{
  "dataset": "OWASP agentic threat classes to MITRE ATLAS case study crosswalk",
  "publisher": "Stingrai",
  "license": "CC BY 4.0",
  "license_url": "https://creativecommons.org/licenses/by/4.0/",
  "cut_off_date": "2026-07-28",
  "recheck_cadence": "monthly",
  "corpus": {
    "source": "https://github.com/mitre-atlas/atlas-data",
    "file": "dist/ATLAS-latest.yaml",
    "pinned_commit": "651dad90d3c007e797c89356fa1f4d8732f90c8d",
    "atlas_release": "2026.06",
    "total_case_studies": 63,
    "case_study_type_split": {
      "Exercise": 45,
      "Incident": 18
    },
    "earliest_event_date": "2016-03-23",
    "latest_event_date": "2026-05-07",
    "excluded_fields": [
      "actor"
    ],
    "excluded_fields_rationale": "ATLAS populates 'actor' predominantly with the discovering researcher rather than the adversary, so it cannot support a threat-group column."
  },
  "verdict_inheritance": "The evidence verdict on every mapped cell is MITRE's own case-study-type value, copied not re-adjudicated. Stingrai's only judgement is the mapping itself.",
  "mapping_rule": "A class is credited against an ATLAS case study only where the ATLAS record explicitly describes the mechanism defining that class, evidenced by a verbatim quoted sentence stored in the cell. No quote, no mapping.",
  "denominator_warning": "The two OWASP lists overlap and must never be summed. Report 10 and 17 as separate denominators.",
  "taxonomies": {
    "ASI_TOP10_2026": {
      "name": "OWASP Top 10 for Agentic Applications 2026",
      "published": "2025-12-09",
      "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
      "class_count": 10,
      "classes": {
        "ASI01": {
          "class_title": "Agent Goal Hijack",
          "atlas_incident_studies": 2,
          "atlas_exercise_studies": 6,
          "unindexed_receipts": 1,
          "atlas_evidence_status": "incident-backed",
          "incident_ids": [
            "AML.CS0047",
            "AML.CS0043"
          ],
          "exercise_ids": [
            "AML.CS0020",
            "AML.CS0026",
            "AML.CS0046",
            "AML.CS0051",
            "AML.CS0059",
            "AML.CS0062"
          ]
        },
        "ASI02": {
          "class_title": "Tool Misuse and Exploitation",
          "atlas_incident_studies": 1,
          "atlas_exercise_studies": 7,
          "unindexed_receipts": 2,
          "atlas_evidence_status": "incident-backed",
          "incident_ids": [
            "AML.CS0047"
          ],
          "exercise_ids": [
            "AML.CS0046",
            "AML.CS0038",
            "AML.CS0045",
            "AML.CS0055",
            "AML.CS0037",
            "AML.CS0048",
            "AML.CS0051"
          ]
        },
        "ASI03": {
          "class_title": "Identity and Privilege Abuse",
          "atlas_incident_studies": 2,
          "atlas_exercise_studies": 5,
          "unindexed_receipts": 1,
          "atlas_evidence_status": "incident-backed",
          "incident_ids": [
            "AML.CS0030",
            "AML.CS0057"
          ],
          "exercise_ids": [
            "AML.CS0048",
            "AML.CS0036",
            "AML.CS0050",
            "AML.CS0045",
            "AML.CS0039"
          ]
        },
        "ASI04": {
          "class_title": "Agentic Supply Chain Vulnerabilities",
          "atlas_incident_studies": 4,
          "atlas_exercise_studies": 4,
          "unindexed_receipts": 1,
          "atlas_evidence_status": "incident-backed",
          "incident_ids": [
            "AML.CS0053",
            "AML.CS0047",
            "AML.CS0031",
            "AML.CS0015"
          ],
          "exercise_ids": [
            "AML.CS0049",
            "AML.CS0054",
            "AML.CS0041",
            "AML.CS0027"
          ]
        },
        "ASI05": {
          "class_title": "Unexpected Code Execution (RCE)",
          "atlas_incident_studies": 2,
          "atlas_exercise_studies": 7,
          "unindexed_receipts": 2,
          "atlas_evidence_status": "incident-backed",
          "incident_ids": [
            "AML.CS0031",
            "AML.CS0023"
          ],
          "exercise_ids": [
            "AML.CS0016",
            "AML.CS0052",
            "AML.CS0062",
            "AML.CS0050",
            "AML.CS0046",
            "AML.CS0049",
            "AML.CS0048"
          ]
        },
        "ASI06": {
          "class_title": "Memory & Context Poisoning",
          "atlas_incident_studies": 1,
          "atlas_exercise_studies": 7,
          "unindexed_receipts": 0,
          "atlas_evidence_status": "incident-backed",
          "incident_ids": [
            "AML.CS0009"
          ],
          "exercise_ids": [
            "AML.CS0040",
            "AML.CS0035",
            "AML.CS0026",
            "AML.CS0054",
            "AML.CS0051",
            "AML.CS0059",
            "AML.CS0060"
          ]
        },
        "ASI07": {
          "class_title": "Insecure Inter-Agent Communication",
          "atlas_incident_studies": 0,
          "atlas_exercise_studies": 1,
          "unindexed_receipts": 0,
          "atlas_evidence_status": "exercise-only",
          "incident_ids": [],
          "exercise_ids": [
            "AML.CS0024"
          ]
        },
        "ASI08": {
          "class_title": "Cascading Failures",
          "atlas_incident_studies": 0,
          "atlas_exercise_studies": 3,
          "unindexed_receipts": 0,
          "atlas_evidence_status": "exercise-only",
          "incident_ids": [],
          "exercise_ids": [
            "AML.CS0024",
            "AML.CS0022",
            "AML.CS0049"
          ]
        },
        "ASI09": {
          "class_title": "Human-Agent Trust Exploitation",
          "atlas_incident_studies": 0,
          "atlas_exercise_studies": 3,
          "unindexed_receipts": 0,
          "atlas_evidence_status": "exercise-only",
          "incident_ids": [],
          "exercise_ids": [
            "AML.CS0026",
            "AML.CS0020",
            "AML.CS0060"
          ]
        },
        "ASI10": {
          "class_title": "Rogue Agents",
          "atlas_incident_studies": 1,
          "atlas_exercise_studies": 2,
          "unindexed_receipts": 3,
          "atlas_evidence_status": "incident-backed",
          "incident_ids": [
            "AML.CS0047"
          ],
          "exercise_ids": [
            "AML.CS0051",
            "AML.CS0024"
          ]
        }
      }
    },
    "THREATS_MITIGATIONS_V1_1": {
      "name": "OWASP Agentic AI Threats and Mitigations",
      "version": "1.1",
      "published": "2025-12",
      "url": "https://genai.owasp.org/resource/agentic-ai-threats-and-mitigations/",
      "class_count": 17,
      "classes": {
        "T1": {
          "class_title": "Memory Poisoning",
          "atlas_incident_studies": 1,
          "atlas_exercise_studies": 6,
          "unindexed_receipts": 0,
          "atlas_evidence_status": "incident-backed",
          "incident_ids": [
            "AML.CS0009"
          ],
          "exercise_ids": [
            "AML.CS0040",
            "AML.CS0035",
            "AML.CS0026",
            "AML.CS0054",
            "AML.CS0051",
            "AML.CS0059"
          ]
        },
        "T2": {
          "class_title": "Tool Misuse",
          "atlas_incident_studies": 1,
          "atlas_exercise_studies": 6,
          "unindexed_receipts": 2,
          "atlas_evidence_status": "incident-backed",
          "incident_ids": [
            "AML.CS0047"
          ],
          "exercise_ids": [
            "AML.CS0046",
            "AML.CS0038",
            "AML.CS0045",
            "AML.CS0055",
            "AML.CS0037",
            "AML.CS0048"
          ]
        },
        "T3": {
          "class_title": "Privilege Compromise",
          "atlas_incident_studies": 2,
          "atlas_exercise_studies": 4,
          "unindexed_receipts": 1,
          "atlas_evidence_status": "incident-backed",
          "incident_ids": [
            "AML.CS0030",
            "AML.CS0057"
          ],
          "exercise_ids": [
            "AML.CS0048",
            "AML.CS0036",
            "AML.CS0050",
            "AML.CS0039"
          ]
        },
        "T4": {
          "class_title": "Resource Overload",
          "atlas_incident_studies": 1,
          "atlas_exercise_studies": 1,
          "unindexed_receipts": 0,
          "atlas_evidence_status": "incident-backed",
          "incident_ids": [
            "AML.CS0030"
          ],
          "exercise_ids": [
            "AML.CS0010"
          ]
        },
        "T5": {
          "class_title": "Cascading Hallucination Attacks",
          "atlas_incident_studies": 0,
          "atlas_exercise_studies": 1,
          "unindexed_receipts": 0,
          "atlas_evidence_status": "exercise-only",
          "incident_ids": [],
          "exercise_ids": [
            "AML.CS0022"
          ]
        },
        "T6": {
          "class_title": "Intent Breaking & Goal Manipulation",
          "atlas_incident_studies": 2,
          "atlas_exercise_studies": 4,
          "unindexed_receipts": 1,
          "atlas_evidence_status": "incident-backed",
          "incident_ids": [
            "AML.CS0047",
            "AML.CS0043"
          ],
          "exercise_ids": [
            "AML.CS0020",
            "AML.CS0026",
            "AML.CS0051",
            "AML.CS0059"
          ]
        },
        "T7": {
          "class_title": "Misaligned & Deceptive Behaviors",
          "atlas_incident_studies": 0,
          "atlas_exercise_studies": 0,
          "unindexed_receipts": 0,
          "atlas_evidence_status": "no qualifying ATLAS entry",
          "incident_ids": [],
          "exercise_ids": []
        },
        "T8": {
          "class_title": "Repudiation & Untraceability",
          "atlas_incident_studies": 1,
          "atlas_exercise_studies": 1,
          "unindexed_receipts": 0,
          "atlas_evidence_status": "incident-backed",
          "incident_ids": [
            "AML.CS0042"
          ],
          "exercise_ids": [
            "AML.CS0061"
          ]
        },
        "T9": {
          "class_title": "Identity Spoofing & Impersonation / Agent Identity Compromise",
          "atlas_incident_studies": 4,
          "atlas_exercise_studies": 2,
          "unindexed_receipts": 0,
          "atlas_evidence_status": "incident-backed",
          "incident_ids": [
            "AML.CS0053",
            "AML.CS0017",
            "AML.CS0004",
            "AML.CS0034"
          ],
          "exercise_ids": [
            "AML.CS0036",
            "AML.CS0027"
          ]
        },
        "T10": {
          "class_title": "Overwhelming Human in the Loop",
          "atlas_incident_studies": 0,
          "atlas_exercise_studies": 0,
          "unindexed_receipts": 0,
          "atlas_evidence_status": "no qualifying ATLAS entry",
          "incident_ids": [],
          "exercise_ids": []
        },
        "T11": {
          "class_title": "Unexpected RCE and Code Attacks",
          "atlas_incident_studies": 2,
          "atlas_exercise_studies": 5,
          "unindexed_receipts": 2,
          "atlas_evidence_status": "incident-backed",
          "incident_ids": [
            "AML.CS0031",
            "AML.CS0023"
          ],
          "exercise_ids": [
            "AML.CS0016",
            "AML.CS0052",
            "AML.CS0062",
            "AML.CS0050",
            "AML.CS0049"
          ]
        },
        "T12": {
          "class_title": "Agent Communication Poisoning",
          "atlas_incident_studies": 0,
          "atlas_exercise_studies": 1,
          "unindexed_receipts": 0,
          "atlas_evidence_status": "exercise-only",
          "incident_ids": [],
          "exercise_ids": [
            "AML.CS0024"
          ]
        },
        "T13": {
          "class_title": "Rogue Agents in Multi-Agent Systems",
          "atlas_incident_studies": 1,
          "atlas_exercise_studies": 2,
          "unindexed_receipts": 3,
          "atlas_evidence_status": "incident-backed",
          "incident_ids": [
            "AML.CS0047"
          ],
          "exercise_ids": [
            "AML.CS0051",
            "AML.CS0024"
          ]
        },
        "T14": {
          "class_title": "Human Attacks on Multi-Agent Systems",
          "atlas_incident_studies": 0,
          "atlas_exercise_studies": 2,
          "unindexed_receipts": 0,
          "atlas_evidence_status": "exercise-only",
          "incident_ids": [],
          "exercise_ids": [
            "AML.CS0039",
            "AML.CS0037"
          ]
        },
        "T15": {
          "class_title": "Human Manipulation",
          "atlas_incident_studies": 1,
          "atlas_exercise_studies": 2,
          "unindexed_receipts": 0,
          "atlas_evidence_status": "incident-backed",
          "incident_ids": [
            "AML.CS0009"
          ],
          "exercise_ids": [
            "AML.CS0026",
            "AML.CS0020"
          ]
        },
        "T16": {
          "class_title": "Insecure Inter-Agent Protocol Abuse",
          "atlas_incident_studies": 1,
          "atlas_exercise_studies": 2,
          "unindexed_receipts": 0,
          "atlas_evidence_status": "incident-backed",
          "incident_ids": [
            "AML.CS0053"
          ],
          "exercise_ids": [
            "AML.CS0054",
            "AML.CS0045"
          ]
        },
        "T17": {
          "class_title": "Supply Chain Compromise",
          "atlas_incident_studies": 4,
          "atlas_exercise_studies": 3,
          "unindexed_receipts": 1,
          "atlas_evidence_status": "incident-backed",
          "incident_ids": [
            "AML.CS0053",
            "AML.CS0047",
            "AML.CS0031",
            "AML.CS0015"
          ],
          "exercise_ids": [
            "AML.CS0049",
            "AML.CS0041",
            "AML.CS0027"
          ]
        }
      }
    }
  },
  "already_indexed_corrections": [
    {
      "ref": "PROMPTSTEAL",
      "url": "https://services.google.com/fh/files/misc/advances-in-threat-actor-usage-of-ai-tools-en.pdf",
      "atlas_id": "AML.CS0044",
      "note": "Checked as an unindexed candidate and found to be ALREADY INDEXED under its CERT-UA alias LAMEHUG. Tracked by Google Threat Intelligence Group as PROMPTSTEAL and by CERT-UA as LAMEHUG."
    }
  ],
  "revision_log": [
    {
      "date": "2026-07-28",
      "version": "1.0",
      "change": "Initial publication. Corpus pinned at ATLAS 2026.06 commit 651dad90d3c007e797c89356fa1f4d8732f90c8d."
    }
  ],
  "rows": [
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI01",
      "class_title": "Agent Goal Hijack",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0047",
      "atlas_case_study_name": "Code to Deploy Destructive AI Agent Discovered in Amazon Q VS Code Extension",
      "mitre_case_study_type": "Incident",
      "event_date": "2025-07-13",
      "evidence_quote": "The commit was designed to cause the VS Code extension to deploy an Amazon Q (Amazon's generative AI assistant) agent prompted to \"clean a system to near-factory state and delete file-system and cloud resources.\"",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0047",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI01",
      "class_title": "Agent Goal Hijack",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0043",
      "atlas_case_study_name": "Malware Prototype with Embedded Prompt Injection",
      "mitre_case_study_type": "Incident",
      "event_date": "2025-06-25",
      "evidence_quote": "identified a prototype malware sample in the wild that contained a prompt injection, which appeared to be designed to manipulate LLM-based malware detectors and/or analysis tools",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0043",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": "Prompt injection recovered from a live sample; ATLAS records that it was not effective against the models tested."
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI01",
      "class_title": "Agent Goal Hijack",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0020",
      "atlas_case_study_name": "Indirect Prompt Injection Threats: Bing Chat Data Pirate",
      "mitre_case_study_type": "Exercise",
      "event_date": "2023-01-01",
      "evidence_quote": "The website includes a prompt which is read by Bing and changes its behavior to access user information, which in turn can sent to an attacker.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0020",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI01",
      "class_title": "Agent Goal Hijack",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0026",
      "atlas_case_study_name": "Financial Transaction Hijacking with M365 Copilot as an Insider",
      "mitre_case_study_type": "Exercise",
      "event_date": "2024-08-08",
      "evidence_quote": "The prompt injection overrode Copilot's search functionality to treat the attacker's content as a retrieved document and manipulate the document reference in its response.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0026",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI01",
      "class_title": "Agent Goal Hijack",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0046",
      "atlas_case_study_name": "Data Destruction via Indirect Prompt Injection Targeting Claude Computer-Use",
      "mitre_case_study_type": "Exercise",
      "event_date": "2024-10-24",
      "evidence_quote": "It caused Claude to invoke its `bash` tool and execute a command to delete the victim's filesystem",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0046",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI01",
      "class_title": "Agent Goal Hijack",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0051",
      "atlas_case_study_name": "OpenClaw Command & Control via Prompt Injection",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-02-03",
      "evidence_quote": "Once executed, the script plants persistent malicious instructions into future system prompts, allowing the attacker to issue new commands, turning OpenClaw into a command and control agent.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0051",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI01",
      "class_title": "Agent Goal Hijack",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0059",
      "atlas_case_study_name": "EchoLeak: Zero-Click Prompt Injection Targeting M365 Copilot for Data Exfiltration",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-05-25",
      "evidence_quote": "When M365 Copilot retrieved the email as part of its retrieval-augmented generation (RAG) context, the malicious instructions caused Copilot to search the user's accessible Microsoft 365 data and include sensitive information in its response context.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0059",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI01",
      "class_title": "Agent Goal Hijack",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0062",
      "atlas_case_study_name": "RCE Vulnerability in Semantic Kernel Search Plugin",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-05-07",
      "evidence_quote": "The agent can call its Search Plugin with parameters based on user-provided input and the Search Plugin's filter parameter is executed using `eval()`.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0062",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI02",
      "class_title": "Tool Misuse and Exploitation",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0047",
      "atlas_case_study_name": "Code to Deploy Destructive AI Agent Discovered in Amazon Q VS Code Extension",
      "mitre_case_study_type": "Incident",
      "event_date": "2025-07-13",
      "evidence_quote": "The commit was designed to cause the VS Code extension to deploy an Amazon Q (Amazon's generative AI assistant) agent prompted to \"clean a system to near-factory state and delete file-system and cloud resources.\"",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0047",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI02",
      "class_title": "Tool Misuse and Exploitation",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0046",
      "atlas_case_study_name": "Data Destruction via Indirect Prompt Injection Targeting Claude Computer-Use",
      "mitre_case_study_type": "Exercise",
      "event_date": "2024-10-24",
      "evidence_quote": "It caused Claude to invoke its `bash` tool and execute a command to delete the victim's filesystem",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0046",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI02",
      "class_title": "Tool Misuse and Exploitation",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0038",
      "atlas_case_study_name": "Planting Instructions for Delayed Automatic AI Agent Tool Invocation",
      "mitre_case_study_type": "Exercise",
      "event_date": "2024-02-01",
      "evidence_quote": "demonstrated that Google Gemini is susceptible to automated tool invocation by delaying the execution to the next conversation turn",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0038",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI02",
      "class_title": "Tool Misuse and Exploitation",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0045",
      "atlas_case_study_name": "Data Exfiltration via an MCP Server used by Cursor",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-06-24",
      "evidence_quote": "The prompt instructs Cursor to execute a shell command to exfiltrate the victim's AI agent configuration files containing credentials.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0045",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI02",
      "class_title": "Tool Misuse and Exploitation",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0055",
      "atlas_case_study_name": "AI ClickFix: Hijacking Computer-Use Agents Using ClickFix",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-05-24",
      "evidence_quote": "The agent then proceeded to follow the instructions, opening a terminal, pasting the malicious command, and executing it.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0055",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI02",
      "class_title": "Tool Misuse and Exploitation",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0037",
      "atlas_case_study_name": "Data Exfiltration via Agent Tools in Copilot Studio",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-06-01",
      "evidence_quote": "Once they understand the AI agent's capabilities, the researchers are able to craft a prompt that retrieves private customer data from the organization's RAG database and CRM, and exfiltrate it via the AI agent's email tool.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0037",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI02",
      "class_title": "Tool Misuse and Exploitation",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0048",
      "atlas_case_study_name": "Exposed ClawdBot Control Interfaces Leads to Credential Access and Execution",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-01-25",
      "evidence_quote": "They were also able to invoke ClawdBot's skills by prompting it via the chat interface, leading to root access in the container.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0048",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI02",
      "class_title": "Tool Misuse and Exploitation",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0051",
      "atlas_case_study_name": "OpenClaw Command & Control via Prompt Injection",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-02-03",
      "evidence_quote": "Once executed, the script plants persistent malicious instructions into future system prompts, allowing the attacker to issue new commands, turning OpenClaw into a command and control agent.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0051",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI03",
      "class_title": "Identity and Privilege Abuse",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0030",
      "atlas_case_study_name": "LLM Jacking",
      "mitre_case_study_type": "Incident",
      "event_date": "2024-05-06",
      "evidence_quote": "malicious actors utilized stolen credentials to gain access to cloud-hosted large language models (LLMs)",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0030",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI03",
      "class_title": "Identity and Privilege Abuse",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0057",
      "atlas_case_study_name": "Storm-2139 Azure OpenAI Guardrail Bypass",
      "mitre_case_study_type": "Incident",
      "event_date": "2024-12-01",
      "evidence_quote": "The group developed and operated tools and services that bypassed safety safeguards, modified service capabilities, and enabled end users to generate harmful and illicit content",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0057",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI03",
      "class_title": "Identity and Privilege Abuse",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0048",
      "atlas_case_study_name": "Exposed ClawdBot Control Interfaces Leads to Credential Access and Execution",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-01-25",
      "evidence_quote": "They were also able to invoke ClawdBot's skills by prompting it via the chat interface, leading to root access in the container.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0048",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI03",
      "class_title": "Identity and Privilege Abuse",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0036",
      "atlas_case_study_name": "AIKatz: Attacking LLM Desktop Applications",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-01-01",
      "evidence_quote": "An attacker could then use those tokens to impersonate as the victim to the LLM backed, thereby gaining access to the victim's conversations as well as the ability to interfere in future conversations.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0036",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI03",
      "class_title": "Identity and Privilege Abuse",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0050",
      "atlas_case_study_name": "OpenClaw 1-Click Remote Code Execution",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-02-01",
      "evidence_quote": "steal authentication tokens from the OpenClaw control interface via a WebSocket connection",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0050",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI03",
      "class_title": "Identity and Privilege Abuse",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0045",
      "atlas_case_study_name": "Data Exfiltration via an MCP Server used by Cursor",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-06-24",
      "evidence_quote": "The prompt instructs Cursor to execute a shell command to exfiltrate the victim's AI agent configuration files containing credentials.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0045",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI03",
      "class_title": "Identity and Privilege Abuse",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0039",
      "atlas_case_study_name": "Living Off AI: Prompt Injection via Jira Service Management",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-06-19",
      "evidence_quote": "These AI agents, operating with internal context and trust, may interpret and execute the malicious instructions, leading to unauthorized actions such as data exfiltration, privilege escalation, or system manipulation.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0039",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI04",
      "class_title": "Agentic Supply Chain Vulnerabilities",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0053",
      "atlas_case_study_name": "Poisoned Postmark MCP Server Email Exfiltration",
      "mitre_case_study_type": "Incident",
      "event_date": "2025-09-01",
      "evidence_quote": "The malicious version added the bad actor's email address in the BCC line of all emails sent by the MCP tool.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0053",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI04",
      "class_title": "Agentic Supply Chain Vulnerabilities",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0047",
      "atlas_case_study_name": "Code to Deploy Destructive AI Agent Discovered in Amazon Q VS Code Extension",
      "mitre_case_study_type": "Incident",
      "event_date": "2025-07-13",
      "evidence_quote": "The commit was designed to cause the VS Code extension to deploy an Amazon Q (Amazon's generative AI assistant) agent prompted to \"clean a system to near-factory state and delete file-system and cloud resources.\"",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0047",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI04",
      "class_title": "Agentic Supply Chain Vulnerabilities",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0031",
      "atlas_case_study_name": "Malicious Models on Hugging Face",
      "mitre_case_study_type": "Incident",
      "event_date": "2025-02-25",
      "evidence_quote": "The models were found to execute reverse shells when loaded, which grants the threat actor command and control capabilities on the victim's system.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0031",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI04",
      "class_title": "Agentic Supply Chain Vulnerabilities",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0015",
      "atlas_case_study_name": "Compromised PyTorch Dependency Chain",
      "mitre_case_study_type": "Incident",
      "event_date": "2022-12-25",
      "evidence_quote": "The malicious binary had the same name as a PyTorch dependency and the PyPI package manager (pip) installed this malicious package instead of the legitimate one.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0015",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": "AI framework dependency chain rather than agent runtime; retained because ASI04 scopes models, libraries and tools."
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI04",
      "class_title": "Agentic Supply Chain Vulnerabilities",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0049",
      "atlas_case_study_name": "Supply Chain Compromise via Poisoned ClawdBot Skill",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-01-26",
      "evidence_quote": "The poisoned Skill contained a prompt injection that caused ClawdBot to execute a shell command that reached the researcher's server.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0049",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI04",
      "class_title": "Agentic Supply Chain Vulnerabilities",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0054",
      "atlas_case_study_name": "Data Exfiltration via Remote Poisoned MCP Tool",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-04-01",
      "evidence_quote": "They show that an MCP Tool can contain malicious prompts in its docstring description, which is ingested into the AI agent's context, modifying its behavior.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0054",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI04",
      "class_title": "Agentic Supply Chain Vulnerabilities",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0041",
      "atlas_case_study_name": "Rules File Backdoor: Supply Chain Attack on AI Coding Assistants",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-03-18",
      "evidence_quote": "The attack uses invisible Unicode characters to hide malicious prompts that manipulate the AI to insert backdoors, vulnerabilities, or malicious scripts into generated code.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0041",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI04",
      "class_title": "Agentic Supply Chain Vulnerabilities",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0027",
      "atlas_case_study_name": "Organization Confusion on Hugging Face",
      "mitre_case_study_type": "Exercise",
      "event_date": "2023-08-23",
      "evidence_quote": "This gave the researcher full access to any AI models uploaded by the employees, including the ability to replace models with malicious versions.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0027",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI05",
      "class_title": "Unexpected Code Execution (RCE)",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0031",
      "atlas_case_study_name": "Malicious Models on Hugging Face",
      "mitre_case_study_type": "Incident",
      "event_date": "2025-02-25",
      "evidence_quote": "The models were found to execute reverse shells when loaded, which grants the threat actor command and control capabilities on the victim's system.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0031",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI05",
      "class_title": "Unexpected Code Execution (RCE)",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0023",
      "atlas_case_study_name": "ShadowRay",
      "mitre_case_study_type": "Incident",
      "event_date": "2023-09-05",
      "evidence_quote": "Ray's Job API allows for arbitrary remote execution by design.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0023",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI05",
      "class_title": "Unexpected Code Execution (RCE)",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0016",
      "atlas_case_study_name": "Achieving Code Execution in MathGPT via Prompt Injection",
      "mitre_case_study_type": "Exercise",
      "event_date": "2023-01-28",
      "evidence_quote": "In the MathGPT application, GPT-3 is used to convert the user's natural language question into Python code that is then executed.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0016",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI05",
      "class_title": "Unexpected Code Execution (RCE)",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0052",
      "atlas_case_study_name": "LLMSmith: RCE Vulnerabilities in LLM-Integrated Applications",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-02-27",
      "evidence_quote": "They discovered applications deployed on the public internet built using these LLM frameworks and demonstrated the RCE vulnerabilities could be exploited using prompt injection.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0052",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI05",
      "class_title": "Unexpected Code Execution (RCE)",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0062",
      "atlas_case_study_name": "RCE Vulnerability in Semantic Kernel Search Plugin",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-05-07",
      "evidence_quote": "The agent can call its Search Plugin with parameters based on user-provided input and the Search Plugin's filter parameter is executed using `eval()`.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0062",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI05",
      "class_title": "Unexpected Code Execution (RCE)",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0050",
      "atlas_case_study_name": "OpenClaw 1-Click Remote Code Execution",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-02-01",
      "evidence_quote": "steal authentication tokens from the OpenClaw control interface via a WebSocket connection",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0050",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI05",
      "class_title": "Unexpected Code Execution (RCE)",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0046",
      "atlas_case_study_name": "Data Destruction via Indirect Prompt Injection Targeting Claude Computer-Use",
      "mitre_case_study_type": "Exercise",
      "event_date": "2024-10-24",
      "evidence_quote": "It caused Claude to invoke its `bash` tool and execute a command to delete the victim's filesystem",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0046",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI05",
      "class_title": "Unexpected Code Execution (RCE)",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0049",
      "atlas_case_study_name": "Supply Chain Compromise via Poisoned ClawdBot Skill",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-01-26",
      "evidence_quote": "The poisoned Skill contained a prompt injection that caused ClawdBot to execute a shell command that reached the researcher's server.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0049",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI05",
      "class_title": "Unexpected Code Execution (RCE)",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0048",
      "atlas_case_study_name": "Exposed ClawdBot Control Interfaces Leads to Credential Access and Execution",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-01-25",
      "evidence_quote": "They were also able to invoke ClawdBot's skills by prompting it via the chat interface, leading to root access in the container.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0048",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI06",
      "class_title": "Memory & Context Poisoning",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0009",
      "atlas_case_study_name": "Tay Poisoning",
      "mitre_case_study_type": "Incident",
      "event_date": "2016-03-23",
      "evidence_quote": "A coordinated attack encouraged malicious users to tweet abusive and offensive language at Tay, which eventually led to Tay generating similarly inflammatory content towards other users.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0009",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": "Pre-agentic conversational system. Retained because the defining mechanism, adversarial input persistently altering later outputs, is explicitly described."
