Skip to content

Enhancement/q2#11

Merged
requie merged 4 commits into
mainfrom
enhancement/Q2
Jun 10, 2026
Merged

Enhancement/q2#11
requie merged 4 commits into
mainfrom
enhancement/Q2

Conversation

@requie

@requie requie commented Jun 10, 2026

Copy link
Copy Markdown
Owner

No description provided.

requie added 4 commits June 10, 2026 15:25
- Add OWASP Top 10 for Agentic Applications (2026) and Microsoft
  agentic failure-mode taxonomy v2.0 to the Frameworks section
- Add new sections: MCP & Tool-Protocol Security, Computer-Use &
  Browser Agent Attacks, RAG Attack Taxonomy, Voice/Audio & Multimodal
  Attacks, Fine-Tuning & Model Supply-Chain Security, AI-on-AI Red Teaming
- Tag agentic attack vectors with OWASP ASI IDs; refresh 2025-2026
  incident list and add industry impact stats
- Update TOC, badge to June 2026, remove stale pip flags
- Update PyRIT (v0.11, repo move, AI Red Teaming Agent), Garak (NVIDIA,
  v0.14), promptfoo (OpenAI acquisition, Hydra); note multi-turn shift
- Add emerging agent-native platforms (Cisco AI Defense, Novee AI)
- Add validation dates to tool entries
- Add three current case studies (AI-orchestrated state intrusion,
  OpenClaw framework, Copilot RCE) and regroup older ones as historical
…tack trees

- Replace pseudocode Evaluation Harness with runnable YAML policy,
  Python scorer, and release-gate runner
- Add AI Incident Response section (agent containment, escalation,
  EU serious-incident reporting)
- Add three agentic attack trees (goal hijack, supply chain, rogue
  agents) and tag all trees with OWASP ASI IDs
- Upgrade EU AI Act section to enforcement-grade GPAI obligations with
  Article-to-evidence mapping table
- Refresh Update Watchlist with NIST 2026 items and current dates
- Add agentic checks (memory integrity, inter-agent auth, MCP pinning,
  agent registry) to PR checklist
- Add worked examples to test-case-library, vulnerability-report, and
  threat-modeling-workshop templates
- Convert CHANGELOG Unreleased to dated 2026-06-10 release entry
- Add 2026 threat-landscape source list to References; fix OWASP/Garak
  links; update footer to June 2026
@requie requie self-assigned this Jun 10, 2026
@requie requie added documentation Improvements or additions to documentation enhancement New feature or request labels Jun 10, 2026
@requie requie merged commit 6feda19 into main Jun 10, 2026
1 check passed
@requie requie deleted the enhancement/Q2 branch June 10, 2026 15:56

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 632f2288bc

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread README.md
| Single-user policy violation, narrow blast radius | Medium | Standard ticket + scheduled fix |

### Regulatory Reporting (don't skip this)
Under the **EU AI Act**, providers of GPAI models with systemic risk must **report serious incidents to the AI Office** (effective 2 Aug 2026). Bake notification timelines into the runbook *before* an incident, and capture evidence (logs, reproductions, the [vulnerability report](#-practitioner-appendices)) in a form regulators and customers will accept. See [Regulatory Compliance](#regulatory-compliance).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Use the GPAI reporting application date

For GPAI models with systemic risk, the AI Act's GPAI obligations, including tracking/documenting/reporting serious incidents, entered into application on 2 August 2025; 2 August 2026 is the later Commission enforcement/fines date, as the implementation timeline below also notes. As written, this incident-response guidance can lead teams to leave reporting out of runbooks for incidents occurring between August 2025 and August 2026.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant