MITRE ATLAS Adds Agentic AI Attack Techniques to Its Threat Catalog
MITRE ATLAS, the AI-focused counterpart to the widely used ATT&CK framework, has expanded its knowledge base in early 2026 to include attack techniques targeting autonomous AI agents. The updates introduce three notable techniques: AI Supply Chain Compromise (AML.T0010), Publish Poisoned AI Agent Tool (AML.T0104), and AI Agent Tool Poisoning (AML.T0110), all describing how adversaries can exploit the tools that AI agents call and the registries they rely on. Together, these techniques outline a realistic attack chain in which a malicious actor poisons a tool, publishes it to a trusted registry, and waits for an agent to install and invoke it. A real-world example of this pattern was observed in the Postmark MCP server incident, where a trusted tool was turned into an exfiltration channel through an agent. Like ATT&CK before it, ATLAS aims to give security teams a shared vocabulary for discussing AI-specific threats, grounding its techniques in documented, real-world incidents rather than theoretical scenarios.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in