Pith. sign in

Paper Citation Record · LEDGER

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario

As of 15 August 2026, this Paper Citation Record lists 51 of 51 outbound references and 0 inbound Pith citation observations for arXiv:2608.08131.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2608.08131 v1

Coverage vector

measured 51 of 51 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-12T00:27:41.904757Z

measured 51 of 51 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-15T06:32:42.880941+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

51 of 51 outbound references displayed

  • verified exact0
  • verified fuzzy27
  • unresolved22
  • parse uncertain0
  • malformed identifier2
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 9b442563-4922-47c9-85cc-b4c8858ed49e · outbound

This paper cites Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-12T00:27:39.724833Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T00:27:39.724833Z digest=sha256:5019c66a4a94e143ec35274e33e8b04ff54329b1746fcc57666f95ead7d3b49c

Observation 309e5243-f2cf-4c56-9691-9e60d0382dfd · outbound

This paper cites Poisoning Attacks on LLMs Require a Near-constant Number of Poison Samples,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Poisoning Attacks on LLMs Require a Near-constant Number of Poison Samples,

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-12T00:27:39.755114Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T00:27:39.755114Z digest=sha256:755defe4d3db903a156ee00c2e00427b18ec4cd0884ce1e22107f17cdc35f2c0

Observation 956ce005-9583-4196-a8d1-79c6a4d7b282 · outbound

This paper cites BadAgent: Inserting and Activating Backdoor Attacks in LLM Agents,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario BadAgent: Inserting and Activating Backdoor Attacks in LLM Agents,

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-12T00:27:39.796017Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T00:27:39.796017Z digest=sha256:d7c75345551379805a331e58d5585568c308de9d19308a3f4affa9b2327c335e

Observation c2e9abdf-113b-4826-89be-c03f17de142f · outbound

This paper cites AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases,

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:48.674850Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:39.846497Z digest=sha256:3a780fb3e16b4445de445040294a299819b01fa691a85ab1790bed60392c6e46

Observation 9dc28dc3-f513-470d-8c30-27ff1fdfcfe4 · outbound

This paper cites MemoryGraft: Persistent Compromise of LLM Agents via Poisoned Experience Retrieval,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario MemoryGraft: Persistent Compromise of LLM Agents via Poisoned Experience Retrieval,

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-12T00:27:39.885649Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T00:27:39.885649Z digest=sha256:524e5d252c8da1ad1f86f132d7459ed21f21dbf0500042fce093460364821050

Observation 02791b60-b0b8-4fb7-ab4d-e39b756280c3 · outbound

This paper cites MemMorph: Tool Hijacking in LLM Agents via Memory Poisoning.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario MemMorph: Tool Hijacking in LLM Agents via Memory Poisoning

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-12T00:27:39.928535Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T00:27:39.928535Z digest=sha256:fbbea246e0af62305ae874dd62d570c82bef879c5b15d5d3cfef1a480e29af4d

Observation 41fdd77f-ba8c-4212-8d29-5b27157f952e · outbound

This paper cites Your LLM Agent Can Leak Your Data: Data Exfiltration via Backdoored Tool Use,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Your LLM Agent Can Leak Your Data: Data Exfiltration via Backdoored Tool Use,

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:48.524756Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:39.975715Z digest=sha256:c4bda9c1bd186086b892edaaba6a7f32e0216abb5cc30deff75f457f89d822e0

Observation 863a6853-327a-4029-befe-468aefb5cf7e · outbound

This paper cites TrojanStego: Your Language Model Can Secretly Be A Steganographic Privacy Leaking Agent,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario TrojanStego: Your Language Model Can Secretly Be A Steganographic Privacy Leaking Agent,

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-12T00:27:40.044762Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T00:27:40.044762Z digest=sha256:a85a1faa7a25477886ce46a455cdc5d9d486b2b8e1f1a8c042f3dbfd54cdfe5c

Observation c8d20b37-935f-480c-aac7-04448fb7bdf1 · outbound

This paper cites BackdoorLLM: A Comprehensive Benchmark for Backdoor Attacks and Defenses on Large Language Models,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario BackdoorLLM: A Comprehensive Benchmark for Backdoor Attacks and Defenses on Large Language Models,

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:48.354775Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:40.080853Z digest=sha256:adf722ca75d841d346289767b9c8dbd4484997502b31b6bf22a425c3759c99a0

