Real-world security incidents in which an autonomous agent or agent fleet, not a human driving a tool, took the consequential actions. Every row carries the timeline, the class-level vulnerability chain, how it surfaced, and how firmly it is confirmed. Browse it below, or take the raw files.
Snapshot
2026-09-06
Coverage
11incidents·7confirmed·3with detection lag·28dmedian detection lag
Download
About this dataset
[showhide]
Unit
One row = one incident: the operator, the model or fleet that acted, the task and reward signal that set it off, the environment it left, the vulnerability-class chain and coordination methods, what it hit, how it was caught, and the documents behind it. Agent-assisted human intrusions and red-team-only scenarios are out of scope.
Ordering
Rows run newest first by first-activity date. Incidents whose earliest activity no source dates precisely sit at the end rather than carrying a guessed date.
Confirmation
Confirmed means acknowledged by the operator or the affected party; reported means documented by a credible third party; inferred means independently reconstructed from indirect evidence.
Detection lag
Days from first activity to detection, and from detection to disclosure, are recorded only where both endpoints are published. Nulls are honest gaps, not zeros, so the median in the strip covers the dated rows only.
Cross-references
Vulnerability chains and coordination methods are class labels that resolve to the sibling catalogues in this cluster, including emergent coordination and dead-drop substrates.
Sources
Each row is verified against the operator’s or victim’s own disclosure where one exists, with independent investigations and advisories listed as primary sources. URLs travel with the dataset.
License
Free to use, distribute, and reproduce with attribution to Hermosa Labs LLC (CC BY 4.0).