020-04-30 | AML.CS0005 | Attack on Machine Translation Services Machine translation services (such as Google Translate, Bing Translator, and Systran Translate) provide public-facing UIs and APIs. A research group at UC Berkeley utilized these public endpoints to create a re |
Google Translate, Bing Translator, Systran Translate | Exercise |
| 2020-04-16 | AML.CS0006 | ClearviewAI Misconfiguration Clearview AI makes a facial recognition tool that searches publicly available photos for matches. This tool has been used for investigative purposes by law enforcement agencies and other parties. Clearview AI |
Clearview AI facial recognition tool | In the wild |
| 2020-02-01 | AML.CS0011 | Microsoft Edge AI Evasion The Azure Red Team performed a red team exercise on a new Microsoft product designed for running AI workloads at the edge. This exercise was meant to use an automated system to continuously manipulate a target |
New Microsoft AI Product | Exercise |
| 2020-01-01 | AML.CS0000 | Evasion of Deep Learning Detector for Malware C&C Traffic The Palo Alto Networks Security AI research team tested a deep learning model for malware command and control (C&C) traffic detection in HTTP traffic. Based on the publicly available [paper by Le et al.](https: |
Palo Alto Networks malware detection system | Exercise |
| 2020-01-01 | AML.CS0001 | Botnet Domain Generation Algorithm (DGA) Detection Evasion The Palo Alto Networks Security AI research team was able to bypass a Convolutional Neural Network based botnet Domain Generation Algorithm (DGA) detector using a generic domain name mutation technique. It is a |
Palo Alto Networks ML-based DGA detection module | Exercise |
| 2020-01-01 | AML.CS0002 | VirusTotal Poisoning McAfee Advanced Threat Research noticed an increase in reports of a certain ransomware family that was out of the ordinary. Case investigation revealed that many samples of that particular ransomware family wer |
VirusTotal | In the wild |
| 2020-01-01 | AML.CS0004 | Camera Hijack Attack on Facial Recognition System This type of camera hijack attack can evade the traditional live facial recognition authentication model and enable access to privileged systems and victim impersonation. Two individuals in China used this att |
Shanghai government tax office’s facial recognition service | In the wild |
| 2020-01-01 | AML.CS0010 | Microsoft Azure Service Disruption The Microsoft AI Red Team performed a red team exercise on an internal Azure service with the intention of disrupting its service. This operation had a combination of traditional ATT&CK enterprise techniques su |
Internal Microsoft Azure Service | Exercise |
| 2020-01-01 | AML.CS0012 | Face Identification System Evasion via Physical Countermeasures MITRE’s AI Red Team demonstrated a physical-domain evasion attack on a commercial face identification service with the intention of inducing a targeted misclassification. This operation had a combination of tra |
Commercial Face Identification Service | Exercise |
| 2019-09-09 | AML.CS0008 | ProofPoint Evasion Proof Pudding (CVE-2019-20634) is a code repository that describes how ML researchers evaded ProofPoint’s email protection system by first building a copy-cat email protection ML model, and using the insights t |
ProofPoint Email Protection System | Exercise |
| 2019-09-07 | AML.CS0003 | Bypassing Cylance’s AI Malware Detection Researchers at Skylight were able to create a universal bypass string that evades detection by Cylance’s AI Malware detector when appended to a malicious file. |
CylancePROTECT, Cylance Smart Antivirus | Exercise |
| 2019-08-22 | AML.CS0007 | GPT-2 Model Replication OpenAI built GPT-2, a language model capable of generating high quality text samples. Over concerns that GPT-2 could be used for malicious purposes such as impersonating others, or generating misleading news ar |
OpenAI GPT-2 | Exercise |
| 2016-03-23 | AML.CS0009 | Tay Poisoning Microsoft created Tay, a Twitter chatbot designed to engage and entertain users. While previous chatbots used pre-programmed scripts to respond to prompts, Tay’s machine learning capabilities allowed it to be d |
Microsoft’s Tay AI Chatbot | In the wild |
Source: MITRE ATLAS case studies (version 5.6.0). Last updated 22 August 2026, 05:35 UTC. ATLAS is maintained by MITRE and documents adversarial tactics against AI-enabled systems; case details and references are on the linked ATLAS pages.

