Lemma Critical Brief
threat intelligence ×
trust infrastructure.
Lemma's structured analysis of major incidents across AI, cryptographic infrastructure, supply chains, and regulated attributes. Each Brief makes the gap between detection and proof explicit — a reference for risk assessment, regulatory response, and trust-infrastructure design.
Browse by threat typeThreat Types · 12
Most-readPopular
1 AI Agent Forwarded Credentials Before Verifying the Sender (OpenClaw / Varonis) 2 SynthID Watermark, Statistically Stripped 3 Both Sides Cited Cases That Never Existed 4 Noroboto: embedded "lying fonts" made AI's document review read different text 5 GTG-1002: AI agent autonomously executed 80–90% of a cyberattack
All Briefs All — 114
July 2026 25 briefs
116
A fake OpenAI model hit #1 trending on Hugging Face
Model Supply Chain 07-31
115
AI applicant-screening discrimination suit against Workday: the adverse action was taken, but whether the decision was independently verified and authorized was never recorded
AI Bias / Harm 07-31
114
AWS Kiro: a harmless summarize request makes the agent rewrite its own MCP config and reach RCE
Agent Infrastructure 07-31
113
Ruflo's MCP Bridge: one unauthenticated request opened 233 high-privilege tools, and the memory poisoning survives the patch
Agent Infrastructure 07-31
112
Ariana Grande: the unreleased tracks were taken from her collaborators' weakest accounts, not from her
Identity & Auth 07-31
111
Wanchain
Bridge Config Trust 07-28
110
OpenAI's evaluation agents escaped containment and breached an unrelated company's production
Agent Infrastructure 07-28
109
ServiceNow AI Platform
Identity & Auth 07-24
108
AFX Trade
Bridge Config Trust 07-24
107
Verus-Ethereum bridge
Bridge Config Trust 07-24
106
Figma
Training Data Provenance 07-21
105
Over 40,000 unauthorized likeness and voice posts across major platforms
Data Provenance 07-21
104
WebMCP
Agent Infrastructure 07-21
103
Ostium
Data Provenance 07-21
102
Friendly Fire
Code Provenance 07-15
101
Paysafe fake SDKs: 17 packages posing as legitimate payment SDKs exfiltrated developers' secrets, payment API keys and all
Code Provenance 07-10
100
Aptos: a Move VM type confusion could let one on-chain resource be treated as another (reproduced in a ~$3,000 test environment)
Code Provenance 07-10
99
Agentjacking: an AI coding agent trusted a single fake error report as its "resolution steps" and ran the attacker's commands
AI Decision Integrity 07-10
98
BioShocking: convince an AI browser "it's a game" and it drops its guardrails and hands over credentials
AI Decision Integrity 07-07
97
JadePuffer: an LLM agent autonomously ran a ransomware attack
Agent Runaway 07-07
96
Gitea: a Docker default let anyone impersonate an admin with a single HTTP header (CVE-2026-20896)
Identity & Auth 07-07
95
Amazon Q Developer: opening a repo auto-executed a bundled MCP config and exfiltrated AWS credentials (CVE-2026-12957)
Agent Infrastructure 07-03
94
Cursor (DuneSlide): a single injected prompt escaped the agent's sandbox and ran arbitrary commands (CVE-2026-50548 / 50549)
Agent Infrastructure 07-03
93
A7A5: a ruble-backed stablecoin moved $110B under sanctions
KYC / AML Disclosure 07-03
92
exploitarium: An Anonymous 'bikini' Publicly Dropped Many Zero-Day PoCs Found via AI-Automated Fuzzing, and Recipients Can't Verify the Provenance of the Disclosures
Code Provenance 07-01
June 2026 71 briefs
91
Photo ZIP: 'Authentication Laundering' Cleared SPF/DKIM/DMARC So a Fake 'via Calendly' Email Looked Legitimate
Identity & Auth 06-30
90
AIR: A Fake Agent Skill Cleared Every Scanner and Reached ~26,000 Agents
Code Provenance 06-30
89
SecondFi: Audited Signing Code Was Replaced by an Unaudited SDK, Letting Private Keys Be Reconstructed From Public Data on Every Signature
Code Provenance 06-30
88
Kestra: Ending a Request Path With /configs Bypassed Authentication and Allowed Unauthenticated Code Execution as Root
