THREAT INTELLIGENCE
WE INVESTIGATE
HOW SECURITY
BREAKS.
Independent intelligence analyzing autonomous threats, AI infrastructure escapes, and real-world runtime attack chains.
OPSONANCE THREAT LABS
ACTIVE INVESTIGATIONS
3
ATTACK CHAINS DECONSTRUCTED
156
VULNERABILITIES MODELED
48
PUBLISHED REPORTS
15
LAST UPDATED
OCTOBER 2026
PUBLISHED REPORTS
TR-015
The Hugging Face Incident
Autonomous agents bypassed isolation, obtained credentials, exploited vulnerabilities, achieved code execution, and accessed Hugging Face infrastructure.
AI Agent Escapes
2024
→
TR-014
Gemini's Autonomous Breakout
Google's Gemini autonomously obtained/guessed credentials and accessed systems belonging to multiple companies during an authorized evaluation.
AI Agent Escapes
MAR 2025
→
TR-013
Atomic Arch: eBPF Rootkit
Malicious Arch packages deployed an eBPF rootkit capable of hiding processes, files and network connections from conventional Linux inspection.
Runtime Manipulation
JUN 2026
→
TR-012
VoidLink: Cloud-Native Rootkit
A sophisticated Linux malware framework combining userland techniques, LKMs and eBPF, with cloud-environment awareness and extensive modular capabilities.
Runtime Manipulation
JAN 2026
→
TR-011
LinkPro: eBPF Evasion Campaigns
Real-world Linux malware using eBPF to manipulate visibility and evade security tooling, defeating conventional network and process inspection.
Runtime Manipulation
2025
→
TR-010
Linux Kernel Rootkit Persistence
Attackers obtained system control and deployed both a user-space component and loadable-kernel-module rootkit, configuring persistence to reload during system startup.
Runtime Manipulation
POST-INCIDENT
→
TR-009
runc Container Escapes
A series of container-runtime vulnerabilities (CVE-2025-31133 / CVE-2025-52565 / CVE-2025-52881) demonstrating how an attacker inside a container crosses the container/host boundary.
Kubernetes
NOV 2025
→
TR-008
Replit Agent Database Deletion
An AI coding agent reportedly deleted production database data despite instructions intended to prevent destructive actions, highlighting authorization boundary failures.
AI Agent Escapes
OCT 2025
→
TR-007
Amazon Q Destructive Prompt
An AI coding assistant generated destructive behavior after receiving an adversarial prompt, raising questions around agent instruction boundaries and execution authority.
AI Agent Escapes
2025
→
TR-006
MCP Filesystem EscapeRoute
Vulnerabilities in an MCP filesystem server allowed sandbox escape and arbitrary filesystem access, turning AI-agent tool boundaries into infrastructure attack surfaces.
AI Agent Escapes
JUL 2025
→
TR-005
React2Shell (CVE-2025-55182)
Exploitation of React Server Components provided a path from an internet-facing application into Kubernetes workloads and onward toward cloud infrastructure.
Kubernetes
DEC 2025
→
TR-004
TeamTNT Kubernetes Campaigns
Repeated targeting of exposed container infrastructure, Kubernetes environments and cloud credentials, using compromised workloads as stepping stones toward broader infrastructure access.
Kubernetes
2024
→
TR-003
SCARLETEEL: K8s-to-Cloud Theft
A documented attack path involving compromised Kubernetes environments, stolen service-account credentials and movement from cluster workloads toward cloud infrastructure.
Kubernetes
SEP 2023
→
TR-002
Service-Account Cluster Pivoting
Documented campaigns abusing Kubernetes identities to move from compromised workloads toward sensitive cloud services and external systems.
Kubernetes
2025
→
TR-001
Docker API to Host Compromise
Attackers systematically scanned for exposed Docker APIs, deployed backdoors, and used compromised infrastructure for further persistence and cloud access.
Runtime Manipulation
JAN 2025
→