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI06",
      "class_title": "Memory & Context Poisoning",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0040",
      "atlas_case_study_name": "Hacking ChatGPT's Memories with Prompt Injection",
      "mitre_case_study_type": "Exercise",
      "event_date": "2024-02-01",
      "evidence_quote": "The researcher demonstrated that these injected memories persist across chat sessions.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0040",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI06",
      "class_title": "Memory & Context Poisoning",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0035",
      "atlas_case_study_name": "Data Exfiltration from Slack AI via Indirect Prompt Injection",
      "mitre_case_study_type": "Exercise",
      "event_date": "2024-08-20",
      "evidence_quote": "The attack relied on Slack AI ingesting a malicious prompt from a post in a public channel into its RAG database and a victim user querying Slack AI, causing the prompt to be retrieved and executed.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0035",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI06",
      "class_title": "Memory & Context Poisoning",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0026",
      "atlas_case_study_name": "Financial Transaction Hijacking with M365 Copilot as an Insider",
      "mitre_case_study_type": "Exercise",
      "event_date": "2024-08-08",
      "evidence_quote": "The prompt injection overrode Copilot's search functionality to treat the attacker's content as a retrieved document and manipulate the document reference in its response.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0026",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI06",
      "class_title": "Memory & Context Poisoning",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0054",
      "atlas_case_study_name": "Data Exfiltration via Remote Poisoned MCP Tool",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-04-01",
      "evidence_quote": "They show that an MCP Tool can contain malicious prompts in its docstring description, which is ingested into the AI agent's context, modifying its behavior.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0054",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI06",
      "class_title": "Memory & Context Poisoning",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0051",
      "atlas_case_study_name": "OpenClaw Command & Control via Prompt Injection",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-02-03",
      "evidence_quote": "Once executed, the script plants persistent malicious instructions into future system prompts, allowing the attacker to issue new commands, turning OpenClaw into a command and control agent.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0051",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI06",
      "class_title": "Memory & Context Poisoning",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0059",
      "atlas_case_study_name": "EchoLeak: Zero-Click Prompt Injection Targeting M365 Copilot for Data Exfiltration",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-05-25",
      "evidence_quote": "When M365 Copilot retrieved the email as part of its retrieval-augmented generation (RAG) context, the malicious instructions caused Copilot to search the user's accessible Microsoft 365 data and include sensitive information in its response context.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0059",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI06",
      "class_title": "Memory & Context Poisoning",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0060",
      "atlas_case_study_name": "Cross-Site Scripting via Prompt Manipulation in Lenovo AI Chatbot",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-08-18",
      "evidence_quote": "The response was saved in the user's chat history, creating a stored cross-site scripting (XSS) payload.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0060",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI07",
      "class_title": "Insecure Inter-Agent Communication",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0024",
      "atlas_case_study_name": "Morris II Worm: RAG-Based Attack",
      "mitre_case_study_type": "Exercise",
      "event_date": "2024-03-05",
      "evidence_quote": "The worm uses an adversarial self-replicating prompt which uses prompt injection to replicate the prompt as output and perform malicious activity.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0024",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI08",
      "class_title": "Cascading Failures",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0024",
      "atlas_case_study_name": "Morris II Worm: RAG-Based Attack",
      "mitre_case_study_type": "Exercise",
      "event_date": "2024-03-05",
      "evidence_quote": "The worm uses an adversarial self-replicating prompt which uses prompt injection to replicate the prompt as output and perform malicious activity.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0024",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI08",
      "class_title": "Cascading Failures",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0022",
      "atlas_case_study_name": "ChatGPT Package Hallucination",
      "mitre_case_study_type": "Exercise",
      "event_date": "2024-06-01",
      "evidence_quote": "Then users of the same or similar large language models may encounter the same hallucination and ultimately download and execute the malicious package leading to a variety of potential harms.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0022",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI08",
      "class_title": "Cascading Failures",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0049",
      "atlas_case_study_name": "Supply Chain Compromise via Poisoned ClawdBot Skill",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-01-26",
      "evidence_quote": "The poisoned Skill contained a prompt injection that caused ClawdBot to execute a shell command that reached the researcher's server.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0049",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI09",
      "class_title": "Human-Agent Trust Exploitation",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0026",
      "atlas_case_study_name": "Financial Transaction Hijacking with M365 Copilot as an Insider",
      "mitre_case_study_type": "Exercise",
      "event_date": "2024-08-08",
      "evidence_quote": "The prompt injection overrode Copilot's search functionality to treat the attacker's content as a retrieved document and manipulate the document reference in its response.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0026",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI09",
      "class_title": "Human-Agent Trust Exploitation",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0020",
      "atlas_case_study_name": "Indirect Prompt Injection Threats: Bing Chat Data Pirate",
      "mitre_case_study_type": "Exercise",
      "event_date": "2023-01-01",
      "evidence_quote": "The website includes a prompt which is read by Bing and changes its behavior to access user information, which in turn can sent to an attacker.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0020",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI09",
      "class_title": "Human-Agent Trust Exploitation",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0060",
      "atlas_case_study_name": "Cross-Site Scripting via Prompt Manipulation in Lenovo AI Chatbot",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-08-18",
      "evidence_quote": "The response was saved in the user's chat history, creating a stored cross-site scripting (XSS) payload.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0060",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI10",
      "class_title": "Rogue Agents",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0047",
      "atlas_case_study_name": "Code to Deploy Destructive AI Agent Discovered in Amazon Q VS Code Extension",
      "mitre_case_study_type": "Incident",
      "event_date": "2025-07-13",
      "evidence_quote": "The commit was designed to cause the VS Code extension to deploy an Amazon Q (Amazon's generative AI assistant) agent prompted to \"clean a system to near-factory state and delete file-system and cloud resources.\"",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0047",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI10",
      "class_title": "Rogue Agents",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0051",
      "atlas_case_study_name": "OpenClaw Command & Control via Prompt Injection",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-02-03",
      "evidence_quote": "Once executed, the script plants persistent malicious instructions into future system prompts, allowing the attacker to issue new commands, turning OpenClaw into a command and control agent.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0051",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI10",
      "class_title": "Rogue Agents",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0024",
      "atlas_case_study_name": "Morris II Worm: RAG-Based Attack",
      "mitre_case_study_type": "Exercise",
      "event_date": "2024-03-05",
      "evidence_quote": "The worm uses an adversarial self-replicating prompt which uses prompt injection to replicate the prompt as output and perform malicious activity.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0024",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T1",
      "class_title": "Memory Poisoning",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0009",
      "atlas_case_study_name": "Tay Poisoning",
      "mitre_case_study_type": "Incident",
      "event_date": "2016-03-23",
      "evidence_quote": "A coordinated attack encouraged malicious users to tweet abusive and offensive language at Tay, which eventually led to Tay generating similarly inflammatory content towards other users.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0009",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": "Pre-agentic conversational system. Retained because the defining mechanism is explicitly described."
