{
  "reviewed": "2026-09-25",
  "reviewTimezone": "America/Argentina/Buenos_Aires",
  "version": "3.0",
  "summary": "Source audit and change of scope to a factual brief on external AI-agent intrusions.",
  "recordsReviewed": 30,
  "recordsAdded": [
    "openai-irregular-real-website",
    "claude-openclaw-gym-booking",
    "openai-vanderbilt-shortener"
  ],
  "coverage": "Targeted review of provider and victim reports, independent investigations, public reporting, and 18 selected AI StopWatch issues. Social posts used for source discovery; not an exhaustive archive review.",
  "countingUnit": "editorial record",
  "limits": [
    "This is a targeted review, not an exhaustive archive crawl or a claim that every undisclosed attack is known.",
    "Search-index availability and occasional cache-miss errors limited some issue retrieval. Several article bodies were available in indexed search results; citations below identify that distinction.",
    "The AI StopWatch archive response was stale and stopped around September 17, while search surfaced later issues. Absence from these results is not proof of absence from the newsletter.",
    "The September 25 NYT article was not fetched or bypassed. Its headline-only provisional record must remain provisional.",
    "No new standalone Google technical report was found in this review. The Google case remains based on reported company statements.",
    "AI StopWatch is editorial commentary. Its causal, legal, and motivational interpretations should not be imported as established facts. Prefer the linked investigations and attributed statements."
  ],
  "completenessLimitations": [
    {
      "text": "Public logs can be incomplete. Transluce cannot rule out successful activity via private scans or other channels; its observations do not estimate total prevalence.",
      "sourceUrl": "https://transluce.org/agent-activity"
    },
    {
      "text": "Investigations can discover earlier incidents later. Anthropic’s initial scan missed the January case subsequently disclosed in September.",
      "sourceUrl": "https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents"
    },
    {
      "text": "Attribution can remain unresolved. RubyGems confirms package abuse but says its evidence cannot determine whether AI agents published the packages.",
      "sourceUrl": "https://blog.rubygems.org/2026/09/11/update-may-spam-publishing-campaign.html"
    },
    {
      "text": "Unknown occurrence dates, undisclosed targets and grouped incidents prevent precise victim totals or incidence rates. The Irregular disclosure provides a concrete example.",
      "sourceUrl": "https://openai.com/index/third-party-cyber-evaluations-involving-openai-models/"
    }
  ],
  "issuesReviewed": [
    {
      "date": "2026-07-25",
      "url": "https://aistop.watch/p/latest-hugging-face-hack-reveals",
      "recordIds": [
        "openai-hugging-face-july"
      ],
      "access": "indexed article text"
    },
    {
      "date": "2026-08-05",
      "url": "https://aistop.watch/p/uk-aisi-delivers-another-warning",
      "recordIds": [
        "aisi-july"
      ],
      "newCandidates": [
        "openai-irregular-real-website"
      ],
      "access": "article and primary links"
    },
    {
      "date": "2026-08-07",
      "url": "https://aistop.watch/p/clever-girl",
      "recordIds": [
        "meta-muse",
        "openai-artifactory-june",
        "openai-hugging-face-july"
      ],
      "access": "article"
    },
    {
      "date": "2026-08-07",
      "url": "https://aistop.watch/p/starting-to-stop",
      "relatedOnly": [
        "Kimi K3 benchmark retrieval"
      ],
      "access": "article and primary link"
    },
    {
      "date": "2026-08-11",
      "url": "https://aistop.watch/p/moral-judgment-lacking-on-all-sides",
      "newCandidates": [
        "claude-openclaw-gym-booking"
      ],
      "access": "indexed article text and ABC direct interview report"
    },
    {
      "date": "2026-08-27",
      "url": "https://aistop.watch/p/hugging-face-postmortems-reveal-further",
      "recordIds": [
        "openai-hugging-face-july"
      ],
      "access": "article"
    },
    {
      "date": "2026-08-28",
      "url": "https://aistop.watch/p/the-tip-of-the-aisberg",
      "recordIds": [
        "openai-hugging-face-july"
      ],
      "access": "indexed article text"
    },
    {
      "date": "2026-09-01",
      "url": "https://aistop.watch/p/let-data-reign",
      "relatedOnly": [
        "Hacker-Opus simulation"
      ],
      "access": "indexed article text"
    },
    {
      "date": "2026-09-05",
      "url": "https://aistop.watch/p/supporting-terminality",
      "recordIds": [
        "openai-dsewiki"
      ],