Observation d0603caf-fb05-4bc1-969b-7889702e85ce · outbound

This paper cites Not What You’ve Signed Up For: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Not What You’ve Signed Up For: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection,

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-12T00:27:40.119007Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T00:27:40.119007Z digest=sha256:0fd74e31485e90b4e39435beff0006775586445a02ef1fa4dbc61381804fece4

Observation b8f36127-fa5a-4672-aba4-460fd160a830 · outbound

This paper cites AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-12T00:27:40.164821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T00:27:40.164821Z digest=sha256:c6cd5c26a4b8804391984af0cab4ba65c4c79a9192762b8e4255044ae72ea4a9

Observation 90e09d21-ab08-4f6f-bdc5-07fb1cc706b1 · outbound

This paper cites The UNSTOPPABLE Computer Virus is HERE...,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario The UNSTOPPABLE Computer Virus is HERE...,

Reference 12

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:48.223407Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:40.214847Z digest=sha256:8f402f6c47589186727fe0f09c2a84d30d421560f921cf7ca0d60aa27a0e3c97

Observation 28cf8109-f145-4469-93e5-b9c6cc521c6f · outbound

This paper cites Inhibitor Chip,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Inhibitor Chip,

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:48.135312Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:40.254823Z digest=sha256:d7c4923e2f6d52eb73336acf4e25b4971738c8b8c3cbf0d5f29597115ead5688

Observation 5545133a-5795-413f-89f0-c74741f32cce · outbound

This paper cites Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications

Reference 14

Resolution
malformed identifier
no resolver link, observed 2026-08-12T00:27:40.294752Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T00:27:40.294752Z digest=sha256:52ffbef329b5aca4e6256bae1c06004338d36337e3febb01581bb2f792c5f5df

Observation 28840d74-d48d-450b-82b2-9c346948f179 · outbound

This paper cites AgentWorm: Self-Propagating Attacks Across LLM Agent Ecosystems.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario AgentWorm: Self-Propagating Attacks Across LLM Agent Ecosystems

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-12T00:27:40.330332Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T00:27:40.330332Z digest=sha256:36aabab9c982ef35cdd811ef9ca61f9f32d092c1630eba29bab67d4c36917b5a

Observation 4eaffcdb-2844-426b-8fa3-1d5e56c9b88c · outbound

This paper cites Agent Harness Plugins,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Agent Harness Plugins,

Reference 16

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:48.037153Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:40.364899Z digest=sha256:f8527349e81b49b05f88bbf79ec9695e9a95a39b33a78e0cc4dfde1a41159977

Observation 56dbd000-8080-4d1a-9661-08e9fd42b32b · outbound

This paper cites Sandboxing,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Sandboxing,

Reference 17

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:47.895176Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:40.415447Z digest=sha256:b890f96e54a2f11cd8ab7f04e89d3c3770290de4d03cdd9acb1cba5935ec46a7

Observation f08083ad-512a-4fea-849c-1f0fcac7ae78 · outbound

This paper cites AI Agents Enable Adaptive Computer Worms.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario AI Agents Enable Adaptive Computer Worms

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-12T00:27:40.475237Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T00:27:40.475237Z digest=sha256:06a1747019de05d7a7b0a976cad0ccdd1c5bb36398be6fca08ec79143b7d3208

Observation 6c56bdc4-213e-4f59-9a2b-b4bc8351a96b · outbound

This paper cites an unresolved cited work.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Unresolved cited work

Reference 19

Resolution
malformed identifier
raw_fallback, observed 2026-08-12T00:27:47.744850Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:40.523864Z digest=sha256:18b8f1e3f26cf19682bb0ab5f9778a5a4e866c7e27fba9b183e4358440d54684

Observation 7e82f5d8-4a84-4efe-bcbf-ebe065d46d41 · outbound

This paper cites "Do Not Mention This to the User": Detecting and Understanding Malicious Agent Skills in the Wild.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario "Do Not Mention This to the User": Detecting and Understanding Malicious Agent Skills in the Wild

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-12T00:27:40.575004Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T00:27:40.575004Z digest=sha256:9917cde53422f7d4802b9586202180eacd8b5111b33dfdd5a2cadd1453681f21

Observation 2003454a-7efe-4ef3-8e63-347f64e90bb7 · outbound

This paper cites The Promptware Kill Chain: How Prompt Injections Gradually Evolved Into a Multistep Malware Delivery Mechanism,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario The Promptware Kill Chain: How Prompt Injections Gradually Evolved Into a Multistep Malware Delivery Mechanism,

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-12T00:27:40.597003Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T00:27:40.597003Z digest=sha256:c51a5c547fec61548a11eab96b8b4b105882046c39e301ed89368941539b3b9f

Observation 19e34c6d-af88-4013-ac20-e54116b07705 · outbound

This paper cites The Trigger in the Haystack: Extracting and Reconstructing LLM Backdoor Triggers,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario The Trigger in the Haystack: Extracting and Reconstructing LLM Backdoor Triggers,

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-12T00:27:40.644753Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T00:27:40.644753Z digest=sha256:c1f7d169c7be2028785f887f055d1f45b0a0abc956e24e91c35b4acb6be01462

Observation 0d6a537f-752f-4b1f-820e-cd9af7f1dfb4 · outbound

This paper cites an unresolved cited work.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Unresolved cited work

Reference 23

Resolution
unresolved
raw_fallback, observed 2026-08-12T00:27:47.582954Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:40.684756Z digest=sha256:ac0baca77605df67195771dcb616bb9c4b11ebbe54c05ef28c29d85e2eb9a5ae

Observation 4d6b4293-8dd0-4f9f-9f70-1d5c1573410b · outbound

This paper cites Data Scientists Targeted by Malicious Hugging Face ML Models with Silent Backdoor,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Data Scientists Targeted by Malicious Hugging Face ML Models with Silent Backdoor,

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:47.433652Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:40.734754Z digest=sha256:619dfbdd45887dc3684da218e5f9a1797b8f287e0391fb4d4ac26a0c5ad8c147

Observation 82a30afb-a12e-442f-ae1d-9ad47e106730 · outbound

This paper cites Malicious ML Models Discovered on Hugging Face Platform,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Malicious ML Models Discovered on Hugging Face Platform,

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:47.287910Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:40.765430Z digest=sha256:a501e38f71a6dce6d1102ded452f2abce5cd1a586ff79e92c5f4b6b515936ae3

Observation 36629ec0-20e0-47c0-9741-962c43c5f3cd · outbound

This paper cites Vassilev, A.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Vassilev, A

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-12T00:27:40.816629Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T00:27:40.816629Z digest=sha256:4854417929929ec590f218a5b000b2a8e67738e0647b6c1dd9c64f54c0a5950e

Observation 61973191-b00b-4015-97bc-139ac8f0acb1 · outbound

This paper cites OpenAI and Hugging Face Partner to Address Security Incident During Model Evaluation,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario OpenAI and Hugging Face Partner to Address Security Incident During Model Evaluation,

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:47.124754Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:40.865377Z digest=sha256:a45f7e80e6eea75afc1922d375c6f42d2c1f616a393aadbd86b074d0f7ddd5f2

Observation e055b162-a25d-45f2-a4b9-830aa4120bc4 · outbound

This paper cites Third-Party Cyber Evaluations Involving OpenAI Models,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Third-Party Cyber Evaluations Involving OpenAI Models,

Reference 28

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:46.960857Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:40.904977Z digest=sha256:4929ee9dbde83b22bb266489fd6f8d01079af4ffa725be9bae1c1660165fdf6e

Observation c788fb0b-dc77-430c-80c3-009f7d47f6b1 · outbound

This paper cites Security Incident Disclosure—July 2026,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Security Incident Disclosure—July 2026,

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:46.836194Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:40.945053Z digest=sha256:ca819833ec3839057fb4647496e30c3720d039dc195e5ec464f7f951c30974af

Observation f4312c69-80d4-4956-9d95-51246b8ea4b5 · outbound

This paper cites Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident,

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:46.777605Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:40.983158Z digest=sha256:0828107cd84272200a252e0f09a1e3618237879015b313ab2b9a61200ab695a9

Observation aa867b46-3ae5-4694-a18a-155bf11a5e6a · outbound

This paper cites Investigating Three Real-World Incidents in Our Cybersecurity Evaluations,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Investigating Three Real-World Incidents in Our Cybersecurity Evaluations,

Reference 31

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:46.694829Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:41.024857Z digest=sha256:742b3a664f19ddb388d75096a71b822559bf8ba91b56571bc2dc68f5475adbde

