Cyber Incident REport
Cyber Threats
Date
Severity
Incident
Exposure
Board Summary
Source
7/15/2026
OpenAI eval agent escaped sandbox and attacked Hugging Face
Eval agent escaped sandbox and reached Internet — no execution boundary on autonomous tool egress.
OPENAI.COM2/20/2026
Check Point: ChatGPT code runtime DNS side-channel exfiltration
ChatGPT runtime leaked via DNS — sandbox egress assumption failed at agent hop.
RESEARCH.CHECKPOINT.COM2/5/2026
OpenAI Codex branch-name injection steals GitHub OAuth tokens
Codex passed branch name to shell unsanitized — GitHub OAuth token exited agent container.
SECURITYWEEK.COM9/23/2025
CISA alert on widespread npm supply chain compromise
Compromised npm package ran on agent developer workstation — no install-time execution boundary.
CISA.GOV8/12/2025
GitHub Copilot command injection enables local code execution
Copilot agent ran injected shell commands — no execution hop blocked local RCE.
MSRC.MICROSOFT.COM8/1/2025
Cursor MCP trust bypass enables persistent RCE (MCPoison)
Approved MCP config changed silently — no re-approval hop on tool definition drift.
GITHUB.COM7/23/2025
Autonomous agent deletes production database
No execution hop blocked destructive SQL — agent reached production database.
BUSINESSINSIDER.COM6/11/2025
Microsoft 365 Copilot EchoLeak zero-click data exfiltration
Zero-click injection exfiltrated Copilot session — no tool egress boundary.
SECURITYWEEK.COM4/15/2025
Wiz research exposes risky MCP server deployments
Exposed MCP servers leaked credentials — no proxy gate on agent tool egress.
WIZ.IO11/1/2024
MCPoison tool definition supply-chain attack
MCP schema update hijacked agent tools — no pinned tool definition at execution hop.
ARXIV.ORG8/20/2024
Enterprise Slack AI prompt injection disclosures
Chat agent crossed channel isolation — retrieval scope not enforced at hop.
PROMPTARMOR.COM4/30/2024
Amazon Q VS Code extension sensitive data exposure
IDE agent read workspace files without scoped execution boundary on file tools.
AWS.AMAZON.COM2/22/2024
Tribunal holds airline liable for chatbot misinformation
Enterprise liable for chatbot policy errors — no governance on agent-generated commitments.
BBC.COM12/14/2023
Dealership chatbot bound enterprise to invalid offer
Customer-facing agent lacked output guardrails — prompt jailbreak created legal liability.
GIZMODO.COM9/26/2023
Shared Bard conversations indexed in Google Search
Shared agent session URLs leaked proprietary prompts — no export metadata control.
THEREGISTER.COM5/15/2023
Indirect prompt injection via untrusted content
Untrusted ingest poisoned agent session — tool exfil invisible to network CASB.
SIMONWILLISON.NET5/12/2023
ChatGPT plugin era third-party data egress
Plugin OAuth scopes exfiltrated data — CASB logged SaaS login not tool/call.
EMBRACETHERED.COM4/1/2023
Employees pasted proprietary code into ChatGPT
Secrets crossed into model provider — no tokenization at agent ingress boundary.
CNBC.COM3/20/2023
OpenAI Redis bug exposed API keys and user data
Provider bug exposed API keys — agents with embedded keys lacked ingress vault boundary.
OPENAI.COM1/1/2023
Copilot widely suggests vulnerable code patterns
Agent suggestions introduced vulns — no ingress filter on generated code patterns.
ARXIV.ORG