Identity & Auth 06-30
87
Polymarket: Malicious JavaScript Injected via a Compromised Third-Party Vendor Tricked Users Into Approving Fraudulent Transactions
Code Provenance 06-30
86
Sumsub: An 18-Month Undetected Intrusion Into a Support Environment Exposed Customers' Names and Contact Details
KYC / AML Disclosure 06-30
85
Secret Network: Deposits From a Forged Channel Went Unverified, Letting Unbacked Wrapped Tokens Be Minted Without Limit
Bridge Config Trust 06-30
84
Hong Kong deepfake video-call fraud: a real-time deepfake of the CFO and every colleague drove a ~$25.6M transfer
Attribute Proof Bypass 06-26
83
Change Healthcare: a breach of a single Citrix account without MFA halted a third of US medical-claims processing for weeks
Identity & Auth 06-26
82
xz utils backdoor (CVE-2024-3094): a two-year impersonation of a "trusted developer" planted a backdoor in a code-signed official release
Code Provenance 06-26
81
Bybit: a "legitimate" multisig approval signed by trusting the UI drained a supposedly secure Ethereum wallet
Bridge Config Trust 06-26
80
Replit: an AI agent broke a code freeze, wiped production data, then fabricated records to cover it
Agent Runaway 06-23
79
Common Crawl: about 12,000 live credentials embedded in a public corpus used to train LLMs
Training Data Provenance 06-23
78
TennCare Connect: an automated eligibility system illegally cut thousands off Medicaid
AI Decision Integrity 06-23
77
IDMerit: the disputed billion-record KYC exposure
KYC / AML Disclosure 06-23
76
A 93% Facial-Recognition 'Match' Led Straight to Arrest Without Independent Verification (Robert Dillon Wrongful Arrest Suit)
AI Bias / Harm 06-23
75
A Dormant, Un-Revoked Credential Turned a Trusted Integration into Mass Salesforce Extraction (Klue)
Identity & Auth 06-23
74
Taiko Bridge: Forged Withdrawals Passed as Valid After a Prover Signing Key Leaked
Bridge Config Trust 06-23
73
ShadowMQ: one unsafe pattern (unauthenticated ZMQ + pickle) copied across AI inference frameworks
Agent Infrastructure 06-19
72
Hugging Face LeRobot: a robotics framework executed untrusted data received over an unauthenticated channel
Agent Infrastructure 06-19
71
DJI ROMO: one authenticated client reached 7,000 robot vacuums' cameras
Identity & Auth 06-19
70
Unitree (UniPwn): one shared key across the fleet
Identity & Auth 06-19
68
Universal Robots PolyScope: unauthenticated network access yields RCE on industrial robots
Identity & Auth 06-19
67
Syscoin Bridge: an invalid SPV proof was read as "valid" and minted 5B SYS with no burn
Bridge Config Trust 06-19
66
LiteLLM AI Gateway: from low-privilege user to admin and RCE
Identity & Auth 06-19
65
NHO Hokkaido Hospitals: assumed shredded, sold online
Attribute Proof Bypass 06-17
61
Hyundai: driver-assist AI braked on a threat that wasn't there
AI Decision Integrity 06-17
42
Waymo: the robotaxi drove past a stopped school bus
AI Decision Integrity 06-17
64
Salesloft Drift: a trusted integration's OAuth tokens stolen, hundreds of Salesforce tenants queried
Agent Infrastructure 06-16
63
Bright Data SDK: your living-room TV became a relay node for AI-scraping
Data Provenance 06-16
62
Claude Code GitHub Action: one issue claiming "[bot]" led the agent to privileged execution
Agent Infrastructure 06-16
60
Both Sides Cited Cases That Never Existed
AI Decision Integrity 06-16
59
When "Allow All" OAuth to an AI Tool Becomes the Breach Path (Vercel / Context.ai)
Agent Infrastructure 06-16
58
From State Store to RCE
Agent Infrastructure 06-16
57
Reachable Meant Readable
Identity & Auth 06-15
56
No Check on Who Was Authorized
Identity & Auth 06-15
55
Internal Data Exfiltrated Without Verifying the Instruction's Origin
AI Decision Integrity 06-15
54
Generated Until the Rightsholder Said No
Data Provenance 06-13
53
200 Million Views of Fake Celebrities
Data Provenance 06-12
52
70,000 Government IDs Leaked to Prove Age
Attribute Proof Bypass 06-12
51
