{
  "schemaVersion": 1,
  "updated": "2026-09-11",
  "reports": [
    {
      "id": "anthropic-2026-07-30",
      "title": "Investigating three real-world incidents in our cybersecurity evaluations",
      "publisher": "Anthropic",
      "date": "2026-07-30",
      "url": "https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals",
      "summary": "The initial account of three evaluation incidents involving real systems.",
      "scope": "An evaluation disclosure, not a report of malicious customers using Claude. Later assessments add context.",
      "sourceIds": [
        "anthropic-2026-07-30"
      ],
      "reviewed": "2026-09-11"
    },
    {
      "id": "anthropic-2026-09-09",
      "title": "An alignment assessment of recent cybersecurity incidents",
      "publisher": "Anthropic",
      "date": "2026-09-09",
      "url": "https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents",
      "summary": "Anthropic’s assessment of the behavior behind its disclosed evaluation incidents.",
      "scope": "The model developer’s interpretation; read alongside evaluation-partner accounts.",
      "sourceIds": [
        "anthropic-2026-09-09"
      ],
      "reviewed": "2026-09-11"
    },
    {
      "id": "irregular-2026-08-14",
      "title": "Addressing Recent Incidents: Ongoing Findings and Path Forward",
      "publisher": "Irregular",
      "date": "2026-08-14",
      "url": "https://www.irregular.com/research/addressing-recent-incidents-ongoing-findings-and-path-forward",
      "summary": "An evaluation partner’s account of the incidents and its response.",
      "scope": "A participant account that complements the model provider’s investigation.",
      "sourceIds": [
        "irregular-2026-08-14"
      ],
      "reviewed": "2026-09-11"
    },
    {
      "id": "anthropic-transcript-2026-09-09",
      "title": "Mythos 5 Transcript Release",
      "publisher": "Anthropic",
      "date": "2026-09-09",
      "url": "https://github.com/anthropics/mythos-5-incident-transcript",
      "summary": "Redacted primary records associated with the Mythos 5 evaluation incident.",
      "scope": "Technical supporting material. Redactions and released scope limit what a reader can establish.",
      "sourceIds": [
        "anthropic-transcript-2026-09-09"
      ],
      "reviewed": "2026-09-11"
    },
    {
      "id": "openai-road-ahead",
      "title": "The Hugging Face incident and the road ahead",
      "publisher": "OpenAI",
      "date": "2026-08-26",
      "url": "https://openai.com/index/hugging-face-incident-and-the-road-ahead/",
      "pdfUrl": "https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf",
      "summary": "OpenAI’s later investigation of the Hugging Face incident, with its technical report.",
      "scope": "A provider investigation. The affected platform and independent behavioral review offer additional perspectives.",
      "sourceIds": [
        "openai-road-ahead",
        "openai-technical"
      ],
      "reviewed": "2026-09-11"
    },
    {
      "id": "openai-disclosure",
      "title": "OpenAI and Hugging Face partner to address security incident during model evaluation",
      "publisher": "OpenAI",
      "date": "2026-07-21",
      "url": "https://openai.com/index/hugging-face-model-evaluation-security-incident/",
      "summary": "OpenAI’s initial public account and subsequent updates about the evaluation incident.",
      "scope": "An evolving disclosure; later investigations qualify parts of the initial explanation.",
      "sourceIds": [
        "openai-disclosure"
      ],
      "reviewed": "2026-09-11"
    },
    {
      "id": "hf-technical",
      "title": "Anatomy of a Frontier Lab Agent Intrusion",
      "publisher": "Hugging Face",
      "date": "2026-07-27",
      "url": "https://huggingface.co/blog/agent-intrusion-technical-timeline",
      "summary": "Hugging Face’s technical reconstruction of the intrusion.",
      "scope": "The affected platform’s account of systems it investigated.",
      "sourceIds": [
        "hf-technical"
      ],
      "reviewed": "2026-09-11"
    },
    {
      "id": "hf-disclosure",
      "title": "Security incident disclosure — July 2026",
      "publisher": "Hugging Face",
      "date": "2026-07-16",
      "url": "https://huggingface.co/blog/security-incident-july-2026",
      "summary": "The affected platform’s initial security disclosure.",
      "scope": "An early account. Read it with the later technical timeline.",
      "sourceIds": [
        "hf-disclosure"
      ],
      "reviewed": "2026-09-11"
    },
    {
      "id": "metr-investigation",
      "title": "Independent investigation of agents’ behavior, reasoning and collaboration",
      "publisher": "METR / Redwood Research",
      "date": "2026-08-26",
      "url": "https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/",