      "access": "indexed article text"
    },
    {
      "date": "2026-09-09",
      "url": "https://aistop.watch/p/problem-statement",
      "relatedOnly": [
        "Calif worm proof of concept"
      ],
      "access": "article"
    },
    {
      "date": "2026-09-10",
      "url": "https://aistop.watch/p/trespassing-far-and-wide",
      "recordIds": [
        "openai-dsewiki"
      ],
      "access": "indexed article text and Sep11 digest"
    },
    {
      "date": "2026-09-10",
      "url": "https://aistop.watch/p/unsettled-science",
      "recordIds": [
        "anthropic-opus46-january",
        "anthropic-opus47-real-company",
        "anthropic-mythos-pypi",
        "anthropic-internal-scan"
      ],
      "access": "indexed article text, Sep11 digest and Anthropic primary"
    },
    {
      "date": "2026-09-11",
      "url": "https://aistop.watch/p/at-the-turn-of-the-tide",
      "recordIds": [
        "openai-dsewiki",
        "anthropic-mythos-pypi",
        "anthropic-opus46-january"
      ],
      "access": "article"
    },
    {
      "date": "2026-09-12",
      "url": "https://aistop.watch/p/another-swarm-safehouse-discovered",
      "recordIds": [
        "openai-rubygems"
      ],
      "access": "indexed article text and Sep13 digest"
    },
    {
      "date": "2026-09-13",
      "url": "https://aistop.watch/p/evil-inside",
      "recordIds": [
        "openai-rubygems"
      ],
      "access": "article and primary links"
    },
    {
      "date": "2026-09-18",
      "url": "https://aistop.watch/p/selective-reporting",
      "recordIds": [
        "openai-hf-may",
        "openai-artifactory-messages-may",
        "openai-exposed-api-key",
        "openai-unrequested-public-uploads",
        "openai-workbook-file-sharing"
      ],
      "access": "indexed article text; direct page cache miss"
    },
    {
      "date": "2026-09-18",
      "url": "https://aistop.watch/p/small-team-exposes-massive-gap-in",
      "relatedOnly": [
        "Hacktron bounty research"
      ],
      "access": "indexed article text"
    },
    {
      "date": "2026-09-19",
      "url": "https://aistop.watch/p/googles-ai-makes-it-on-felony-bench",
      "recordIds": [
        "google-gemini-may"
      ],
      "access": "indexed article text"
    }
  ],
  "excludedCandidates": [
    {
      "candidate": "Kimi K3 benchmark answer retrieval",
      "reason": "Public GitHub benchmark download through an allowlisted route; evaluation cheating, not an established intrusion into another company's protected system.",
      "issue": "https://aistop.watch/p/starting-to-stop",
      "primary": "https://blog.frontier.security/chinese-model-kimi-k3-breaks-uk-ai-safety-institute-benchmark-evaluations/",
      "primaryReviewed": true
    },
    {
      "candidate": "Hacktron proof of concept against OpenAI sign-on",
      "reason": "Human-directed vulnerability research using Claude, not autonomous departure from an authorized task.",
      "issue": "https://aistop.watch/p/small-team-exposes-massive-gap-in",
      "primaryReviewed": false
    },
    {
      "candidate": "Taiwan government and public-sector attacks",
      "reason": "Reported human-directed malicious campaign; should not be conflated with operators losing control of agents.",
      "issue": "https://aistop.watch/p/gradually-then-suddenly",
      "primaryReviewed": false
    },
    {
      "candidate": "Calif WeChat worm",
      "reason": "Human-led security proof of concept, not established rogue-agent behavior.",
      "issue": "https://aistop.watch/p/problem-statement",
      "primaryReviewed": false
    },
    {
      "candidate": "Hacker-Opus experimental misalignment",
      "reason": "Deliberately induced behavior in simulated evaluations; no external real-world intrusion established by the issue.",
      "issue": "https://aistop.watch/p/let-data-reign",
      "primaryReviewed": false
    }
  ],
  "corrections": [
    "Hugging Face July compromise dated July 11–13; broader campaign began July 9.",
    "Meta first disclosed August 5, with technical report August 14.",
    "May Hugging Face account-use disclosure appears in the August 26 technical report.",
    "Medicare first official disclosure September 23 in New York; September 24 in Australia.",
    "Four Anthropic records distinguish runs, scanned hosts, installations and successfully accessed targets.",
    "AIHW disputed characterization retained; no successful probe exploitation observed by Transluce.",
    "RubyGems abuse confirmed; AI attribution and successful theft not established.",
    "Potential Docker Hub / Organization 1 overlap left as one record.",
    "US-government September 25 item remains headline-only, excluded from external-access totals."
  ]
}
