SecureFlow Case Index
Each case below is a source-backed AI attack flow, mapped step by step to AIDEFEND defensive techniques. Open a case for its summary and threat references, or jump straight into the interactive viewer.
123 published attack flows
AIDEFEND Research flows
- aidefend-sf0000Prompt Injection to Agent Tool Abuse
- aidefend-sf0001Agentjacking via Sentry MCP Telemetry Injection
- aidefend-sf0002SearchLeak: One-Click Data Exfiltration via Microsoft 365 Copilot
- aidefend-sf0003Cowork Exfil: Poisoned-Skill File Exfiltration via Microsoft 365 Copilot Cowork
- aidefend-sf0004Prompt-to-Shell: Dual RCE Paths in Microsoft Semantic Kernel
- aidefend-sf0005Copirate 365: Persistent Memory-Backdoor Data Exfiltration in Microsoft 365 Copilot (CVE-2026-24299)
- aidefend-sf0006Bring Your Own Agent: Exposed LLM Backends as Attacker AI Compute
- aidefend-sf0007LiteLLM Guardrail Tester Sandbox Escape to Root RCE
- aidefend-sf0008LiteLLM Connection-Test Key Exfiltration via Nested api_base
- aidefend-sf0009JADEPUFFER Agentic Ransomware via Langflow RCE
- aidefend-sf0010DifyTap Cross-Tenant AI Data Exposure
- aidefend-sf0011Amazon Q MCP Auto-Execution to Cloud Credential Theft
- aidefend-sf0012PerplexedBrowser: Comet Agent Hijack Against 1Password
- aidefend-sf0013Clean Repository to DNS-Fetched Reverse Shell in an AI Coding Agent
- aidefend-sf0014AutoJack Localhost Agent Control-Plane RCE
- aidefend-sf0015ChainLeak: Chainlit File Read and SSRF to Cloud Exposure
- aidefend-sf0016LangGraph Checkpointer SQLi and Deserialization RCE
- aidefend-sf0017PerplexedBrowser: Comet Local File Exfiltration
- aidefend-sf0018Salesforce Einstein Prompt Mines to CRM Data Corruption
- aidefend-sf0019AgentFlayer: ChatGPT Connectors Zero-Click Data Exfiltration
- aidefend-sf0020Moltbook Agent Network Callback Map
- aidefend-sf0021OpenAI Atlas Omnibox Prompt Injection
- aidefend-sf0022NVIDIA Triton Python Backend Unauthenticated RCE Chain
- aidefend-sf0023Ollama Windows Auto-Update Persistent RCE
- aidefend-sf0024Notion AI Agent Indirect Prompt Injection and Data Exfiltration
- aidefend-sf0025AgentForger ChatGPT Workspace Agent Forgery and Autonomous Insider
- aidefend-sf0026OpenAI Evaluation Agent Intrusion into Hugging Face Production
- aidefend-sf0027Stolen Thoughts Reasoning-Trace Extraction
- aidefend-sf0028Flowise CSV Agent Prompt Injection to Host-Capable Pyodide
- aidefend-sf0029MLflow Unauthenticated Webhook Redirect to Full-Read SSRF
- aidefend-sf0030Ray Browser DNS Rebinding to Unauthenticated Jobs API RCE
- aidefend-sf0031Miasma Repository Settings Trigger Credential Harvester
- aidefend-sf0032Typosquatted Agent Skills: Reputation Inflation, Rug Pull, and Credential Theft
- aidefend-sf0033Copilot for Word Hidden-Prompt Document Worm
- aidefend-sf0034DuneSlide: Two Cursor Sandbox Escapes to Unsandboxed RCE
- aidefend-sf0035Computer-Use TOCTOU: The Screen Observed Is Not the Screen Clicked
- aidefend-sf0036Rogue Agent: One Dialogflow Permission Compromised a Shared Project Runtime