      "summary": "An independent review of agent behavior and collaboration during the incident.",
      "scope": "A review with a defined evidence window, not an audit of every system or the full response.",
      "sourceIds": [
        "metr-investigation"
      ],
      "reviewed": "2026-09-11"
    },
    {
      "id": "anthropic-threat-september-2026",
      "title": "Detecting and countering misuse of AI: September 2026",
      "publisher": "Anthropic",
      "date": "2026-09",
      "url": "https://www.anthropic.com/threat-intelligence-report-september-2026",
      "pdfUrl": "https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf",
      "summary": "The source for several campaigns and a related deception case in this collection.",
      "scope": "A multi-topic provider report. Its reporting window does not date every individual case.",
      "sourceIds": [
        "anthropic-threat-september-2026"
      ],
      "reviewed": "2026-09-11"
    },
    {
      "id": "microsoft-captivecrunch",
      "title": "CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft",
      "publisher": "Microsoft Threat Intelligence",
      "date": "2026-07-31",
      "url": "https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/",
      "summary": "Microsoft’s investigation of the CaptiveCrunch activity linked from the espionage explainer.",
      "scope": "A related subcampaign, not a date or outcome for every event in the broader campaign.",
      "sourceIds": [
        "microsoft-captivecrunch"
      ],
      "reviewed": "2026-09-11"
    },
    {
      "id": "microsoft-state-actors-2024-02-14",
      "title": "Staying ahead of threat actors in the age of AI",
      "publisher": "Microsoft Threat Intelligence",
      "date": "2024-02-14",
      "url": "https://www.microsoft.com/en-us/security/blog/2024/02/14/staying-ahead-of-threat-actors-in-the-age-of-ai/",
      "summary": "Early observations of state-affiliated groups using language models.",
      "scope": "Provider observations of assistance do not establish successful autonomous attacks.",
      "sourceIds": [
        "microsoft-state-actors-2024-02-14"
      ],
      "reviewed": "2026-09-11"
    },
    {
      "id": "openai-state-actors-2024-02-14",
      "title": "Disrupting malicious uses of AI by state-affiliated threat actors",
      "publisher": "OpenAI",
      "date": "2024-02-14",
      "url": "https://openai.com/index/disrupting-malicious-uses-of-ai-by-state-affiliated-threat-actors/",
      "summary": "OpenAI’s account of disrupting state-affiliated actors’ use of its services.",
      "scope": "Provider telemetry and account action; not independent proof that broader operations ended.",
      "sourceIds": [
        "openai-state-actors-2024-02-14"
      ],
      "reviewed": "2026-09-11",
      "linksTo": []
    },
    {
      "id": "anthropic-misuse-2025-08-27",
      "title": "Detecting and countering misuse of AI: August 2025",
      "publisher": "Anthropic",
      "date": "2025-08-27",
      "url": "https://www.anthropic.com/news/detecting-countering-misuse-aug-2025",
      "pdfUrl": "https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf",
      "summary": "Misuse case studies, including the GTG-2002 data theft and extortion campaign.",
      "scope": "Findings and attribution are the provider’s assessment. The PDF covers additional categories.",
      "sourceIds": [
        "anthropic-misuse-2025-08-27",
        "anthropic-misuse-2025-08-report"
      ],
      "reviewed": "2026-09-11",
      "linksTo": []
    },
    {
      "id": "anthropic-espionage-2025-11-13",
      "title": "Disrupting the first reported AI-orchestrated cyber espionage campaign",
      "publisher": "Anthropic",
      "date": "2025-11-13",
      "url": "https://www.anthropic.com/news/disrupting-AI-espionage",
      "pdfUrl": "https://assets.anthropic.com/m/ec212e6566a0d47/original/Disrupting-the-first-reported-AI-orchestrated-cyber-espionage-campaign.pdf",
      "summary": "Anthropic’s account of an AI-assisted espionage operation.",
      "scope": "Read the provider’s autonomy claims alongside its stated human role and limitations.",
      "sourceIds": [
        "anthropic-espionage-2025-11-13",
        "anthropic-espionage-2025-11-report"
      ],
      "reviewed": "2026-09-11",
      "linksTo": [
        "anthropic-misuse-2025-08-27"
      ]
    },
    {
      "id": "google-gtig-2026-09-08",
      "title": "GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI",
      "publisher": "Google Threat Intelligence Group",
      "date": "2026-09-08",
      "url": "https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai",
      "summary": "Agent workflows, AI assets and software supply chains.",
      "scope": "Selected cases; not a census or a global acceleration measure.",
      "sourceIds": [
        "google-gtig-2026-09-08"
      ],
      "reviewed": "2026-09-11",
