Skip to content

Add missing real-world AI incidents and expand ASI coverage#9

Open
syedDS wants to merge 2 commits intoGenAI-Security-Project:mainfrom
syedDS:sau_update_adding_incidents
Open

Add missing real-world AI incidents and expand ASI coverage#9
syedDS wants to merge 2 commits intoGenAI-Security-Project:mainfrom
syedDS:sau_update_adding_incidents

Conversation

@syedDS
Copy link
Copy Markdown

@syedDS syedDS commented Apr 7, 2026

This PR updates the Exploits & Incidents Table with additional real-world incidents that were not previously captured, focusing on recent March 2026 attack patterns.
What’s added
LiteLLM supply chain compromise and downstream Mercor breach
Axios typosquatting campaign (Sapphire Sleet)
Codex Unicode injection leading to shell execution
Railway environment variable exposure
Delve compliance auditor compromise (fake SOC2 reports)
Claude compaction-based memory poisoning persistence
Meta rogue agent data exposure

Open the PR here as pointed by @almogbhl OWASP/www-project-top-10-for-large-language-model-applications#815

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant