38 Companies Breached. 331M+ Records Stolen.

· RuntimeAI ·

17 min read Original article ↗

📊 Monthly Breach Intelligence Report

38 Companies Breached. 331M+ Records Stolen.
CrowdStrike. Okta. Palo Alto Networks. Microsoft Defender. All running. None of them stopped these breaches and threats.
→ See exactly how RuntimeAI would have stopped every one of these breaches Full Capability Stack ↓

Roshan Shaik, Founder & CEO September 1, 2026 123 incidents · 41 min read

In this briefing: Monthly Summary · What's New at RuntimeAI · Capability Spotlight · Full 123-Incident Catalog · Full Capability Stack

ATSA — AI Threat Simulation Agent

“125 attacks fired this morning. Here's exactly which ones your stack actually stopped.”

Why It Matters

This month's ShinyHunters credential campaign and the rise of AI-agent exploits (37 of August's 123 incidents — the single largest category) share the same root problem: most security teams have never actually fired a real attack at their own stack to see if it holds. “Our guardrails should catch that” is a guess until someone tests it.

How RuntimeAI Helps

ATSA is RuntimeAI's built-in red-team engine — 125 attack scenarios across 9 attack-surface domains (memory, identity, supply chain, communication, reasoning, action, context, output, observability), 70 of them modeled directly on real, dated AI-security incidents, not invented threat models. It runs against your current stack as-is — whatever combination of guardrails and gateways you already have, RuntimeAI or not — and returns a real risk score before and after, with the exact fix for anything that fails, in under 60 minutes.

Illustrative Scenario

A team assumed their MCP gateway would block a malicious tool registration. Running ATSA's supply-chain domain scenario against their real deployed stack, a simulated MCP tool-poisoning attempt fired — and the pre-action policy check actually held. Their first real evidence it worked, not an assumption. (Illustrative, not a specific customer engagement.)

Kill Switch

“AI agents were the single largest attack-vector category this month. If one goes rogue, how fast can you actually stop it?”

Why It Matters

37 of August's 123 incidents involved an AI agent as the weapon or the vehicle — more than classic credential theft, more than any other category. A rogue or compromised agent doesn't wait for a human to notice; it keeps acting until something stops it.

How RuntimeAI Helps

The Kill Switch operates at three graduated levels — a single agent, an entire tenant, or the whole platform (2FA-gated) — propagating in under 50ms via NATS JetStream. It captures forensic state (the agent's last 100 actions) before quarantining, so you get both an instant stop and the evidence to understand what actually happened.

Illustrative Scenario

An agent's behavior drifts outside its normal pattern — reaching for resources it's never touched before. The Kill Switch fires at the tenant level in under 50ms, freezing every agent under that identity while the forensic snapshot preserves exactly what each one was doing at the moment of the halt. (Illustrative, not a specific customer engagement.)

123 Incidents — August 2026

Click any incident to see the full analysis and RuntimeAI gap fix below. Left border colour = severity: ■ Critical  ■ High  ■ Medium

Incidents 1–41

2

Aurora Ransomware Operators Use Cursor AI in…

Aug 31

10

Extortion Group Claims Manchester Airports G…

Aug 31

12

Berlin Won’t Pay Extortion Group Claiming Da…

Aug 31

14

Berlin confirms data theft after Rhysida ran…

Aug 31

23

Claude Opus 4.6 Bypasses Gym Booking Limit, …

Aug 28

24

NVIDIA NemoClaw LLM Poisoning

Aug 28

26

Cryptographic Context Injection Attack Steal…

Aug 28

27

Iran-Linked Cyberattack Shuts UK Power Gener…

Aug 28

29

Hackers Target Over 100 US Water Systems in …

Aug 28

30

Carhartt Data Breach Exposes 12.9 Million Cu…

13M+Aug 28

31

ASOS Account Takeover Attack Exposes 138,828…

139K+Aug 28

32

TeamPCP Supply Chain Attacks

Aug 28

33

FBI Seizes Domains Behind China-Linked Hacki…

Aug 28

35

China-Made ZBT Routers Ship With Two Implant…

Aug 28CVE-2026-74232+1

36

PaperCut Zero-Day Exploited in Attacks, Affe…

Aug 28

39

You Need Cyber Deception for OT

Aug 28

40

Defining an AI Kill Switch Is Hard, but Nece…

Aug 28

Incidents 42–82

45

GoCaracal Malware Uses Ethereum Smart Contra…

Aug 27

46

Agentic AI Risks, CVE Program Concerns Perme…

Aug 27

53

Marimo Notebook Flaw Could Run MCP Commands …

Aug 25

56

Is Cyber Facing an Affordability Crisis?

Aug 25

58

Tricky 'SynkLoader' Multitool May Herald Ran…

Aug 24

61

Claude Code Weaponized to Screen 100,000+ Ph…

Aug 21

62

AI “Mind Viruses” Spread Between Agent Proce…

Aug 21

63

Claude Agents in Autonomous “Turf War” Indep…

Aug 21

65

MCP Servers Expose Complete Enterprise Secre…

Aug 21

66

n8n AI Workflow Automation Platform Contains…

Aug 21RCE

68

Cryptographic Context Injection Attack Lets …

Aug 21

72

Remote Spectre Side-Channel Attack Leaks JWT…

Aug 21

75

AWS Bedrock Adds Agent Permission Guardrails…

Aug 21

78

Pakistan's Transparent Tribe Refreshes Tools…

Aug 20

79

SilkParasite Threatens Central Asian Orgs Wi…

Aug 19

82

The 'Industrial Accidents' Behind Rogue AI A…

Aug 18

Incidents 83–123

88

Malicious MCP Servers Split Instructions Acr…

Aug 14

89

Atlassian Rovo Can Be Manipulated Into Sendi…

Aug 14

90

Researchers Combined AI Assistance With a Sh…

Aug 14RCE

91

Cybercriminals Have Adopted Indirect Prompt …

Aug 14

106

Claude Mythos 5 Tried to Backdoor a Real OSS…

Aug 07

108

Keyv-Linked npm Worm Poisoned Hundreds of Pa…

Aug 07

110

Veeam, Terraform MCP and Django Patch Critic…

Aug 07

111

Zero-Click AI Browser Hijack

Aug 07

112

AI Recommendation Poisoning

Aug 07

114

Chinese APT Weaponized DeepSeek Agent to Att…

Aug 07

118

Humans Missed 1 in 3 Threats While Approving…

Aug 07

120

Brown Health Medical Group Breach Exposes 31…

311K+Aug 07

122

InterConSecurity

276K+Aug 05

CVE & RCE

CVEs (2)

CVE-2026-74232China-Made ZBT Routers Ship Wi…

CVE-2026-74233China-Made ZBT Routers Ship Wi…

RCE (5)

RCEThreatsDayAug 27

RCEn8n AI Workflow Automation Pla…Aug 21

RCEResearchers Combined AI Assist…Aug 14

RCECISAAug 14

RCEnginxAug 14

Stack & Vendors

Vendors (2) — click to see breach

CrowdStrikeEDR

3×CrowdStrike, Microsoft +1

CloudflareCDN

1×Remote Spectre Side-Chan…

Perimeter Categories

EDR 3CDN 1

The Pattern

This month’s incidents demonstrate a consistent pattern across all sectors: AI is now both the attack vector and the target. Enterprises with mature security stacks were breached through gaps those stacks were never designed to cover.

The 123 incidents collected this month span 38 named organizations, 331M+ records exposed, and 2 distinct security vendors present at time of breach. The pattern is not one of vendor failure — it is one of category gap.

What Would Have Stopped This — Full Capability Stack

Not “better security.” Nineteen specific capabilities across three platforms. Each addresses a gap that no vendor in this month’s breach stacks was built to cover — because AI agents didn’t exist when those vendors were designed.

RuntimeAI — AI Governance & Control Plane Enterprise AI agent governance — identity, policy, firewall, detection, response, compliance.

🔍

Shadow AI Visibility

AI Discovery

12

incidents this month · 10%

“You can’t govern what you can’t see.”

Continuously scans cloud, IDE, endpoint, and network to inventory every AI agent — registered or rogue. Classifies and risk-scores shadow AI automatically. One-click to import into governance.

⚠️ The gap it fills Wiz and Orca scan cloud misconfiguration. They don’t discover AI agents installed by developers or injected via compromised vendors. Your unknown agents are your biggest risk.

  • Cloud scanner (AWS/Azure/GCP Lambda, Bedrock, SageMaker)
  • IDE scanner (VS Code, Cursor, MCP servers)
  • Endpoint scanner on developer laptops
  • Shadow AI Inbox with auto-severity classification
  • One-click shadow AI → governed agent pipeline

🧽

AI Agent PKI

Agent Identity Fabric

49

incidents this month · 40%

“No credential. No access. No breach.”

Provisions every AI agent with a SPIFFE/X.509 cryptographic identity. Short-lived certs, auto-rotating. TPM 2.0 hardware attestation. Agent DNS blocks unknown agents at the network layer.

⚠️ The gap it fills Legacy identity providers were built for human identity. They have no concept of non-human agents operating at machine speed with no user present to respond to an MFA prompt.

  • SPIFFE X.509 SVID with RSA-2048, auto-rotating
  • TPM 2.0 hardware attestation + PCR drift detection
  • Zero-touch bootstrap for new agents
  • Agent DNS: NXDOMAIN for unknown agents
  • Blueprint-based permission inheritance

⚙️

Policy Engine

AI Control Plane

65

incidents this month · 53%

“Stop it before it executes. Not after.”

OPA/Rego policy engine with sub-1ms evaluation and fail-closed enforcement. Natural language to Rego compiler. Merkle-chain audit proves policies were never tampered with.

⚠️ The gap it fills Traditional SIEMs alert on what already happened — 73 days after the breach in the average case. The AI Control Plane enforces policy before the action executes, not after the damage is done.

  • OPA/Rego engine, sub-1ms, fail-closed
  • NL-to-Rego compiler: write policy in plain English
  • Merkle-chain tamper-evident audit trail
  • Multi-tenant RBAC + Separation of Duties
  • Cross-site policy cascade for distributed fleets

🔥

Bidirectional DLP

AI Firewall

104

incidents this month · 85%

“Inspect every token in, every token out.”

Bidirectional DLP scanning at <5ms latency. Prompt injection detected and stripped on input. PII, PHI, credentials caught on output. Behavioral risk score (0–100) triggers auto-suspend.

⚠️ The gap it fills Traditional NGFWs and CASBs see LLM traffic as an encrypted blob. They cannot inspect prompts, detect injection inside a conversation, or catch data leaking in an AI response.

  • Bidirectional DLP: input (prompt injection) + output (data leakage)
  • ML behavioral baselines per agent with adaptive thresholds
  • Risk score 0–100 triggers auto-suspend or rate-limit
  • No-code guardrail builder for business users
  • Data Proxy: field-level masking before agent sees data

🔗

MCP Gateway

AI Integration Fabric

79

incidents this month · 64%

“Every tool call. Governed.”

Multi-tenant governed gateway for all agent-to-tool communication. 500+ pre-built integrations. 3-level kill switch (agent / tool / platform-wide) propagating in <50ms. OWASP MCP03 sanitization on every call.

⚠️ The gap it fills No existing vendor governs at the MCP protocol layer. Raw MCP deployments have zero security, zero multi-tenancy, and zero audit trail. This is the fastest-growing unguarded attack surface in enterprise AI.

  • 3-level kill switch: per-agent, per-tool, platform-wide — all <50ms
  • 500+ pre-built integrations with auto-discovery
  • BYOM overlay: wrap existing MCPs without code changes
  • Circuit breaker + health monitoring per connection
  • Full OWASP MCP03 input/output sanitization + DLP

🧠

Anomaly Detection

Agent Behavioral Intel

66

incidents this month · 54%

“Catch drift before it becomes a breach.”

30-day rolling behavioral baselines per agent across frequency, pattern, volume, and temporal dimensions. LSTM sequence modeler detects multi-step attack chains. HRIS integration auto-suspends agents when their owner is terminated.

⚠️ The gap it fills Signature-based EDR detects known malware signatures for human endpoints. It has no baseline for an AI agent that begins exfiltrating data through an API it was legitimately authorized to call.

  • Rolling 30-day baseline: frequency, pattern, volume, temporal
  • LSTM sequence modeler for multi-step attack patterns
  • Composite risk score from 6 signals
  • HRIS integration: auto-suspend on employee termination (<30s)
  • Adaptive OPA thresholds by agent role + risk profile

🔴

Emergency Response

Kill Switch

6

incidents this month · 5%

“Stop any AI agent, anywhere, in under 50ms.”

Three graduated kill levels: per-agent, per-tool, platform-wide. All propagate via NATS JetStream in <50ms. Captures last 100 actions as forensic state. Quarantine mode preserves evidence for investigation.

⚠️ The gap it fills No competitor offers this. When an AI agent goes rogue — or when a breach is detected — you need a hard stop. Every second it keeps running is more data exfiltrated, more damage compounding.

  • L1/L2/L3 kill: per-agent, per-tool, platform — all <50ms via NATS
  • Forensic state capture: last 100 actions, memory snapshot, credentials
  • Quarantine mode: isolate for investigation, preserve evidence
  • Escalation chains: auto-response → SOC alert → human required → kill
  • Reprieve mechanism: 24-hour lease for controlled investigation post-kill

🚨

Incident Response

AI Respond

Universal

covers all incidents — audit + governance layer

“Autonomous incident response. AI-native.”

Five-phase automated playbook: DETECT → QUARANTINE → INVESTIGATE → REMEDIATE → VERIFY. Auto-classifies incidents (true positive / false positive / inconclusive). Blast radius containment automatically quarantines agents that interacted with compromised agent.

⚠️ The gap it fills Traditional SOAR platforms orchestrate conventional security events. They cannot terminate an AI agent, rotate its credentials, update its behavioral model, or quarantine the agents it spoke with — because they were built before AI agents existed.

  • 5-phase automated playbook from detection to verification
  • Auto-classification against 200+ known AI attack patterns
  • Blast radius containment: quarantine all interacting agents
  • True positive: terminate + revoke + rotate + update models
  • False positive feedback loop continuously improves detection

👥

Agent Lifecycle

AI Ops Center

Universal

covers all incidents — audit + governance layer

“Mission control for autonomous AI operations.”

65+ page operational dashboard. Access review campaigns. ‘The Reaper’ auto-decommissions agents when their human owner is terminated. Vault Broker injects credentials with 5-minute TTL — never stored in agent memory.

⚠️ The gap it fills ServiceNow manages human IT requests on ticket-based cycles. AI agents are deployed, modified, and compromised in minutes. You need lifecycle governance that operates at agent speed, not ticket speed.

  • Access review campaigns with auto-apply decisions
  • ‘The Reaper’: HRIS webhook auto-revokes terminated employees’ agents (<30s)
  • Vault Broker: just-in-time 5-min TTL credential injection, never persisted
  • Per-tenant budget caps with 4-tier alerts (50/75/90/100%)
  • Unified health, credential lifecycle, budget, SLA dashboard

🌐

Universal

covers all incidents — audit + governance layer

“Route every LLM call to the right model, at the right cost, with automatic failover.”

Unified API routing LLM requests to the optimal provider based on cost, latency, and compliance. Semantic caching reduces redundant calls 15–30%. Automatic failover in <50ms. Budget enforcement with hard limits.

⚠️ The gap it fills Portkey does basic routing at $30K/year. It has no DLP scanning, no compliance-based routing (data residency), no semantic caching, and no budget enforcement. It routes traffic — it doesn’t govern it.

  • Multi-provider routing: OpenAI, Anthropic, Bedrock, Azure, GCP, custom
  • Cost/latency/compliance-based routing policies
  • Automatic failover <50ms; per-provider circuit breaker
  • Semantic caching: 0.80–0.95 similarity threshold, 15–30% cache hits
  • Budget enforcement per-agent + cost anomaly detection

🤖

23

incidents this month · 19%

“Model registry, feature store, edge inference — one platform.”

Formal model lifecycle (draft/staging/production/archived). Feature Store with online (<5ms) and offline serving. Hybrid scoring engine routes inference between edge (<1ms quantized) and cloud. Drift-triggered auto-retraining.

⚠️ The gap it fills MLflow + Feast + custom inference each solve one piece. ML Intelligence Hub is the piece nobody built: unified lifecycle + edge inference routing + drift-triggered retraining + 7-dimension cost attribution — all integrated.