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T1",
      "class_title": "Memory Poisoning",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0040",
      "atlas_case_study_name": "Hacking ChatGPT's Memories with Prompt Injection",
      "mitre_case_study_type": "Exercise",
      "event_date": "2024-02-01",
      "evidence_quote": "The researcher demonstrated that these injected memories persist across chat sessions.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0040",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T1",
      "class_title": "Memory Poisoning",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0035",
      "atlas_case_study_name": "Data Exfiltration from Slack AI via Indirect Prompt Injection",
      "mitre_case_study_type": "Exercise",
      "event_date": "2024-08-20",
      "evidence_quote": "The attack relied on Slack AI ingesting a malicious prompt from a post in a public channel into its RAG database and a victim user querying Slack AI, causing the prompt to be retrieved and executed.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0035",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T1",
      "class_title": "Memory Poisoning",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0026",
      "atlas_case_study_name": "Financial Transaction Hijacking with M365 Copilot as an Insider",
      "mitre_case_study_type": "Exercise",
      "event_date": "2024-08-08",
      "evidence_quote": "The prompt injection overrode Copilot's search functionality to treat the attacker's content as a retrieved document and manipulate the document reference in its response.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0026",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T1",
      "class_title": "Memory Poisoning",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0054",
      "atlas_case_study_name": "Data Exfiltration via Remote Poisoned MCP Tool",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-04-01",
      "evidence_quote": "They show that an MCP Tool can contain malicious prompts in its docstring description, which is ingested into the AI agent's context, modifying its behavior.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0054",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T1",
      "class_title": "Memory Poisoning",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0051",
      "atlas_case_study_name": "OpenClaw Command & Control via Prompt Injection",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-02-03",
      "evidence_quote": "Once executed, the script plants persistent malicious instructions into future system prompts, allowing the attacker to issue new commands, turning OpenClaw into a command and control agent.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0051",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T1",
      "class_title": "Memory Poisoning",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0059",
      "atlas_case_study_name": "EchoLeak: Zero-Click Prompt Injection Targeting M365 Copilot for Data Exfiltration",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-05-25",
      "evidence_quote": "When M365 Copilot retrieved the email as part of its retrieval-augmented generation (RAG) context, the malicious instructions caused Copilot to search the user's accessible Microsoft 365 data and include sensitive information in its response context.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0059",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T2",
      "class_title": "Tool Misuse",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0047",
      "atlas_case_study_name": "Code to Deploy Destructive AI Agent Discovered in Amazon Q VS Code Extension",
      "mitre_case_study_type": "Incident",
      "event_date": "2025-07-13",
      "evidence_quote": "The commit was designed to cause the VS Code extension to deploy an Amazon Q (Amazon's generative AI assistant) agent prompted to \"clean a system to near-factory state and delete file-system and cloud resources.\"",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0047",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T2",
      "class_title": "Tool Misuse",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0046",
      "atlas_case_study_name": "Data Destruction via Indirect Prompt Injection Targeting Claude Computer-Use",
      "mitre_case_study_type": "Exercise",
      "event_date": "2024-10-24",
      "evidence_quote": "It caused Claude to invoke its `bash` tool and execute a command to delete the victim's filesystem",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0046",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T2",
      "class_title": "Tool Misuse",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0038",
      "atlas_case_study_name": "Planting Instructions for Delayed Automatic AI Agent Tool Invocation",
      "mitre_case_study_type": "Exercise",
      "event_date": "2024-02-01",
      "evidence_quote": "demonstrated that Google Gemini is susceptible to automated tool invocation by delaying the execution to the next conversation turn",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0038",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T2",
      "class_title": "Tool Misuse",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0045",
      "atlas_case_study_name": "Data Exfiltration via an MCP Server used by Cursor",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-06-24",
      "evidence_quote": "The prompt instructs Cursor to execute a shell command to exfiltrate the victim's AI agent configuration files containing credentials.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0045",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T2",
      "class_title": "Tool Misuse",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0055",
      "atlas_case_study_name": "AI ClickFix: Hijacking Computer-Use Agents Using ClickFix",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-05-24",
      "evidence_quote": "The agent then proceeded to follow the instructions, opening a terminal, pasting the malicious command, and executing it.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0055",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T2",
      "class_title": "Tool Misuse",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0037",
      "atlas_case_study_name": "Data Exfiltration via Agent Tools in Copilot Studio",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-06-01",
      "evidence_quote": "Once they understand the AI agent's capabilities, the researchers are able to craft a prompt that retrieves private customer data from the organization's RAG database and CRM, and exfiltrate it via the AI agent's email tool.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0037",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T2",
      "class_title": "Tool Misuse",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0048",
      "atlas_case_study_name": "Exposed ClawdBot Control Interfaces Leads to Credential Access and Execution",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-01-25",
      "evidence_quote": "They were also able to invoke ClawdBot's skills by prompting it via the chat interface, leading to root access in the container.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0048",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T3",
      "class_title": "Privilege Compromise",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0030",
      "atlas_case_study_name": "LLM Jacking",
      "mitre_case_study_type": "Incident",
      "event_date": "2024-05-06",
      "evidence_quote": "malicious actors utilized stolen credentials to gain access to cloud-hosted large language models (LLMs)",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0030",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T3",
      "class_title": "Privilege Compromise",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0057",
      "atlas_case_study_name": "Storm-2139 Azure OpenAI Guardrail Bypass",
      "mitre_case_study_type": "Incident",
      "event_date": "2024-12-01",
      "evidence_quote": "The group developed and operated tools and services that bypassed safety safeguards, modified service capabilities, and enabled end users to generate harmful and illicit content",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0057",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T3",
      "class_title": "Privilege Compromise",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0048",
      "atlas_case_study_name": "Exposed ClawdBot Control Interfaces Leads to Credential Access and Execution",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-01-25",
      "evidence_quote": "They were also able to invoke ClawdBot's skills by prompting it via the chat interface, leading to root access in the container.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0048",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T3",
      "class_title": "Privilege Compromise",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0036",
      "atlas_case_study_name": "AIKatz: Attacking LLM Desktop Applications",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-01-01",
      "evidence_quote": "An attacker could then use those tokens to impersonate as the victim to the LLM backed, thereby gaining access to the victim's conversations as well as the ability to interfere in future conversations.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0036",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T3",
      "class_title": "Privilege Compromise",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0050",
      "atlas_case_study_name": "OpenClaw 1-Click Remote Code Execution",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-02-01",
      "evidence_quote": "steal authentication tokens from the OpenClaw control interface via a WebSocket connection",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0050",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T3",
      "class_title": "Privilege Compromise",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0039",
      "atlas_case_study_name": "Living Off AI: Prompt Injection via Jira Service Management",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-06-19",
      "evidence_quote": "These AI agents, operating with internal context and trust, may interpret and execute the malicious instructions, leading to unauthorized actions such as data exfiltration, privilege escalation, or system manipulation.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0039",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T4",
      "class_title": "Resource Overload",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0030",
      "atlas_case_study_name": "LLM Jacking",
      "mitre_case_study_type": "Incident",
      "event_date": "2024-05-06",
      "evidence_quote": "malicious actors utilized stolen credentials to gain access to cloud-hosted large language models (LLMs)",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0030",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": "Unauthorized consumption of paid model capacity rather than denial of service."
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T4",
      "class_title": "Resource Overload",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0010",
      "atlas_case_study_name": "Microsoft Azure Service Disruption",
      "mitre_case_study_type": "Exercise",
      "event_date": "2020-01-01",
      "evidence_quote": "The Microsoft AI Red Team performed a red team exercise on an internal Azure service with the intention of disrupting its service.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0010",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T5",
      "class_title": "Cascading Hallucination Attacks",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0022",
      "atlas_case_study_name": "ChatGPT Package Hallucination",
      "mitre_case_study_type": "Exercise",
      "event_date": "2024-06-01",
      "evidence_quote": "Then users of the same or similar large language models may encounter the same hallucination and ultimately download and execute the malicious package leading to a variety of potential harms.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0022",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T6",
      "class_title": "Intent Breaking & Goal Manipulation",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0047",
      "atlas_case_study_name": "Code to Deploy Destructive AI Agent Discovered in Amazon Q VS Code Extension",
      "mitre_case_study_type": "Incident",
      "event_date": "2025-07-13",
      "evidence_quote": "The commit was designed to cause the VS Code extension to deploy an Amazon Q (Amazon's generative AI assistant) agent prompted to \"clean a system to near-factory state and delete file-system and cloud resources.\"",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0047",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T6",
      "class_title": "Intent Breaking & Goal Manipulation",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0043",
      "atlas_case_study_name": "Malware Prototype with Embedded Prompt Injection",
      "mitre_case_study_type": "Incident",
      "event_date": "2025-06-25",
      "evidence_quote": "identified a prototype malware sample in the wild that contained a prompt injection, which appeared to be designed to manipulate LLM-based malware detectors and/or analysis tools",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0043",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": "ATLAS records that the injection was not effective against the models tested."
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T6",
      "class_title": "Intent Breaking & Goal Manipulation",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0020",
      "atlas_case_study_name": "Indirect Prompt Injection Threats: Bing Chat Data Pirate",
      "mitre_case_study_type": "Exercise",
      "event_date": "2023-01-01",
      "evidence_quote": "The website includes a prompt which is read by Bing and changes its behavior to access user information, which in turn can sent to an attacker.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0020",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T6",
      "class_title": "Intent Breaking & Goal Manipulation",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0026",
      "atlas_case_study_name": "Financial Transaction Hijacking with M365 Copilot as an Insider",
      "mitre_case_study_type": "Exercise",
      "event_date": "2024-08-08",
      "evidence_quote": "The prompt injection overrode Copilot's search functionality to treat the attacker's content as a retrieved document and manipulate the document reference in its response.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0026",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T6",
      "class_title": "Intent Breaking & Goal Manipulation",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0051",
      "atlas_case_study_name": "OpenClaw Command & Control via Prompt Injection",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-02-03",
      "evidence_quote": "Once executed, the script plants persistent malicious instructions into future system prompts, allowing the attacker to issue new commands, turning OpenClaw into a command and control agent.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0051",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T6",
      "class_title": "Intent Breaking & Goal Manipulation",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0059",
      "atlas_case_study_name": "EchoLeak: Zero-Click Prompt Injection Targeting M365 Copilot for Data Exfiltration",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-05-25",
      "evidence_quote": "When M365 Copilot retrieved the email as part of its retrieval-augmented generation (RAG) context, the malicious instructions caused Copilot to search the user's accessible Microsoft 365 data and include sensitive information in its response context.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0059",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T7",
      "class_title": "Misaligned & Deceptive Behaviors",
      "evidence_kind": "no_qualifying_entry",
      "atlas_case_study_id": "",
      "atlas_case_study_name": "",
      "mitre_case_study_type": "",
      "event_date": "",
      "evidence_quote": "",
      "source_url": "",
      "not_indexed_as_of": "2026-07-28",
      "atlas_submission_candidate": "no",
      "note": "No qualifying ATLAS entry or primary receipt found in the pre-registered corpus as of 2026-07-28. T7 is defined by misalignment arising 'without direct malicious input'. Every ATLAS case study in the pinned corpus has an identified adversary supplying that input, so none satisfies the pre-registered rule."
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T8",
      "class_title": "Repudiation & Untraceability",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0042",
      "atlas_case_study_name": "SesameOp: Novel backdoor uses OpenAI Assistants API for command and control",
      "mitre_case_study_type": "Incident",
      "event_date": "2025-07-01",
      "evidence_quote": "The SesameOp malware used the OpenAI API to fetch and execute the threat actor's commands and to exfiltrate encrypted results from the victim system.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0042",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": "Attribution gap arises from an AI service acting as intermediary rather than from an agent's own action log."
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T8",
      "class_title": "Repudiation & Untraceability",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0061",
      "atlas_case_study_name": "AI in the Middle: Web-Based AI Services as C2 Relays",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-02-17",
      "evidence_quote": "The proof of concept used public AI web interfaces, including Grok and Microsoft Copilot, to cause the AI service to fetch attacker-controlled URLs, relay victim data in outbound requests, and return attacker-supplied commands through normal AI assistant responses.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0061",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": "Same caveat as AML.CS0042."
