Research · curated 23 Sep 2026

Beyond Predictable Paths: AI Security Incident Reporting for Compromised Agents

Coverage timeline

23 Sep 2026arxiv.orgprimary

Single-source research — first reported, latest, and curated coincide.

Why it matters

Incident reporting for AI agents lacks frameworks tuned to agent-specific attack surfaces like memory poisoning and tool compromise, and this synthesis gives defenders a structured basis for capturing and comparing agentic-AI incidents.

An academic paper, drawing on input from 23 experts, examines how AI security incident reporting frameworks must be adapted for compromised AI agents, identifying required reporting elements such as agent memory and memory accesses, autonomy levels, and tool usage. The work references agent-specific vulnerabilities including EchoLeak (CVE-2025-32711), ShareLeak in Copilot Studio (CVE-2026-21520), Reprompt (CVE-2026-24307), and a GitHub Copilot tool compromise (CVE-2025-53773), and outlines open research questions on recording incidents and generalizing vulnerabilities.