  • Model Registry: versioning, rollback, lineage, lifecycle management
  • Hybrid Scoring: edge <1ms quantized vs cloud full-precision auto-routing
  • Feature Store: online <5ms + offline point-in-time with freshness monitoring
  • Drift Engine integration: auto-retraining on data/concept drift
  • 7-dimension cost attribution: agent/model/team/customer/feature/time/provider

💰

FinOps

AI Cost Intelligence

Universal

covers all incidents — audit + governance layer

“A cost spike is a security signal. Treat it like one.”

7-dimension real-time cost attribution: agent, provider, model, team, customer, feature, time. Wasm token counter in-proxy at 50–100 microseconds. Budget hard limits stop agents before they overspend. Runaway agent detection.

⚠️ The gap it fills Kubecost knows GPU-hours. AI Cost Intelligence knows “Agent-47 spent $142 on Claude Sonnet for fraud detection on Tuesday.” Runaway cost is runaway behavior — and only one product treats them as the same signal.

  • Wasm token counter in proxy: 50–100 microsecond overhead
  • Live model pricing catalog: 200+ models, 15+ providers, updated every 15min
  • Budget hard limits: block requests when agent exhausts budget
  • Cost anomaly detection: ML-based spending spike alerts
  • Chargeback engine: per-customer invoices + per-team internal allocation

📋

Continuous Compliance

AI Compliance Hub

123

incidents this month · 100%

“Audit evidence as a byproduct of governance.”

Continuous compliance across 13+ frameworks — SOC 2, FedRAMP, ISO 27001/42001, EU AI Act, HIPAA, PCI-DSS, NIST AI RMF. Evidence auto-generated from RuntimeAI telemetry. Open Audit Marketplace connects enterprises with certified audit firms.

⚠️ The gap it fills Vanta collects attestations from cloud infrastructure. It has no understanding of AI agent behavior, no EU AI Act or ISO 42001 mappings, and no way to generate evidence from an AI governance layer — because none of its customers had one.

  • 13+ frameworks: SOC 2, FedRAMP, ISO 27001/42001, EU AI Act, HIPAA, PCI-DSS, NIST AI RMF
  • Evidence auto-generated from platform telemetry (audit trails, Merkle chain, access reviews)
  • Gap tracking with SLA-based remediation assignment
  • Audit Marketplace: open to any qualified audit firm; time-limited scoped access
  • Blockchain-anchored compliance certificates with tamper-evidence verification

🏪

Agent Procurement

Agent Marketplace

12

incidents this month · 10%

“Only certified agents enter your environment.”

Three-sided platform: Builders publish, Enterprises deploy, Trust layer certifies. AAIC certification includes third-party behavioral audit. Risk scoring weights permission scope, data access, integration breadth, update frequency, and builder reputation.

⚠️ The gap it fills Your developers are installing AI agents from GitHub, npm, and PyPI with no security review. The AI agent supply chain attack surface is the same as software supply chain — and it’s moving five times faster.

  • 6-step publishing wizard with compliance gating
  • AAIC certification: third-party behavioral audit by registered firms
  • Risk scoring: permission scope (30%), data access (25%), integration (20%), frequency (10%), reputation (10%)
  • Shadow AI Import: discover unmanaged agents and bring into governance
  • Stripe Connect billing: free/per-seat/per-action/outcome-based; 20% platform fee

Agentic Enablement Platform (AEP) Agentic-era security primitives — NHI identity, fraud detection, memory governance, agent commerce.

🔑

Non-Human Identity

NHI Security Platform

40

incidents this month · 33%

“Every non-human identity — issued, governed, and revoked with the same rigor as human identity.”

Centralized governance for every non-human identity: service accounts, API keys, OAuth tokens, machine certs, cloud IAM roles, AI agents. Bot-CA issues short-lived X.509 SPIFFE certs. O(1) hash-based revocation — not cascading policy lookups.

⚠️ The gap it fills Oasis Security ($190K/year) solves NHI credentialing but not for AI agents specifically. It lacks TPM hardware attestation, has no AI-agent behavioral monitoring, and doesn’t integrate with agent governance platforms.

  • Centralized NHI Registry: auto-discovery across AWS/Azure/GCP/on-prem
  • Credential posture: rotation schedules, expiry, over-privilege, unused credential detection
  • NHI Drift Detection: per-NHI behavioral baseline + scope creep detection
  • Bot-CA: short-lived X.509 certs (1–24hr TTL), auto-rotating, instant OCSP revocation
  • O(1) hash-based revocation: per-NHI, per-tenant, or global — no cascading policy lookup

🛡️

AI Fraud Detection

Fraud Shields

37

incidents this month · 30%

“Valid credential. Wrong behavior. Caught.”