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T9",
      "class_title": "Identity Spoofing & Impersonation / Agent Identity Compromise",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0053",
      "atlas_case_study_name": "Poisoned Postmark MCP Server Email Exfiltration",
      "mitre_case_study_type": "Incident",
      "event_date": "2025-09-01",
      "evidence_quote": "The malicious version added the bad actor's email address in the BCC line of all emails sent by the MCP tool.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0053",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T9",
      "class_title": "Identity Spoofing & Impersonation / Agent Identity Compromise",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0017",
      "atlas_case_study_name": "Bypassing ID.me Identity Verification",
      "mitre_case_study_type": "Incident",
      "event_date": "2020-10-01",
      "evidence_quote": "The individual was able to verify stolen identities by wearing the same wig in his submitted selfie.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0017",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T9",
      "class_title": "Identity Spoofing & Impersonation / Agent Identity Compromise",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0004",
      "atlas_case_study_name": "Camera Hijack Attack on Facial Recognition System",
      "mitre_case_study_type": "Incident",
      "event_date": "2020-01-01",
      "evidence_quote": "This type of camera hijack attack can evade the traditional live facial recognition authentication model and enable access to privileged systems and victim impersonation.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0004",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T9",
      "class_title": "Identity Spoofing & Impersonation / Agent Identity Compromise",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0034",
      "atlas_case_study_name": "ProKYC: Deepfake Tool for Account Fraud Attacks",
      "mitre_case_study_type": "Incident",
      "event_date": "2024-10-09",
      "evidence_quote": "ProKYC can create fake identity documents and generate deepfake selfie videos, two key pieces of biometric data used during KYC verification.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0034",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T9",
      "class_title": "Identity Spoofing & Impersonation / Agent Identity Compromise",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0036",
      "atlas_case_study_name": "AIKatz: Attacking LLM Desktop Applications",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-01-01",
      "evidence_quote": "An attacker could then use those tokens to impersonate as the victim to the LLM backed, thereby gaining access to the victim's conversations as well as the ability to interfere in future conversations.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0036",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T9",
      "class_title": "Identity Spoofing & Impersonation / Agent Identity Compromise",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0027",
      "atlas_case_study_name": "Organization Confusion on Hugging Face",
      "mitre_case_study_type": "Exercise",
      "event_date": "2023-08-23",
      "evidence_quote": "This gave the researcher full access to any AI models uploaded by the employees, including the ability to replace models with malicious versions.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0027",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T10",
      "class_title": "Overwhelming Human in the Loop",
      "evidence_kind": "no_qualifying_entry",
      "atlas_case_study_id": "",
      "atlas_case_study_name": "",
      "mitre_case_study_type": "",
      "event_date": "",
      "evidence_quote": "",
      "source_url": "",
      "not_indexed_as_of": "2026-07-28",
      "atlas_submission_candidate": "no",
      "note": "No qualifying ATLAS entry or primary receipt found in the pre-registered corpus as of 2026-07-28. No ATLAS record in the pinned corpus explicitly describes defeating or saturating a human review step as the mechanism of compromise."
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T11",
      "class_title": "Unexpected RCE and Code Attacks",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0031",
      "atlas_case_study_name": "Malicious Models on Hugging Face",
      "mitre_case_study_type": "Incident",
      "event_date": "2025-02-25",
      "evidence_quote": "The models were found to execute reverse shells when loaded, which grants the threat actor command and control capabilities on the victim's system.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0031",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T11",
      "class_title": "Unexpected RCE and Code Attacks",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0023",
      "atlas_case_study_name": "ShadowRay",
      "mitre_case_study_type": "Incident",
      "event_date": "2023-09-05",
      "evidence_quote": "Ray's Job API allows for arbitrary remote execution by design.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0023",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T11",
      "class_title": "Unexpected RCE and Code Attacks",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0016",
      "atlas_case_study_name": "Achieving Code Execution in MathGPT via Prompt Injection",
      "mitre_case_study_type": "Exercise",
      "event_date": "2023-01-28",
      "evidence_quote": "In the MathGPT application, GPT-3 is used to convert the user's natural language question into Python code that is then executed.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0016",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T11",
      "class_title": "Unexpected RCE and Code Attacks",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0052",
      "atlas_case_study_name": "LLMSmith: RCE Vulnerabilities in LLM-Integrated Applications",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-02-27",
      "evidence_quote": "They discovered applications deployed on the public internet built using these LLM frameworks and demonstrated the RCE vulnerabilities could be exploited using prompt injection.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0052",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T11",
      "class_title": "Unexpected RCE and Code Attacks",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0062",
      "atlas_case_study_name": "RCE Vulnerability in Semantic Kernel Search Plugin",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-05-07",
      "evidence_quote": "The agent can call its Search Plugin with parameters based on user-provided input and the Search Plugin's filter parameter is executed using `eval()`.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0062",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T11",
      "class_title": "Unexpected RCE and Code Attacks",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0050",
      "atlas_case_study_name": "OpenClaw 1-Click Remote Code Execution",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-02-01",
      "evidence_quote": "steal authentication tokens from the OpenClaw control interface via a WebSocket connection",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0050",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T11",
      "class_title": "Unexpected RCE and Code Attacks",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0049",
      "atlas_case_study_name": "Supply Chain Compromise via Poisoned ClawdBot Skill",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-01-26",
      "evidence_quote": "The poisoned Skill contained a prompt injection that caused ClawdBot to execute a shell command that reached the researcher's server.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0049",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T12",
      "class_title": "Agent Communication Poisoning",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0024",
      "atlas_case_study_name": "Morris II Worm: RAG-Based Attack",
      "mitre_case_study_type": "Exercise",
      "event_date": "2024-03-05",
      "evidence_quote": "The worm uses an adversarial self-replicating prompt which uses prompt injection to replicate the prompt as output and perform malicious activity.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0024",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T13",
      "class_title": "Rogue Agents in Multi-Agent Systems",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0047",
      "atlas_case_study_name": "Code to Deploy Destructive AI Agent Discovered in Amazon Q VS Code Extension",
      "mitre_case_study_type": "Incident",
      "event_date": "2025-07-13",
      "evidence_quote": "The commit was designed to cause the VS Code extension to deploy an Amazon Q (Amazon's generative AI assistant) agent prompted to \"clean a system to near-factory state and delete file-system and cloud resources.\"",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0047",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T13",
      "class_title": "Rogue Agents in Multi-Agent Systems",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0051",
      "atlas_case_study_name": "OpenClaw Command & Control via Prompt Injection",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-02-03",
      "evidence_quote": "Once executed, the script plants persistent malicious instructions into future system prompts, allowing the attacker to issue new commands, turning OpenClaw into a command and control agent.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0051",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T13",
      "class_title": "Rogue Agents in Multi-Agent Systems",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0024",
      "atlas_case_study_name": "Morris II Worm: RAG-Based Attack",
      "mitre_case_study_type": "Exercise",
      "event_date": "2024-03-05",
      "evidence_quote": "The worm uses an adversarial self-replicating prompt which uses prompt injection to replicate the prompt as output and perform malicious activity.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0024",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T14",
      "class_title": "Human Attacks on Multi-Agent Systems",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0039",
      "atlas_case_study_name": "Living Off AI: Prompt Injection via Jira Service Management",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-06-19",
      "evidence_quote": "These AI agents, operating with internal context and trust, may interpret and execute the malicious instructions, leading to unauthorized actions such as data exfiltration, privilege escalation, or system manipulation.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0039",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T14",
      "class_title": "Human Attacks on Multi-Agent Systems",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0037",
      "atlas_case_study_name": "Data Exfiltration via Agent Tools in Copilot Studio",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-06-01",
      "evidence_quote": "Once they understand the AI agent's capabilities, the researchers are able to craft a prompt that retrieves private customer data from the organization's RAG database and CRM, and exfiltrate it via the AI agent's email tool.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0037",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T15",
      "class_title": "Human Manipulation",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0009",
      "atlas_case_study_name": "Tay Poisoning",
      "mitre_case_study_type": "Incident",
      "event_date": "2016-03-23",
      "evidence_quote": "A coordinated attack encouraged malicious users to tweet abusive and offensive language at Tay, which eventually led to Tay generating similarly inflammatory content towards other users.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0009",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T15",
      "class_title": "Human Manipulation",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0026",
      "atlas_case_study_name": "Financial Transaction Hijacking with M365 Copilot as an Insider",
      "mitre_case_study_type": "Exercise",
      "event_date": "2024-08-08",
      "evidence_quote": "The prompt injection overrode Copilot's search functionality to treat the attacker's content as a retrieved document and manipulate the document reference in its response.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0026",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T15",
      "class_title": "Human Manipulation",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0020",
      "atlas_case_study_name": "Indirect Prompt Injection Threats: Bing Chat Data Pirate",
      "mitre_case_study_type": "Exercise",
      "event_date": "2023-01-01",
      "evidence_quote": "The website includes a prompt which is read by Bing and changes its behavior to access user information, which in turn can sent to an attacker.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0020",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T16",
      "class_title": "Insecure Inter-Agent Protocol Abuse",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0053",