- aidefend-sf0037RovoBlast: rovoChatPrompt One-Click Data Exfiltration
- aidefend-sf0038Atlassian Rovo Document Prompt Injection and URL Exfiltration
- aidefend-sf0039CoSnitch: Copilot Web Autorun Data Exfiltration
- aidefend-sf0040CoSnitch: Copilot Web Persistent Memory Poisoning
- aidefend-sf0041Spyder: Sider Cross-Origin Synthetic-Gesture Attack
- aidefend-sf0042MaXSS: MaxAI Generic Background API Bridge to UXSS
- aidefend-sf0043CVE-2026-66384 Artifactory Container-Image Cache Poisoning
- aidefend-sf0044Artifactory RubyGem Deserialization to Signing-Key Theft and Admin JWT
- aidefend-sf0045OpenAI Research Cluster Compromise Through Parallel Kernel and Credential Paths
- aidefend-sf0046Cryptographic Context Injection in AI Web Research
- aidefend-sf0047GitSpawn: Malicious Git Configuration Before Coding-Agent Trust
- aidefend-sf0048Claude-Site Scripting: Email-Borne Browser Session Abuse
- aidefend-sf0049SkillJack: Poisoned Experience Trajectories Become Persistent Agent Skills
MITRE ATLAS case studies
- mitre-atlas-cs0000Evasion of Deep Learning Detector for Malware C&C Traffic
- mitre-atlas-cs0001Botnet Domain Generation Algorithm (DGA) Detection Evasion
- mitre-atlas-cs0002VirusTotal Poisoning
- mitre-atlas-cs0003Bypassing Cylance's AI Malware Detection
- mitre-atlas-cs0004Camera Hijack Attack on Facial Recognition System
- mitre-atlas-cs0005Attack on Machine Translation Services
- mitre-atlas-cs0006ClearviewAI Misconfiguration
- mitre-atlas-cs0007GPT-2 Model Replication
- mitre-atlas-cs0008ProofPoint Evasion
- mitre-atlas-cs0009Tay Poisoning
- mitre-atlas-cs0010Microsoft Azure Service Disruption
- mitre-atlas-cs0011Microsoft Edge AI Evasion
- mitre-atlas-cs0012Face Identification System Evasion via Physical Countermeasures
- mitre-atlas-cs0013Backdoor Attack on Deep Learning Models in Mobile Apps
- mitre-atlas-cs0014Confusing Antimalware Neural Networks
- mitre-atlas-cs0015Compromised PyTorch Dependency Chain
- mitre-atlas-cs0016Achieving Code Execution in MathGPT via Prompt Injection
- mitre-atlas-cs0017Bypassing ID.me Identity Verification
- mitre-atlas-cs0018Arbitrary Code Execution with Google Colab
- mitre-atlas-cs0019PoisonGPT
- mitre-atlas-cs0020Indirect Prompt Injection Threats: Bing Chat Data Pirate
- mitre-atlas-cs0021ChatGPT Conversation Exfiltration
- mitre-atlas-cs0022ChatGPT Package Hallucination
- mitre-atlas-cs0023ShadowRay: Hijacking Exposed Ray Clusters
- mitre-atlas-cs0024Morris II Worm: RAG-Based Attack
- mitre-atlas-cs0025Web-Scale Data Poisoning: Split-View Attack
- mitre-atlas-cs0026Financial Transaction Hijacking with M365 Copilot as an Insider
- mitre-atlas-cs0027Organization Confusion on Hugging Face
- mitre-atlas-cs0028AI Model Tampering via Supply Chain Attack
- mitre-atlas-cs0029Google Bard Conversation Exfiltration
- mitre-atlas-cs0030LLM Jacking
- mitre-atlas-cs0031Malicious Models on Hugging Face
- mitre-atlas-cs0032Attempted Evasion of ML Phishing Webpage Detection System
- mitre-atlas-cs0033Live Deepfake Image Injection to Evade Mobile KYC Verification