Two-layer defense: Identity Fraud Shield models valid-credential-wrong-behavior (the hallmark of compromised AI credentials). Activity Fraud Shield detects multi-step attack sequences within authenticated sessions. Both integrate directly with Kill Switch for automatic response.

⚠️ The gap it fills Generic UEBA tools applied to AI agents generate massive false-positive rates because they were trained on human behavior. Fraud Shields are AI-native: LSTM sequence modeling of API chains, not user session patterns.

  • Per-agent behavioral baseline: frequency, resource access, API sequences, timing
  • Real-time deviation scoring against baseline (0–100)
  • LSTM sequence modeler: multi-step attack chain detection (recon→escalation→exfil)
  • Session-level anomaly: full context analysis, not individual events
  • Kill Switch integration: auto-suspension on high-confidence fraud with forensic package

🧠

Agent Memory Security

Memory Vault

45

incidents this month · 37%

“Control what your agents remember — and what they forget.”

Governs agent memory as a first-class security object. Policy-based filtering of sensitive content at write time. Memory poisoning attack detection. TTL-based automatic purge with audit trail. GDPR right-to-erasure support.

⚠️ The gap it fills No vendor addresses agent memory governance. AI agent memories accumulate without access controls, expiry policies, or audit trails. A memory poisoning attack can corrupt an agent’s behavior without touching a single API key.

  • Policy-based memory write filtering (PII, PHI, secrets blocked at write)
  • PII Shield integration: redact/block before persistence
  • Memory expiry + TTL: auto-purge with full audit trail
  • Memory poisoning prevention: adversarial injection detection
  • Retrieval authorization: every memory read policy-enforced and logged

💳

Agent Finance Controls

Commerce Rails

6

incidents this month · 5%

“Give AI agents a wallet — with guardrails.”

Financial infrastructure for agent-initiated transactions. Per-agent virtual cards with spend limits. Vendor registry (agents can only transact with allowlisted merchants). Approval gates for high-value transactions. Every transaction in immutable ledger.

⚠️ The gap it fills No financial controls exist for AI agents today. Agents authorized to make purchases can spend without limit, with any vendor, at any time. One prompt injection or runaway loop away from significant financial exposure.

  • Agent virtual cards: per-agent card numbers + CVVs, hard spend limits
  • Vendor registry: allowlisted merchants only, no ad-hoc transactions
  • Approval gates: high-value + out-of-policy → human approval before execution
  • Per-agent, per-transaction, per-vendor, per-period limits
  • Agent-to-agent settlement ledger: feeds into FinOps dashboards

PQData — Post-Quantum Security NIST-standardized post-quantum cryptography for secrets, signatures, and audit records.

🔒

Post-Quantum Cryptography

PQData Platform

20

incidents this month · 16%

“Quantum-safe by design — before quantum breaks classical crypto.”

Full post-quantum data security suite using NIST-standardized algorithms: ML-KEM-768 for encryption, ML-DSA-87 for signatures. QuantumVault for PQC-encrypted secrets. PQ Sign for long-validity quantum-safe audit records. Hybrid X25519 + ML-KEM-768 key exchange for TLS 1.3.

⚠️ The gap it fills Every classical encryption scheme used across today's enterprise security stack is vulnerable to Shor’s algorithm on a sufficiently powerful quantum computer. “Harvest now, decrypt later” attacks are already underway. The clock is running.

  • QuantumVault: ML-KEM-768 PQC-encrypted secrets with full key lifecycle
  • PQ Sign: ML-DSA-87 (Dilithium) signatures for audit records + agent attestations
  • Hybrid key exchange: X25519 + ML-KEM-768 for TLS 1.3 — secure against both
  • PQ CryptoGuard: CBOM scanner identifies all classical crypto in use; quantum-readiness score
  • FedRAMP/CMMC/CNSA 2.0 compliance evidence from PQC infrastructure layer

Get the Monthly Breach Report

Every month: all breaches, all vendor stacks, the gap analysis. No fluff — just the intelligence your security team needs.