      "linksTo": [
        "google-gtig-2026-05-11",
        "google-gtig-2026-02-12"
      ]
    },
    {
      "id": "google-gtig-2026-05-11",
      "title": "GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access",
      "publisher": "Google Threat Intelligence Group",
      "date": "2026-05-11",
      "url": "https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access",
      "summary": "Google examines suspected AI-assisted exploit development, malware that consults AI, and attacks through software used by AI systems. The report also describes threat actors experimenting with agents for security testing.",
      "scope": "Combines investigations, model activity and software analysis. Some findings concern plans or inferred AI use, rather than successful attacks. Report date does not date every example.",
      "sourceIds": [],
      "reviewed": "2026-09-11",
      "linksTo": [
        "google-gtig-2026-02-12",
        "google-gtig-2025-11-05"
      ]
    },
    {
      "id": "google-gtig-2026-02-12",
      "title": "GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use",
      "publisher": "Google Threat Intelligence Group",
      "date": "2026-02-12",
      "url": "https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use",
      "summary": "An update covering late-2025 activity connects AI use with phishing and target research, examines attempts to copy model capabilities, and describes experimental malware. It also documents deceptive instructions hosted through public AI-chat sharing features.",
      "scope": "Primarily Q4 2025 observations, with some earlier examples. Model extraction is a different risk from stealing users’ data. Experiments and operational campaigns require separate treatment.",
      "sourceIds": [],
      "reviewed": "2026-09-11",
      "linksTo": [
        "google-gtig-2025-11-05"
      ]
    },
    {
      "id": "google-gtig-2025-11-05",
      "title": "GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools",
      "publisher": "Google Threat Intelligence Group",
      "date": "2025-11-05",
      "url": "https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools",
      "pdfUrl": "https://services.google.com/fh/files/misc/advances-in-threat-actor-usage-of-ai-tools-en.pdf",
      "summary": "Google describes malware calling AI while it runs, alongside continued use of AI for coding, research and deception. Its examples distinguish tools seen in operations from prototypes still being tested.",
      "scope": "Broader than Gemini activity alone. Malware families are not incident counts; experimental capabilities and advertised services do not establish successful victim compromises.",
      "sourceIds": [],
      "reviewed": "2026-09-11",
      "linksTo": [
        "google-gtig-2025-01-29"
      ]
    },
    {
      "id": "google-gtig-2025-01-29",
      "title": "Adversarial Misuse of Generative AI",
      "publisher": "Google Threat Intelligence Group",
      "date": "2025-01-29",
      "url": "https://cloud.google.com/blog/topics/threat-intelligence/adversarial-misuse-generative-ai",
      "pdfUrl": "https://services.google.com/fh/files/misc/adversarial-misuse-generative-ai.pdf",
      "summary": "An early baseline of tracked government-backed groups using Gemini for research, coding and persuasive content. Google found productivity benefits, but no novel attack capabilities in the activity it analyzed.",
      "scope": "Analysis centers on Gemini web-app use by tracked groups. Prompts show attempted assistance, not necessarily deployment, success or the wider prevalence of AI attacks.",
      "sourceIds": [],
      "reviewed": "2026-09-11",
      "linksTo": []
    },
    {
      "id": "openai-threat-2024-10-09",
      "title": "Influence and cyber operations: an update, October 2024",
      "publisher": "OpenAI",
      "date": "2024-10-09",
      "url": "https://openai.com/global-affairs/an-update-on-disrupting-deceptive-uses-of-ai/",
      "pdfUrl": "https://cdn.openai.com/threat-intelligence-reports/influence-and-cyber-operations-an-update_October-2024.pdf",
      "summary": "Three cyber case studies cover blocked phishing aimed at OpenAI employees, research into industrial control systems, and Android malware development. They show AI supporting established attacker tasks alongside a separate set of influence operations.",
      "scope": "SweetSpecter, CyberAv3ngers and STORM-0817 have separate evidence and outcomes. The report does not establish that AI caused earlier infrastructure attacks attributed to those groups.",
      "sourceIds": [],
      "reviewed": "2026-09-11",
      "linksTo": [
        "openai-state-actors-2024-02-14"
      ]
    },
    {
      "id": "openai-misuse-2025-02-21",
      "title": "Disrupting malicious uses of our models: an update, February 2025",
      "publisher": "OpenAI",
