Cyber Incident REport

Cyber Threats

Date
Severity
Incident
Exposure
Board Summary
Source
7/15/2026
critical
OpenAI eval agent escaped sandbox and attacked Hugging Face
5/5
Eval agent escaped sandbox and reached Internet — no execution boundary on autonomous tool egress.
OPENAI.COM
2/20/2026
critical
Check Point: ChatGPT code runtime DNS side-channel exfiltration
5/5
ChatGPT runtime leaked via DNS — sandbox egress assumption failed at agent hop.
RESEARCH.CHECKPOINT.COM
2/5/2026
critical
OpenAI Codex branch-name injection steals GitHub OAuth tokens
5/5
Codex passed branch name to shell unsanitized — GitHub OAuth token exited agent container.
SECURITYWEEK.COM
9/23/2025
high
CISA alert on widespread npm supply chain compromise
4/5
Compromised npm package ran on agent developer workstation — no install-time execution boundary.
CISA.GOV
8/12/2025
high
GitHub Copilot command injection enables local code execution
5/5
Copilot agent ran injected shell commands — no execution hop blocked local RCE.
MSRC.MICROSOFT.COM
8/1/2025
critical
Cursor MCP trust bypass enables persistent RCE (MCPoison)
5/5
Approved MCP config changed silently — no re-approval hop on tool definition drift.
GITHUB.COM
7/23/2025
critical
Autonomous agent deletes production database
5/5
No execution hop blocked destructive SQL — agent reached production database.
BUSINESSINSIDER.COM
6/11/2025
critical
Microsoft 365 Copilot EchoLeak zero-click data exfiltration
5/5
Zero-click injection exfiltrated Copilot session — no tool egress boundary.
SECURITYWEEK.COM
4/15/2025
high
Wiz research exposes risky MCP server deployments
4/5
Exposed MCP servers leaked credentials — no proxy gate on agent tool egress.
WIZ.IO
11/1/2024
critical
MCPoison tool definition supply-chain attack
5/5
MCP schema update hijacked agent tools — no pinned tool definition at execution hop.
ARXIV.ORG
8/20/2024
high
Enterprise Slack AI prompt injection disclosures
4/5
Chat agent crossed channel isolation — retrieval scope not enforced at hop.
PROMPTARMOR.COM
4/30/2024
high
Amazon Q VS Code extension sensitive data exposure
4/5
IDE agent read workspace files without scoped execution boundary on file tools.
AWS.AMAZON.COM
2/22/2024
high
Tribunal holds airline liable for chatbot misinformation
4/5
Enterprise liable for chatbot policy errors — no governance on agent-generated commitments.
BBC.COM
12/14/2023
high
Dealership chatbot bound enterprise to invalid offer
4/5
Customer-facing agent lacked output guardrails — prompt jailbreak created legal liability.
GIZMODO.COM
9/26/2023
medium
Shared Bard conversations indexed in Google Search
3/5
Shared agent session URLs leaked proprietary prompts — no export metadata control.
THEREGISTER.COM
5/15/2023
critical
Indirect prompt injection via untrusted content
5/5
Untrusted ingest poisoned agent session — tool exfil invisible to network CASB.
SIMONWILLISON.NET
5/12/2023
high
ChatGPT plugin era third-party data egress
4/5
Plugin OAuth scopes exfiltrated data — CASB logged SaaS login not tool/call.
EMBRACETHERED.COM
4/1/2023
high
Employees pasted proprietary code into ChatGPT
4/5
Secrets crossed into model provider — no tokenization at agent ingress boundary.
CNBC.COM
3/20/2023
high
OpenAI Redis bug exposed API keys and user data
4/5
Provider bug exposed API keys — agents with embedded keys lacked ingress vault boundary.
OPENAI.COM
1/1/2023
medium
Copilot widely suggests vulnerable code patterns
3/5
Agent suggestions introduced vulns — no ingress filter on generated code patterns.
ARXIV.ORG