Research · curated 23 Sep 2026
Beyond Predictable Paths: AI Security Incident Reporting for Compromised Agents
First reported arxiv.org
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Incident reporting for AI agents lacks frameworks tuned to agent-specific attack surfaces like memory poisoning and tool compromise, and this synthesis gives defenders a structured basis for capturing and comparing agentic-AI incidents.
An academic paper, drawing on input from 23 experts, examines how AI security incident reporting frameworks must be adapted for compromised AI agents, identifying required reporting elements such as agent memory and memory accesses, autonomy levels, and tool usage. The work references agent-specific vulnerabilities including EchoLeak (CVE-2025-32711), ShareLeak in Copilot Studio (CVE-2026-21520), Reprompt (CVE-2026-24307), and a GitHub Copilot tool compromise (CVE-2025-53773), and outlines open research questions on recording incidents and generalizing vulnerabilities.