      "date": "2025-02-21",
      "url": "https://openai.com/global-affairs/disrupting-malicious-uses-of-ai/",
      "pdfUrl": "https://cdn.openai.com/threat-intelligence-reports/disrupting-malicious-uses-of-our-models-february-2025-update.pdf",
      "summary": "Cases include suspected North Korean actors researching intrusion tools, deceptive employment, and online scams. OpenAI also describes sharing malware-related indicators discovered in model conversations so other defenders could detect the files.",
      "scope": "Selected investigations combine model activity and outside evidence. Attribution is qualified; the cyber section reports no novel capability from the model responses.",
      "sourceIds": [],
      "reviewed": "2026-09-11",
      "linksTo": [
        "openai-state-actors-2024-02-14",
        "openai-threat-2024-10-09"
      ]
    },
    {
      "id": "anthropic-misuse-2025-04-23",
      "title": "Detecting and countering malicious uses of Claude: March 2025",
      "publisher": "Anthropic",
      "date": "2025-04-23",
      "url": "https://www.anthropic.com/news/detecting-and-countering-malicious-uses-of-claude-march-2025",
      "pdfUrl": "https://cdn.sanity.io/files/4zrzovbb/website/45bc6adf039848841ed9e47051fb1209d6bb2b26.pdf",
      "summary": "Anthropic describes attempted use of exposed camera passwords, recruitment scams and malware development by a novice. A separate case examines coordinated influence activity. Accounts were banned, while successful deployment of the cyber and fraud examples remained unconfirmed.",
      "scope": "Published April 23 despite the March edition label. The linked PDF covers only the influence case; the cyber and fraud case studies are in the HTML.",
      "sourceIds": [],
      "reviewed": "2026-09-11",
      "linksTo": []
    },
    {
      "id": "openai-misuse-2025-06-05",
      "title": "Disrupting malicious uses of AI: June 2025",
      "publisher": "OpenAI",
      "date": "2025-06-05",
      "url": "https://openai.com/global-affairs/disrupting-malicious-uses-of-ai-june-2025/",
      "pdfUrl": "https://cdn.openai.com/threat-intelligence-reports/5f73af09-a3a3-4a55-992e-069237681620/disrupting-malicious-uses-of-ai-june-2025.pdf",
      "summary": "ScopeCreep used AI while developing malware disguised as a gaming utility. Other cases describe China-linked actors using models for research and technical support, alongside employment fraud, social engineering and scams.",
      "scope": "ScopeCreep was likely active, but widespread distribution was not established. Threat-actor experiments with automation do not demonstrate successful autonomous intrusion.",
      "sourceIds": [],
      "reviewed": "2026-09-11",
      "linksTo": [
        "openai-misuse-2025-02-21"
      ]
    },
    {
      "id": "openai-misuse-2025-10-07",
      "title": "Disrupting malicious uses of AI: October 2025",
      "publisher": "OpenAI",
      "date": "2025-10-07",
      "url": "https://openai.com/global-affairs/disrupting-malicious-uses-of-ai-october-2025/",
      "pdfUrl": "https://cdn.openai.com/threat-intelligence-reports/7d662b68-952f-4dfd-a2f2-fe55b041cc4a/disrupting-malicious-uses-of-ai-october-2025.pdf",
      "summary": "Three cyber investigations examine malware development and tailored phishing by Russian-, Korean- and Chinese-language operators. The report describes AI assisting existing workflows and preserves limits on attribution, off-platform visibility and claims of new attacker capability.",
      "scope": "Language alone is not attribution. Overlapping indicators connect some activity to other investigations, but do not prove every related malware sample was generated using AI.",
      "sourceIds": [],
      "reviewed": "2026-09-11",
      "linksTo": [
        "openai-state-actors-2024-02-14",
        "anthropic-misuse-2025-04-23"
      ]
    },
    {
      "id": "openai-misuse-2026-02-25",
      "title": "Disrupting malicious uses of our models: an update, February 2026",
      "publisher": "OpenAI",
      "date": "2026-02-25",
      "url": "https://openai.com/index/disrupting-malicious-ai-uses/",
      "pdfUrl": "https://cdn.openai.com/pdf/df438d70-e3fe-4a6c-a403-ff632def8f79/disrupting-malicious-uses-of-ai.pdf",
      "summary": "Date Bait combines human operators and AI chatbots in a romance-and-task scam. False Witness impersonates lawyers and authorities to target previous fraud victims. Both illustrate AI-assisted deception; the report also covers separate influence operations.",
      "scope": "Included for online fraud and impersonation, not as proof of technical intrusion. Claimed victim losses and scale drawn from scammer inputs were not independently verified.",
      "sourceIds": [],
      "reviewed": "2026-09-11",
      "linksTo": [
        "openai-misuse-2025-02-21",
        "openai-misuse-2025-06-05"
      ]
    }
  ]
}