      "atlas_case_study_name": "Poisoned Postmark MCP Server Email Exfiltration",
      "mitre_case_study_type": "Incident",
      "event_date": "2025-09-01",
      "evidence_quote": "The malicious version added the bad actor's email address in the BCC line of all emails sent by the MCP tool.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0053",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T16",
      "class_title": "Insecure Inter-Agent Protocol Abuse",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0054",
      "atlas_case_study_name": "Data Exfiltration via Remote Poisoned MCP Tool",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-04-01",
      "evidence_quote": "They show that an MCP Tool can contain malicious prompts in its docstring description, which is ingested into the AI agent's context, modifying its behavior.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0054",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T16",
      "class_title": "Insecure Inter-Agent Protocol Abuse",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0045",
      "atlas_case_study_name": "Data Exfiltration via an MCP Server used by Cursor",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-06-24",
      "evidence_quote": "The prompt instructs Cursor to execute a shell command to exfiltrate the victim's AI agent configuration files containing credentials.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0045",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T17",
      "class_title": "Supply Chain Compromise",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0053",
      "atlas_case_study_name": "Poisoned Postmark MCP Server Email Exfiltration",
      "mitre_case_study_type": "Incident",
      "event_date": "2025-09-01",
      "evidence_quote": "The malicious version added the bad actor's email address in the BCC line of all emails sent by the MCP tool.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0053",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T17",
      "class_title": "Supply Chain Compromise",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0047",
      "atlas_case_study_name": "Code to Deploy Destructive AI Agent Discovered in Amazon Q VS Code Extension",
      "mitre_case_study_type": "Incident",
      "event_date": "2025-07-13",
      "evidence_quote": "The commit was designed to cause the VS Code extension to deploy an Amazon Q (Amazon's generative AI assistant) agent prompted to \"clean a system to near-factory state and delete file-system and cloud resources.\"",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0047",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T17",
      "class_title": "Supply Chain Compromise",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0031",
      "atlas_case_study_name": "Malicious Models on Hugging Face",
      "mitre_case_study_type": "Incident",
      "event_date": "2025-02-25",
      "evidence_quote": "The models were found to execute reverse shells when loaded, which grants the threat actor command and control capabilities on the victim's system.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0031",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T17",
      "class_title": "Supply Chain Compromise",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0015",
      "atlas_case_study_name": "Compromised PyTorch Dependency Chain",
      "mitre_case_study_type": "Incident",
      "event_date": "2022-12-25",
      "evidence_quote": "The malicious binary had the same name as a PyTorch dependency and the PyPI package manager (pip) installed this malicious package instead of the legitimate one.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0015",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T17",
      "class_title": "Supply Chain Compromise",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0049",
      "atlas_case_study_name": "Supply Chain Compromise via Poisoned ClawdBot Skill",
      "mitre_case_study_type": "Exercise",
      "event_date": "2026-01-26",
      "evidence_quote": "The poisoned Skill contained a prompt injection that caused ClawdBot to execute a shell command that reached the researcher's server.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0049",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T17",
      "class_title": "Supply Chain Compromise",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0041",
      "atlas_case_study_name": "Rules File Backdoor: Supply Chain Attack on AI Coding Assistants",
      "mitre_case_study_type": "Exercise",
      "event_date": "2025-03-18",
      "evidence_quote": "The attack uses invisible Unicode characters to hide malicious prompts that manipulate the AI to insert backdoors, vulnerabilities, or malicious scripts into generated code.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0041",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T17",
      "class_title": "Supply Chain Compromise",
      "evidence_kind": "atlas_case_study",
      "atlas_case_study_id": "AML.CS0027",
      "atlas_case_study_name": "Organization Confusion on Hugging Face",
      "mitre_case_study_type": "Exercise",
      "event_date": "2023-08-23",
      "evidence_quote": "This gave the researcher full access to any AI models uploaded by the employees, including the ability to replace models with malicious versions.",
      "source_url": "https://atlas.mitre.org/studies/AML.CS0027",
      "not_indexed_as_of": "",
      "atlas_submission_candidate": "no",
      "note": ""
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI01",
      "class_title": "Agent Goal Hijack",
      "evidence_kind": "unindexed_primary_receipt",
      "atlas_case_study_id": "",
      "atlas_case_study_name": "ATT&CK Campaign C0062 / GTG-1002",
      "mitre_case_study_type": "not adjudicated by MITRE",
      "event_date": "2025-09",
      "evidence_quote": "The Anthropic AI-orchestrated Campaign was a highly coordinated operation that manipulated Claude Code to perform reconnaissance, vulnerability discovery, exploitation, lateral movement, credential harvesting, data analysis, and exfiltration operations at approximately 30 entities in the technology, financial, chemical, and government sectors.",
      "source_url": "https://attack.mitre.org/campaigns/C0062/",
      "not_indexed_as_of": "2026-07-28",
      "atlas_submission_candidate": "yes",
      "note": "Indexed by MITRE in ATT&CK as a Campaign, not in ATLAS as a case study. Corroborated by the vendor disclosure at https://www.anthropic.com/news/disrupting-AI-espionage which states the actor was able to use AI to perform 80-90% of the campaign."
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI02",
      "class_title": "Tool Misuse and Exploitation",
      "evidence_kind": "unindexed_primary_receipt",
      "atlas_case_study_id": "",
      "atlas_case_study_name": "ATT&CK Campaign C0062 / GTG-1002",
      "mitre_case_study_type": "not adjudicated by MITRE",
      "event_date": "2025-09",
      "evidence_quote": "The Anthropic AI-orchestrated Campaign was a highly coordinated operation that manipulated Claude Code to perform reconnaissance, vulnerability discovery, exploitation, lateral movement, credential harvesting, data analysis, and exfiltration operations at approximately 30 entities in the technology, financial, chemical, and government sectors.",
      "source_url": "https://attack.mitre.org/campaigns/C0062/",
      "not_indexed_as_of": "2026-07-28",
      "atlas_submission_candidate": "yes",
      "note": "Indexed by MITRE in ATT&CK as a Campaign, not in ATLAS as a case study. Corroborated by the vendor disclosure at https://www.anthropic.com/news/disrupting-AI-espionage which states the actor was able to use AI to perform 80-90% of the campaign."
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI03",
      "class_title": "Identity and Privilege Abuse",
      "evidence_kind": "unindexed_primary_receipt",
      "atlas_case_study_id": "",
      "atlas_case_study_name": "ATT&CK Campaign C0062 / GTG-1002",
      "mitre_case_study_type": "not adjudicated by MITRE",
      "event_date": "2025-09",
      "evidence_quote": "The Anthropic AI-orchestrated Campaign was a highly coordinated operation that manipulated Claude Code to perform reconnaissance, vulnerability discovery, exploitation, lateral movement, credential harvesting, data analysis, and exfiltration operations at approximately 30 entities in the technology, financial, chemical, and government sectors.",
      "source_url": "https://attack.mitre.org/campaigns/C0062/",
      "not_indexed_as_of": "2026-07-28",
      "atlas_submission_candidate": "yes",
      "note": "Indexed by MITRE in ATT&CK as a Campaign, not in ATLAS as a case study. Corroborated by the vendor disclosure at https://www.anthropic.com/news/disrupting-AI-espionage which states the actor was able to use AI to perform 80-90% of the campaign."
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI10",
      "class_title": "Rogue Agents",
      "evidence_kind": "unindexed_primary_receipt",
      "atlas_case_study_id": "",
      "atlas_case_study_name": "ATT&CK Campaign C0062 / GTG-1002",
      "mitre_case_study_type": "not adjudicated by MITRE",
      "event_date": "2025-09",
      "evidence_quote": "The Anthropic AI-orchestrated Campaign was a highly coordinated operation that manipulated Claude Code to perform reconnaissance, vulnerability discovery, exploitation, lateral movement, credential harvesting, data analysis, and exfiltration operations at approximately 30 entities in the technology, financial, chemical, and government sectors.",
      "source_url": "https://attack.mitre.org/campaigns/C0062/",
      "not_indexed_as_of": "2026-07-28",
      "atlas_submission_candidate": "yes",
      "note": "Indexed by MITRE in ATT&CK as a Campaign, not in ATLAS as a case study. Corroborated by the vendor disclosure at https://www.anthropic.com/news/disrupting-AI-espionage which states the actor was able to use AI to perform 80-90% of the campaign."
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T2",
      "class_title": "Tool Misuse",
      "evidence_kind": "unindexed_primary_receipt",
      "atlas_case_study_id": "",
      "atlas_case_study_name": "ATT&CK Campaign C0062 / GTG-1002",
      "mitre_case_study_type": "not adjudicated by MITRE",
      "event_date": "2025-09",
      "evidence_quote": "The Anthropic AI-orchestrated Campaign was a highly coordinated operation that manipulated Claude Code to perform reconnaissance, vulnerability discovery, exploitation, lateral movement, credential harvesting, data analysis, and exfiltration operations at approximately 30 entities in the technology, financial, chemical, and government sectors.",
      "source_url": "https://attack.mitre.org/campaigns/C0062/",
      "not_indexed_as_of": "2026-07-28",
      "atlas_submission_candidate": "yes",
      "note": "Indexed by MITRE in ATT&CK as a Campaign, not in ATLAS as a case study. Corroborated by the vendor disclosure at https://www.anthropic.com/news/disrupting-AI-espionage which states the actor was able to use AI to perform 80-90% of the campaign."
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T3",
      "class_title": "Privilege Compromise",
      "evidence_kind": "unindexed_primary_receipt",
      "atlas_case_study_id": "",
      "atlas_case_study_name": "ATT&CK Campaign C0062 / GTG-1002",
      "mitre_case_study_type": "not adjudicated by MITRE",
      "event_date": "2025-09",
      "evidence_quote": "The Anthropic AI-orchestrated Campaign was a highly coordinated operation that manipulated Claude Code to perform reconnaissance, vulnerability discovery, exploitation, lateral movement, credential harvesting, data analysis, and exfiltration operations at approximately 30 entities in the technology, financial, chemical, and government sectors.",
      "source_url": "https://attack.mitre.org/campaigns/C0062/",
      "not_indexed_as_of": "2026-07-28",
      "atlas_submission_candidate": "yes",
      "note": "Indexed by MITRE in ATT&CK as a Campaign, not in ATLAS as a case study. Corroborated by the vendor disclosure at https://www.anthropic.com/news/disrupting-AI-espionage which states the actor was able to use AI to perform 80-90% of the campaign."
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T6",
      "class_title": "Intent Breaking & Goal Manipulation",
      "evidence_kind": "unindexed_primary_receipt",
      "atlas_case_study_id": "",
      "atlas_case_study_name": "ATT&CK Campaign C0062 / GTG-1002",
      "mitre_case_study_type": "not adjudicated by MITRE",
      "event_date": "2025-09",
      "evidence_quote": "The Anthropic AI-orchestrated Campaign was a highly coordinated operation that manipulated Claude Code to perform reconnaissance, vulnerability discovery, exploitation, lateral movement, credential harvesting, data analysis, and exfiltration operations at approximately 30 entities in the technology, financial, chemical, and government sectors.",
      "source_url": "https://attack.mitre.org/campaigns/C0062/",
      "not_indexed_as_of": "2026-07-28",
      "atlas_submission_candidate": "yes",
      "note": "Indexed by MITRE in ATT&CK as a Campaign, not in ATLAS as a case study. Corroborated by the vendor disclosure at https://www.anthropic.com/news/disrupting-AI-espionage which states the actor was able to use AI to perform 80-90% of the campaign."