Asking the AI Support Bot Was Enough
Identity & Auth 06-12
50
Generated Without Consent or Age Verification
Attribute Proof Bypass 06-12
49
Tesla Robotaxi Crash Records
AI Decision Integrity 06-12
48
TrapDoor Plants Hidden Directives in AI Assistant Instruction Files Across npm, PyPI, and Crates.io
Code Provenance 06-12
47
AI Agent Forwarded Credentials Before Verifying the Sender (OpenClaw / Varonis)
AI Decision Integrity 06-12
46
ServiceNow Scripted REST Endpoint Served Customer Data Without Authentication
Identity & Auth 06-12
45
When One Laptop Meets the Multisig Threshold
Bridge Config Trust 06-11
43
Self-Reported Autonomous-Driving Safety, Unverified
AI Decision Integrity 06-09
41
AOG Technics: over 60,000 aircraft engine parts circulated with forged airworthiness certificates
Attribute Proof Bypass 06-09
40
Phantom Carbon Credits
Attribute Proof Bypass 06-09
39
Semantic Kernel: Prompt Injection Turned Into Host-Level Remote Code Execution
Agent Infrastructure 06-09
38
IronWorm
Code Provenance 06-09
37
When the Assistant Becomes the Trigger
Agent Infrastructure 06-09
36
12.8 Billion Training Images Contained Passports, Résumés, and Faces
Training Data Provenance 06-08
35
The Inspections Were Recorded as 'Complete'
Attribute Proof Bypass 06-08
34
Live Biometric Verification Defeated by an Injected Video Feed
Attribute Proof Bypass 06-08
33
One Edge Appliance Compromise Cascaded to Full Domain Takeover
Identity & Auth 06-08
32
Inside a Legitimate Booking Platform, the Payout Bank Account Was Silently Rewritten
Attribute Proof Bypass 06-08
31
AI Agents Drove Intrusions From Initial Access to Exfiltration
Agent Runaway 06-08
30
Stripe's Trusted API Infrastructure Repurposed to Deliver Card-Skimming Code and Store Stolen Data
Code Provenance 06-06
29
One-Click GitHub OAuth Token Theft via github.dev
Agent Infrastructure 06-06
28
The npm Dependency-Confusion Recon Campaign
Code Provenance 06-05
27
LibreChat CVE-2026-32625
Agent Infrastructure 06-05
26
Adaptive AI Worm
Agent Runaway 06-05
25
MCP Design: Config-to-Command Execution and Supply-Chain-Scale RCE
Agent Infrastructure 06-05
24
Invisible Unicode Instruction Injection
AI Decision Integrity 06-05
23
The Alephium TokenBridge Exploit ($815K)
Bridge Config Trust 06-05
22
OnlyFake
Attribute Proof Bypass 06-04
21
Wirecard: forged bank balance confirmations asserted €1.9B that didn't exist
Attribute Proof Bypass 06-03
20
Tampered Certification Test Data Behind Type Designation
Attribute Proof Bypass 06-03
19
Unqualified Engineers Placed Under National-License Claims
Attribute Proof Bypass 06-03
May 2026 18 briefs
18
The hackerbot-claw Campaign's First Recorded AI-vs-AI Attack
AI Decision Integrity 05-31
17
McKinsey Lilli's Writable System Prompts
AI Decision Integrity 05-31
16
The Verus-Ethereum Bridge Hack ($11.58M)
Bridge Config Trust 05-31
15
The GitHub Internal Repository Breach
Code Provenance 05-31
14
The TanStack npm Compromise
Code Provenance 05-31
13
The Coinbase KYC Insider Breach
KYC / AML Disclosure 05-31
12
The Robert Williams Wrongful Arrest
AI Bias / Harm 05-31
11
SynthID Watermark, Statistically Stripped
Data Provenance 05-31
10
Claude Code Source-Leak Lures
Code Provenance 05-31
9
GTG-1002: AI agent autonomously executed 80–90% of a cyberattack
Agent Runaway 05-31
8
Discord 2.05 Billion Message Scraping via Public API
Training Data Provenance 05-30
7
Cursor + Claude Opus 4.6 Wiped PocketOS Production DB in 9 Seconds
Agent Runaway 05-30
6
Google API Keys Remain Usable for 23 Minutes After Deletion
Attribute Proof Bypass 05-30
5
Noroboto: embedded "lying fonts" made AI's document review read different text
AI Decision Integrity 05-30
4
Megalodon GitHub Supply Chain
Code Provenance 05-30
3
Starlette CVE-2026-48710 (BadHost)
Agent Infrastructure 05-30
2
Stake DAO vsdCRV Unauthorized Mint
Bridge Config Trust 05-29
1
KelpDAO / rsETH Unauthorized Unlock
Bridge Config Trust 05-29
No Briefs matched your filters.