Skip to Content
logologo
AI Incident Database
Donar
Descubrir
Enviar
  • Bienvenido a la AIID
  • Vista Tabular
  • Vista de lista
  • Entidades
  • Taxonomías
  • Vista espacial
  • Blog
  • Resumen de noticias de IA
  • Incidente aleatorio
  • Registrarse
Descubrir
Enviar
  • Bienvenido a la AIID
  • Vista Tabular
  • Vista de lista
  • Entidades
  • Taxonomías
  • Vista espacial
  • Blog
  • Resumen de noticias de IA
  • Incidente aleatorio
  • Registrarse
Entidades

Enterprise IT systems

Afectado por Incidentes

Incidente 10153 Reportes
Reported Darknet Launch of Xanthorox AI Introduces Autonomous Cyberattack Platform

2025-04-07

Xanthorox AI is a malicious, modular AI system released on darknet forums in early 2025. Designed from scratch for offensive cyber operations, it runs on private infrastructure and includes models for code generation, phishing, malware, social engineering, and real-time voice/image input. Its release represents a deliberate deployment of an autonomous attack platform.

Más

Incidente 16703 Reportes
Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

2026-05-10

An unidentified attacker reportedly used an LLM agent during a May 10 intrusion after exploiting a vulnerable marimo Python notebook. The agent reportedly reused harvested AWS credentials to obtain an SSH key, then pivoted through a bastion host and exfiltrated the schema and contents of an internal PostgreSQL database. Sysdig attributed the post-compromise command stream to real-time agent execution rather than a prebuilt script.

Más

Incidente 15861 Reporte
Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

2026-07-08

Sygnia reported that a threat actor apparently used purportedly AI-assisted or agentic workflows to move rapidly through an unidentified organization's AWS environment during an approximately 72-hour intrusion. The attacker allegedly expanded from an Internet-facing application into cloud infrastructure and data stores, reportedly stealing credentials and sensitive information while demonstrating the ability to disrupt services as leverage for extortion. Sygnia did not identify a specific model.

Más

Entidades relacionadas
Otras entidades que están relacionadas con el mismo incidente. Por ejemplo, si el desarrollador de un incidente es esta entidad pero el implementador es otra entidad, se marcan como entidades relacionadas.
 

Entity

Malicious actors

Incidents involved as Deployer
  • Incidente 1015
    3 Report

    Reported Darknet Launch of Xanthorox AI Introduces Autonomous Cyberattack Platform

Más
Entity

Darknet forum users

Incidents involved as Deployer
  • Incidente 1015
    3 Report

    Reported Darknet Launch of Xanthorox AI Introduces Autonomous Cyberattack Platform

Más
Entity

Cybercriminals

Incidents involved as Deployer
  • Incidente 1015
    3 Report

    Reported Darknet Launch of Xanthorox AI Introduces Autonomous Cyberattack Platform

  • Incidente 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

Más
Entity

Xanthorox AI creators

Incidents involved as Developer
  • Incidente 1015
    3 Report

    Reported Darknet Launch of Xanthorox AI Introduces Autonomous Cyberattack Platform

Más
Entity

Unknown black-hat AI developers

Incidents involved as Developer
  • Incidente 1015
    3 Report

    Reported Darknet Launch of Xanthorox AI Introduces Autonomous Cyberattack Platform

Más
Entity

Victims of phishing attacks

Afectado por Incidentes
  • Incidente 1015
    3 Report

    Reported Darknet Launch of Xanthorox AI Introduces Autonomous Cyberattack Platform

Más
Entity

Victims of malware attacks

Afectado por Incidentes
  • Incidente 1015
    3 Report

    Reported Darknet Launch of Xanthorox AI Introduces Autonomous Cyberattack Platform

Más
Entity

Victims of automated cybercrime

Afectado por Incidentes
  • Incidente 1015
    3 Report

    Reported Darknet Launch of Xanthorox AI Introduces Autonomous Cyberattack Platform

  • Incidente 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

Más
Entity

General public

Afectado por Incidentes
  • Incidente 1015
    3 Report

    Reported Darknet Launch of Xanthorox AI Introduces Autonomous Cyberattack Platform

Más
Entity

Critical infrastructure systems

Afectado por Incidentes
  • Incidente 1015
    3 Report

    Reported Darknet Launch of Xanthorox AI Introduces Autonomous Cyberattack Platform

Más
Entity

Xanthorox Vision

Incidents implicated systems
  • Incidente 1015
    3 Report

    Reported Darknet Launch of Xanthorox AI Introduces Autonomous Cyberattack Platform

Más
Entity

Xanthorox Reasoner Advanced

Incidents implicated systems
  • Incidente 1015
    3 Report

    Reported Darknet Launch of Xanthorox AI Introduces Autonomous Cyberattack Platform

Más
Entity

Xanthorox Coder

Incidents implicated systems
  • Incidente 1015
    3 Report

    Reported Darknet Launch of Xanthorox AI Introduces Autonomous Cyberattack Platform

Más
Entity

Xanthorox AI

Incidents implicated systems
  • Incidente 1015
    3 Report

    Reported Darknet Launch of Xanthorox AI Introduces Autonomous Cyberattack Platform

Más
Entity

Voice and image handling modules

Incidents implicated systems
  • Incidente 1015
    3 Report

    Reported Darknet Launch of Xanthorox AI Introduces Autonomous Cyberattack Platform

Más
Entity

Live web scraping module

Incidents implicated systems
  • Incidente 1015
    3 Report

    Reported Darknet Launch of Xanthorox AI Introduces Autonomous Cyberattack Platform

Más
Entity

Extortionists

Incidents involved as Deployer
  • Incidente 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

Más
Entity

Agentic threat actors

Incidents involved as Deployer
  • Incidente 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • Incidente 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

Más
Entity

Large language model developers

Incidents involved as Developer
  • Incidente 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • Incidente 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

Más
Entity

AI agent system developers

Incidents involved as Developer
  • Incidente 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • Incidente 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

Más
Entity

Privacy

Afectado por Incidentes
  • Incidente 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • Incidente 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

Más
Entity

Amazon Web Services (AWS) customers

Afectado por Incidentes
  • Incidente 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • Incidente 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

Más
Entity

Large language models

Incidents implicated systems
  • Incidente 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • Incidente 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

Más
Entity

Amazon Web Services (AWS) cloud infrastructure

Incidents implicated systems
  • Incidente 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • Incidente 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

Más
Entity

Amazon Web Services (AWS)

Incidents implicated systems
  • Incidente 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • Incidente 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

Más
Entity

AI agent systems

Incidents implicated systems
  • Incidente 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • Incidente 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

Más
Entity

Threat actors

Incidents involved as Deployer
  • Incidente 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

Más
Entity

hackers

Incidents involved as Deployer
  • Incidente 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

Más
Entity

AI agent system deployers

Incidents involved as Deployer
  • Incidente 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

Más
Entity

Information security

Afectado por Incidentes
  • Incidente 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

Más
Entity

marimo

Incidents implicated systems
  • Incidente 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

Más

Investigación

  • Definición de un “Incidente de IA”
  • Definición de una “Respuesta a incidentes de IA”
  • Hoja de ruta de la base de datos
  • Trabajo relacionado
  • Descargar Base de Datos Completa

Proyecto y Comunidad

  • Acerca de
  • Contactar y Seguir
  • Aplicaciones y resúmenes
  • Guía del editor

Incidencias

  • Todos los incidentes en forma de lista
  • Incidentes marcados
  • Cola de envío
  • Vista de clasificaciones
  • Taxonomías

2026 - AI Incident Database

  • Condiciones de uso
  • Política de privacidad
  • dd3f754