Lemma Critical Brief

threat intelligence × trust infrastructure.

Lemma's structured analysis of major incidents across AI, cryptographic infrastructure, supply chains, and regulated attributes. Each Brief makes the gap between detection and proof explicit — a reference for risk assessment, regulatory response, and trust-infrastructure design.

Category
43 All Briefs (by Pillar)
Pillar 01

Verifiable Origin

15 briefs

The layer that independently verifies the origin of messages, data, and code.

No. 045 · 2026-06-11

When One Laptop Meets the Multisig Threshold

Distributed Approval Collapses to a Single Custody Point (Humanity Protocol)

Bridge Config Trust Identity & Auth
Brief →
No. 038 · 2026-06-09

IronWorm

When Stolen Credentials Become Publishing Authority (npm Self-Propagating Implant)

Code Provenance Identity & Auth
Brief →
No. 036 · 2026-06-08

12.8 Billion Training Images Contained Passports, Résumés, and Faces

The Provenance and Consent of Training Data Were Never Verified at Collection

Training Data Provenance Data ProvenanceAttribute Proof Bypass
Brief →
No. 030 · 2026-06-06

Stripe's Trusted API Infrastructure Repurposed to Deliver Card-Skimming Code and Store Stolen Data

Allowlists Trust the Domain's Identity, Not the Provenance of What It Carries

Code Provenance Identity & AuthData Provenance
Brief →
See all 15 in Verifiable Origin
Pillar 02

Verifiable AI

7 briefs

The layer that ZK-commits the process of AI judgment.

See all 7 in Verifiable AI
Pillar 03

Agent Authority Proof

11 briefs

The layer that records and proves the delegation relationships of agents.

No. 046 · 2026-06-12

ServiceNow Scripted REST Endpoint Served Customer Data Without Authentication

It is ordinary for a business system to have an "API that returns data." But in June 2026, it was disclosed that some ServiceNow REST endpoi…

Identity & Auth Agent InfrastructureAttribute Proof Bypass
Brief →
No. 037 · 2026-06-09

When the Assistant Becomes the Trigger

AI Coding Agents Auto-Execute Project-Local Config (SymJack / TrustFall + Miasma)

Agent Infrastructure Identity & Auth
Brief →
No. 033 · 2026-06-08

One Edge Appliance Compromise Cascaded to Full Domain Takeover

An Implicitly Trusted F5 BIG-IP Became the Pivot, Along With the Credentials It Stored

Identity & Auth Agent InfrastructureAttribute Proof Bypass
Brief →
No. 031 · 2026-06-08

AI Agents Drove Intrusions From Initial Access to Exfiltration

Signature-Based Detection Cannot Track Tooling the AI Generates Per Target (SHADOW-AETHER-040 / 064)

Agent Runaway Agent InfrastructureIdentity & Auth
Brief →
See all 11 in Agent Authority Proof
Pillar 04

Regulatory Attribute Proof

10 briefs

The layer that proves KYC / AML / regulatory attributes via selective disclosure.

No. 040 · 2026-06-09

Phantom Carbon Credits

When an Environmental Attribute Is Issued Without Independent Verification of Its Underlying Data (Operation Greenwashing)

Attribute Proof Bypass Data Provenance
Brief →
No. 035 · 2026-06-08

The Inspections Were Recorded as 'Complete'

But Never Performed. On the Boeing 787, the Existence of a Record Was Mistaken for Proof of the Act

Attribute Proof Bypass Data ProvenanceIdentity & Auth
Brief →
No. 034 · 2026-06-08

Live Biometric Verification Defeated by an Injected Video Feed

KYC Believed It Had Captured a Live Person, But the Provenance of the Capture Was Never Verified

Attribute Proof Bypass AI Decision IntegrityIdentity & Auth
Brief →
No. 032 · 2026-06-08

Inside a Legitimate Booking Platform, the Payout Bank Account Was Silently Rewritten

The Change Was Not Independently Verified Before Funds Moved (Polaris Holdings / Booking.com)

Attribute Proof Bypass Data ProvenanceIdentity & Auth
Brief →
See all 10 in Regulatory Attribute Proof