A thorough compilation of major AI agent security incidents from 2024 to 2026 has been released, detailing 90 incidents in total. The database, which is updated weekly, covers a wide range of breaches, vulnerabilities, and attacks, including supply chain attacks, framework vulnerabilities, enterprise incidents, AI coding tool CVEs, and crypto exploits.
The incidents are organized by year and include key information such as dates, affected companies, impact, root cause, and relevant CVEs. The database also features 20 sourced industry statistics and an attack pattern taxonomy that groups incidents by type.
The database covers notable incidents involving companies such as Meta, Mercor, LiteLLM, Trivy, and Axios, as well as AI coding tools like Claude Code, Copilot, and Cursor. Additionally, it includes information on significant crypto exploits, including the Drift Protocol and Bybit incidents.
The database is available on GitHub and is open to contributions and updates from the community. The goal is to provide a factual and comprehensive resource for tracking AI agent security incidents, without product pitches or opinions.
Photo by panumas nikhomkhai on Pexels
Photos provided by Pexels