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T13",
      "class_title": "Rogue Agents in Multi-Agent Systems",
      "evidence_kind": "unindexed_primary_receipt",
      "atlas_case_study_id": "",
      "atlas_case_study_name": "ATT&CK Campaign C0062 / GTG-1002",
      "mitre_case_study_type": "not adjudicated by MITRE",
      "event_date": "2025-09",
      "evidence_quote": "The Anthropic AI-orchestrated Campaign was a highly coordinated operation that manipulated Claude Code to perform reconnaissance, vulnerability discovery, exploitation, lateral movement, credential harvesting, data analysis, and exfiltration operations at approximately 30 entities in the technology, financial, chemical, and government sectors.",
      "source_url": "https://attack.mitre.org/campaigns/C0062/",
      "not_indexed_as_of": "2026-07-28",
      "atlas_submission_candidate": "yes",
      "note": "Indexed by MITRE in ATT&CK as a Campaign, not in ATLAS as a case study. Corroborated by the vendor disclosure at https://www.anthropic.com/news/disrupting-AI-espionage which states the actor was able to use AI to perform 80-90% of the campaign."
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI04",
      "class_title": "Agentic Supply Chain Vulnerabilities",
      "evidence_kind": "unindexed_primary_receipt",
      "atlas_case_study_id": "",
      "atlas_case_study_name": "Hugging Face security incident, July 2026",
      "mitre_case_study_type": "not adjudicated by MITRE",
      "event_date": "2026-07-16",
      "evidence_quote": "A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker.",
      "source_url": "https://huggingface.co/blog/security-incident-july-2026",
      "not_indexed_as_of": "2026-07-28",
      "atlas_submission_candidate": "yes",
      "note": "Post-dates the pinned ATLAS corpus. Second, corroborating disclosure published by OpenAI at https://openai.com/index/hugging-face-model-evaluation-security-incident/ (not quoted here: the page was not retrievable for direct quotation at the cut-off date)."
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI05",
      "class_title": "Unexpected Code Execution (RCE)",
      "evidence_kind": "unindexed_primary_receipt",
      "atlas_case_study_id": "",
      "atlas_case_study_name": "Hugging Face security incident, July 2026",
      "mitre_case_study_type": "not adjudicated by MITRE",
      "event_date": "2026-07-16",
      "evidence_quote": "A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker.",
      "source_url": "https://huggingface.co/blog/security-incident-july-2026",
      "not_indexed_as_of": "2026-07-28",
      "atlas_submission_candidate": "yes",
      "note": "Post-dates the pinned ATLAS corpus. Second, corroborating disclosure published by OpenAI at https://openai.com/index/hugging-face-model-evaluation-security-incident/ (not quoted here: the page was not retrievable for direct quotation at the cut-off date)."
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI10",
      "class_title": "Rogue Agents",
      "evidence_kind": "unindexed_primary_receipt",
      "atlas_case_study_id": "",
      "atlas_case_study_name": "Hugging Face security incident, July 2026",
      "mitre_case_study_type": "not adjudicated by MITRE",
      "event_date": "2026-07-16",
      "evidence_quote": "A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker.",
      "source_url": "https://huggingface.co/blog/security-incident-july-2026",
      "not_indexed_as_of": "2026-07-28",
      "atlas_submission_candidate": "yes",
      "note": "Post-dates the pinned ATLAS corpus. Second, corroborating disclosure published by OpenAI at https://openai.com/index/hugging-face-model-evaluation-security-incident/ (not quoted here: the page was not retrievable for direct quotation at the cut-off date)."
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T11",
      "class_title": "Unexpected RCE and Code Attacks",
      "evidence_kind": "unindexed_primary_receipt",
      "atlas_case_study_id": "",
      "atlas_case_study_name": "Hugging Face security incident, July 2026",
      "mitre_case_study_type": "not adjudicated by MITRE",
      "event_date": "2026-07-16",
      "evidence_quote": "A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker.",
      "source_url": "https://huggingface.co/blog/security-incident-july-2026",
      "not_indexed_as_of": "2026-07-28",
      "atlas_submission_candidate": "yes",
      "note": "Post-dates the pinned ATLAS corpus. Second, corroborating disclosure published by OpenAI at https://openai.com/index/hugging-face-model-evaluation-security-incident/ (not quoted here: the page was not retrievable for direct quotation at the cut-off date)."
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T13",
      "class_title": "Rogue Agents in Multi-Agent Systems",
      "evidence_kind": "unindexed_primary_receipt",
      "atlas_case_study_id": "",
      "atlas_case_study_name": "Hugging Face security incident, July 2026",
      "mitre_case_study_type": "not adjudicated by MITRE",
      "event_date": "2026-07-16",
      "evidence_quote": "A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker.",
      "source_url": "https://huggingface.co/blog/security-incident-july-2026",
      "not_indexed_as_of": "2026-07-28",
      "atlas_submission_candidate": "yes",
      "note": "Post-dates the pinned ATLAS corpus. Second, corroborating disclosure published by OpenAI at https://openai.com/index/hugging-face-model-evaluation-security-incident/ (not quoted here: the page was not retrievable for direct quotation at the cut-off date)."
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T17",
      "class_title": "Supply Chain Compromise",
      "evidence_kind": "unindexed_primary_receipt",
      "atlas_case_study_id": "",
      "atlas_case_study_name": "Hugging Face security incident, July 2026",
      "mitre_case_study_type": "not adjudicated by MITRE",
      "event_date": "2026-07-16",
      "evidence_quote": "A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker.",
      "source_url": "https://huggingface.co/blog/security-incident-july-2026",
      "not_indexed_as_of": "2026-07-28",
      "atlas_submission_candidate": "yes",
      "note": "Post-dates the pinned ATLAS corpus. Second, corroborating disclosure published by OpenAI at https://openai.com/index/hugging-face-model-evaluation-security-incident/ (not quoted here: the page was not retrievable for direct quotation at the cut-off date)."
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI02",
      "class_title": "Tool Misuse and Exploitation",
      "evidence_kind": "unindexed_primary_receipt",
      "atlas_case_study_id": "",
      "atlas_case_study_name": "JADEPUFFER agentic ransomware",
      "mitre_case_study_type": "not adjudicated by MITRE",
      "event_date": "2026-07-01",
      "evidence_quote": "the first documented case of agentic ransomware: a complete extortion operation driven end-to-end by a large language model (LLM)",
      "source_url": "https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion",
      "not_indexed_as_of": "2026-07-28",
      "atlas_submission_candidate": "yes",
      "note": "Post-dates the pinned ATLAS corpus."
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI05",
      "class_title": "Unexpected Code Execution (RCE)",
      "evidence_kind": "unindexed_primary_receipt",
      "atlas_case_study_id": "",
      "atlas_case_study_name": "JADEPUFFER agentic ransomware",
      "mitre_case_study_type": "not adjudicated by MITRE",
      "event_date": "2026-07-01",
      "evidence_quote": "the first documented case of agentic ransomware: a complete extortion operation driven end-to-end by a large language model (LLM)",
      "source_url": "https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion",
      "not_indexed_as_of": "2026-07-28",
      "atlas_submission_candidate": "yes",
      "note": "Post-dates the pinned ATLAS corpus."
    },
    {
      "taxonomy": "ASI_TOP10_2026",
      "class_id": "ASI10",
      "class_title": "Rogue Agents",
      "evidence_kind": "unindexed_primary_receipt",
      "atlas_case_study_id": "",
      "atlas_case_study_name": "JADEPUFFER agentic ransomware",
      "mitre_case_study_type": "not adjudicated by MITRE",
      "event_date": "2026-07-01",
      "evidence_quote": "the first documented case of agentic ransomware: a complete extortion operation driven end-to-end by a large language model (LLM)",
      "source_url": "https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion",
      "not_indexed_as_of": "2026-07-28",
      "atlas_submission_candidate": "yes",
      "note": "Post-dates the pinned ATLAS corpus."
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T2",
      "class_title": "Tool Misuse",
      "evidence_kind": "unindexed_primary_receipt",
      "atlas_case_study_id": "",
      "atlas_case_study_name": "JADEPUFFER agentic ransomware",
      "mitre_case_study_type": "not adjudicated by MITRE",
      "event_date": "2026-07-01",
      "evidence_quote": "the first documented case of agentic ransomware: a complete extortion operation driven end-to-end by a large language model (LLM)",
      "source_url": "https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion",
      "not_indexed_as_of": "2026-07-28",
      "atlas_submission_candidate": "yes",
      "note": "Post-dates the pinned ATLAS corpus."
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T11",
      "class_title": "Unexpected RCE and Code Attacks",
      "evidence_kind": "unindexed_primary_receipt",
      "atlas_case_study_id": "",
      "atlas_case_study_name": "JADEPUFFER agentic ransomware",
      "mitre_case_study_type": "not adjudicated by MITRE",
      "event_date": "2026-07-01",
      "evidence_quote": "the first documented case of agentic ransomware: a complete extortion operation driven end-to-end by a large language model (LLM)",
      "source_url": "https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion",
      "not_indexed_as_of": "2026-07-28",
      "atlas_submission_candidate": "yes",
      "note": "Post-dates the pinned ATLAS corpus."
    },
    {
      "taxonomy": "THREATS_MITIGATIONS_V1_1",
      "class_id": "T13",
      "class_title": "Rogue Agents in Multi-Agent Systems",
      "evidence_kind": "unindexed_primary_receipt",
      "atlas_case_study_id": "",
      "atlas_case_study_name": "JADEPUFFER agentic ransomware",
      "mitre_case_study_type": "not adjudicated by MITRE",
      "event_date": "2026-07-01",
      "evidence_quote": "the first documented case of agentic ransomware: a complete extortion operation driven end-to-end by a large language model (LLM)",
      "source_url": "https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion",
      "not_indexed_as_of": "2026-07-28",
      "atlas_submission_candidate": "yes",
      "note": "Post-dates the pinned ATLAS corpus."
    }
  ]
}