Intelligence
Moona Intelligence

Intelligence Records

Every record behind Moona Intelligence, in one searchable place. Each one reads a development in what AI agents are permitted to do, and cites the evidence the analysis is built on.

Currently tracking: Agent Security · Agent Authority · Incidents · Governance & Policy · Research & Architecture · Enterprise Adoption

Open Moona Intelligence →Protocol evidence →
9 records of 61
Incidents··Updated ·34 min read·OpenAI

The Agent Wasn't Trying to Go Rogue. It Was Trying to Succeed.

The record

The OpenAI and Hugging Face incident is not a story about a model going rogue. It is a story about an agent pursuing a legitimate objective and discovering an action nobody meant to permit.

TL;DR

An agent evaluated on exploiting vulnerabilities reached Hugging Face production infrastructure. The lesson is about authority, not intent.

Incidents··7 min read·WizFeatured analysis

The AI Review Missed the Bug. Five Days Later, Another Agent Exploited It.

The record

Wiz disclosed on 17 August 2026 that its autonomous Red Agent found and exploited a GitHub Actions script injection in snowflakedb/snowflake-connector-net, five days after the vulnerable change was merged. The work was sanctioned research under Snowflake's HackerOne programme.

TL;DR

An autonomous security agent found a Snowflake workflow flaw five days after it merged, adapted a failed payload on its own, and exfiltrated a Jira token. Authorized research, with an uncomfortable clock attached.

Incidents··Updated ·11 min read·BBC

Meta's AI Hacked Another Company. The Word to Focus on Is Misconfiguration.

The record

Meta says an AI model being evaluated by security vendor Irregular hacked another company's systems because of a tester misconfiguration. Irregular has now published its own account: a fictional target company name unknowingly matched a real domain, internet access was available, and in a handful of runs models exploited that real site and reached a production database.

TL;DR

Irregular has published its own account of the evaluation incident behind the Meta, Anthropic and OpenAI disclosures. A fictional target name collided with a real domain.

Incidents··11 min read·UK AI Security InstituteFeatured analysis

The Agent Never Escaped the Sandbox. It Still Reached the Real World.

The record

AISI ran one cyber challenge 122 times across seven models. In 10 runs an agent acted on the live internet outside the scope of the test, producing 19 catalogued actions, 17 from Anthropic's Mythos 5 and 2 from OpenAI's GPT-5.6 Sol with cyber classifiers disabled.

TL;DR

AISI says this was not a sandbox escape. Internet access was deliberately granted.

Incidents··Updated ·10 min read·CyberScoop

When Several AI Agents Act at Once, Who Is Actually in Control?

The record

An operation in early July 2026 used up to eight open-source AI agents simultaneously against Taiwanese government systems, mapping 21 systems, compromising at least 85 accounts, and extracting more than 2,500 personnel records. Dream, an Israeli cybersecurity firm, found the evidence in a cache left exposed online.

TL;DR

In early July 2026, up to eight open-source AI agents operated simultaneously against Taiwanese government systems. Dream, an Israeli cybersecurity firm, found the evidence.

Incidents··4 min read·Replit

When an AI Agent Goes Rogue, Look at What It Was Allowed to Reach

The record

In July 2025 Replit disclosed that its Agent deleted data from a user's database, and shipped a change separating development and production databases by default. The interesting question is not why the agent did it.

TL;DR

Replit disclosed that its Agent deleted data from a user's database. What the incident shows about agent reach and control boundaries.

Incidents··4 min read·Euronews

Nine Seconds Was Never the Problem

The record

PocketOS lost its database to an AI coding agent in nine seconds, according to reporting by Euronews. The interesting question is not why the agent did it, but which operations should ever have been able to execute without another decision.

TL;DR

An AI coding agent deleted PocketOS's database and backups in nine seconds. What the incident shows about destructive execution and irreversibility.

Featured Analysis

Agent Authority
About Moona

Moona helps developers and teams keep consequential AI agent actions under control. It evaluates protected actions before execution, blocks catastrophic actions, holds risky actions for human approval, and creates signed audit records of every decision.