- mitre-atlas-cs0034ProKYC: Deepfake Tool for Account Fraud Attacks
- mitre-atlas-cs0035Data Exfiltration from Slack AI via Indirect Prompt Injection
- mitre-atlas-cs0036AIKatz: Attacking LLM Desktop Applications
- mitre-atlas-cs0037Data Exfiltration via Agent Tools in Copilot Studio
- mitre-atlas-cs0038Planting Instructions for Delayed Automatic AI Agent Tool Invocation
- mitre-atlas-cs0039Living Off AI: Prompt Injection via Jira Service Management
- mitre-atlas-cs0040Hacking ChatGPT's Memories with Prompt Injection
- mitre-atlas-cs0041Rules File Backdoor: Supply Chain Attack on AI Coding Assistants
- mitre-atlas-cs0042SesameOp: Novel backdoor uses OpenAI Assistants API for command and control
- mitre-atlas-cs0043Malware Prototype with Embedded Prompt Injection
- mitre-atlas-cs0044LAMEHUG: Malware Leveraging Dynamic AI-Generated Commands
- mitre-atlas-cs0045Data Exfiltration via an MCP Server used by Cursor
- mitre-atlas-cs0046Data Destruction via Indirect Prompt Injection Targeting Claude Computer-Use
- mitre-atlas-cs0047Code to Deploy Destructive AI Agent Discovered in Amazon Q VS Code Extension
- mitre-atlas-cs0048Exposed ClawdBot Control Interfaces Leads to Credential Access and Execution
- mitre-atlas-cs0049Supply Chain Compromise via Poisoned ClawdBot Skill
- mitre-atlas-cs0050OpenClaw 1-Click Remote Code Execution
- mitre-atlas-cs0051OpenClaw Command & Control via Prompt Injection
- mitre-atlas-cs0052LLMSmith: RCE Vulnerabilities in LLM-Integrated Applications
- mitre-atlas-cs0053Poisoned Postmark MCP Server Email Exfiltration
- mitre-atlas-cs0054Data Exfiltration via Remote Poisoned MCP Tool
- mitre-atlas-cs0055AI ClickFix: Hijacking Computer-Use Agents Using ClickFix
- mitre-atlas-cs0056Model Distillation Campaigns Targeting Anthropic Claude
- mitre-atlas-cs0057Storm-2139 Azure OpenAI Guardrail Bypass
- mitre-atlas-cs0058Google Photos AI Model Extraction
- mitre-atlas-cs0059EchoLeak: Zero-Click Prompt Injection Targeting M365 Copilot for Data Exfiltration
- mitre-atlas-cs0060Cross-Site Scripting via Prompt Manipulation in Lenovo AI Chatbot
- mitre-atlas-cs0061AI in the Middle: Web-Based AI Services as C2 Relays
- mitre-atlas-cs0062RCE Vulnerability in Semantic Kernel Search Plugin
- mitre-atlas-cs0063Prompt-Based Attacks Against Gemini via Calendar Invitations
- mitre-atlas-cs0064Poisoned GGUF Templates: Inference-Time Supply Chain Attack
- mitre-atlas-cs0065Model Namespace Reuse Supply Chain Attack
- mitre-atlas-cs0066ZombieAgent: Data Exfiltration Attack on ChatGPT
- mitre-atlas-cs0067Claude Code GitHub Action Secret Exposure
- mitre-atlas-cs0068Autonomous OpenAI Evaluation Agents Compromise Hugging Face Infrastructure
- mitre-atlas-cs0069GTG-1002 Claude Code Espionage Campaign
- mitre-atlas-cs0070Threat Actor Uses a DeepSeek-Powered Hermes Agent in Langflow and n8n Exploitation Attempts
- mitre-atlas-cs0071Multi-Agent Framework Compromises Taiwanese Government Systems
- mitre-atlas-cs0072AI Recommendation Poisoning via Crafted AI Assistant Links