โ† Real-world cases

CISA/NSA/FBI warn of AI-generated exploit scripts targeting Siemens S7 PLCs (AA26-231A)

Framework / advisory19 Aug 2026

Reported as the first government-confirmed in-the-wild use of AI code-generation to build offensive tooling against operational-technology/ICS (python-snap7 over S7comm), extending offensive-AI risk from software and espionage into physical-safety and critical-infrastructure territory. Scope and attribution are per the CISA advisory.

More cases on Tool Misuse

GTG-1002 โ€” first reported AI-orchestrated cyber-espionage campaign (Claude Code)ForcedLeak โ€” Salesforce Agentforce CRM exfiltration (CVSS 9.4, no CVE)ServiceNow Now Assist โ€” second-order prompt injection via agent-to-agent discoveryIDEsaster โ€” AI coding IDEs/agents turned into exfiltration & RCE surfacesAmazon Q Developer 'wiper' prompt shipped via poisoned pull request (CVE-2025-8217)SesameOp: backdoor abuses the OpenAI Assistants API as covert command-and-controlAnamorpher โ€” image-scaling prompt injection against production AI systemsMCPTox: tool-poisoning benchmark over real-world MCP serversAgentjacking โ€” hijacking AI coding agents via Sentry error reports (Tenet Security)Meta AI support bot tricked into hijacking Instagram accountsAI-assisted breach of Mexican government infrastructure (Claude Code + GPT-4.1)Grok + Bankrbot Morse-code prompt injection drains on-chain walletClaudeBleed โ€” co-resident Chrome extensions coerce Claude for Chrome into reading Gmail/Docs/CalendarHermes AI agent run unattended ('YOLO' mode) to automate post-exploitation at Thailand's Ministry of FinanceJADEPUFFER โ€” first documented end-to-end autonomous agentic ransomware operation (Sysdig)Zscaler ThreatLabz โ€” web indirect prompt injection targeting AI agents in the wildAgentic botnets via universal, transferable adversarial HalluSquattingMOSAIC: CLI command-composition attacks on LLM coding agentsAur0ra ransomware crew reportedly used the Cursor AI coding agent to hack seven firmsLLM Heist: hijacking a LiteLLM gateway for traffic interception, key theft and forged tool-calls

AI RiskAtlas is an educational model of how GenAI & agentic systems work and fail. Architectures and payloads are illustrative and simplified for learning โ€” not operational guidance. Real-world cases are summarised from public reporting.

Sources & further reading โ†’ยทBuilt by Shi Yuan โ†—