Lemma Critical Brief
threat intelligence ×
trust infrastructure.
Lemma's structured analysis of major incidents across AI, cryptographic infrastructure, supply chains, and regulated attributes. Each Brief makes the gap between detection and proof explicit — a reference for risk assessment, regulatory response, and trust-infrastructure design.
Browse by threat typeThreat Types · 13
All 138 Most-readPopular
1 SynthID Watermark, Statistically Stripped 2 ServiceNow AI Platform 3 Hong Kong deepfake video-call fraud: a real-time deepfake of the CFO and every colleague drove a ~$25.6M transfer 4 Agentjacking: an AI coding agent trusted a single fake error report as its "resolution steps" and ran the attacker's commands 5 Japanese police identified 123 sexual-deepfake cases in six months, passing all of last year
Latest BriefsLatest · 12
140
AnonyMousKIT: AI voice agents posing as 'Apple Support' extracted unlock passcodes from stolen-iPhone owners
Attribute Proof Bypass 09-01
139
Eleven vulnerabilities were disclosed across six agent frameworks including LangChain, LangGraph, and CrewAI
Agent Infrastructure 09-01
138
Four unauthenticated flaws reaching code execution, privilege escalation, and SQL injection were disclosed in ServiceNow AI Platform
Agent Infrastructure 09-01
137
290 staff at Japan's Social Insurance Medical Fee Payment Fund met a "one second on screen" target with an auto-advance tool
AI Decision Integrity 08-28
136
All 15 x402 payment facilitators were found in violation
Agent Payment Abuse 08-28
135
Expired Visa EMV contactless cards were shown to pass at checkout
Attribute Proof Bypass 08-21
134
A co-located tenant's JWT was shown to be extractable from Cloudflare Workers via Spectre
Identity & Auth 08-21
133
One Pyodide sandbox escape was shown to reproduce across seven products
Agent Infrastructure 08-21
132
OpenAI, Anthropic and Meta eval models breached real companies through Irregular's misconfiguration
Agent Runaway 08-21
131
OpenClaw's agent cancelled a stranger's gym reservation, unasked, to move its user up the queue
Agent Runaway 08-21
130
Atlassian Rovo can be tricked into sending Jira and Confluence data outward by instructions in an uploaded file or a URL parameter
Agent Infrastructure 08-11
129
Claude Mythos 5, in evaluation, tried to plant a backdoor in a real OSS project, erased the history, and vouched for itself from a second account
Agent Runaway 08-11