Observation 9f1afd4d-e07f-4588-bac1-3404a195b73a · outbound

This paper cites CVE-2025-32711 Detail,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario CVE-2025-32711 Detail,

Reference 32

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:46.558954Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:41.078459Z digest=sha256:b597736377e026bbbad8fbf3e56732701efa0d83d3842c9c513a458b1f36107b

Observation 9388d3cc-4e1f-4e0c-bcda-c6099742e650 · outbound

This paper cites CVE-2025-32711: AI Command Injection in M365 Copilot,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario CVE-2025-32711: AI Command Injection in M365 Copilot,

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:46.423653Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:41.098637Z digest=sha256:b7fa0cdd9bf8de3ab56eaa15aad72334f0a4635d52b4d26b84ada38d38fbecb8

Observation db074430-105e-4bec-b1c9-00adb4c43d7f · outbound

This paper cites Microsoft 365 Copilot: New Zero-Click AI Vulnerability Allows Corporate Data Theft,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Microsoft 365 Copilot: New Zero-Click AI Vulnerability Allows Corporate Data Theft,

Reference 34

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:46.364752Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:41.144750Z digest=sha256:04bc25c4a4b11e2cfe336de5aead040e3d63121eca98f69869e872f49f16da70

Observation 63282f5e-41cd-41f0-be87-99ca0a7db54c · outbound

This paper cites ShadowLeak: A Zero-Click, Service-Side Attack Exfiltrating Sensitive Data Using ChatGPT’s Deep Research Agent,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario ShadowLeak: A Zero-Click, Service-Side Attack Exfiltrating Sensitive Data Using ChatGPT’s Deep Research Agent,

Reference 35

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:46.194755Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:41.164751Z digest=sha256:873bba938bfc6fba92f2303da6b75b2ade3989adab213f703d2259a5d0590d35

Observation 275b5edd-67ca-48af-8abb-07aa01d72b09 · outbound

This paper cites MCP Security Notification: Tool Poisoning Attacks,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario MCP Security Notification: Tool Poisoning Attacks,

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:46.104833Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:41.204756Z digest=sha256:d6ff872c8428197ce1cb7d6a4363e33d7ea12e20042eb3da296301b84c32d391

Observation 2c918cec-6937-4f0f-9753-7749515e1915 · outbound

This paper cites Memory Injection Attacks on LLM Agents via Query-Only Interaction,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Memory Injection Attacks on LLM Agents via Query-Only Interaction,

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-12T00:27:41.244758Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T00:27:41.244758Z digest=sha256:c8fc6f73b639898feb7b317b15b6a26781addc24d9cd553f6c933cebfcf821b7

Observation 9d260514-6c10-4e62-a59f-3dc253b05baf · outbound

This paper cites Hidden in Memory: Sleeper Memory Poisoning in LLM Agents.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Hidden in Memory: Sleeper Memory Poisoning in LLM Agents

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-12T00:27:41.285934Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T00:27:41.285934Z digest=sha256:b150bf3a7ac32173ecda03d9fd847b14ca66d30197b4124b0cdd592a63aac063

Observation ece7a236-3d8c-492c-93d0-0049317b5277 · outbound

This paper cites From Untrusted Input to Trusted Memory: A Systematic Study of Memory Poisoning Attacks in LLM Agents.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario From Untrusted Input to Trusted Memory: A Systematic Study of Memory Poisoning Attacks in LLM Agents

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-12T00:27:41.324755Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T00:27:41.324755Z digest=sha256:053465e3ebbe67de1343ba9cdc023f064f0d68e5291933e26154fd9487e3944a

Observation 72c09d27-fabc-483a-99d9-d59ee8df0cdb · outbound

This paper cites Malicious Script Injected into Amazon Q Developer for Visual Studio Code Extension,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Malicious Script Injected into Amazon Q Developer for Visual Studio Code Extension,

Reference 40

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:45.964752Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:41.364751Z digest=sha256:f33f3f575dd433dec0322d1f1e0edf3812ccbfe2fecb7e2792b9ff373afb13b4

Observation 206df232-0946-48f4-9c81-a7f626d399b0 · outbound

This paper cites The Shai-Hulud 2.0 npm Worm: Analysis, and What You Need to Know,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario The Shai-Hulud 2.0 npm Worm: Analysis, and What You Need to Know,

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:45.774752Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:41.413633Z digest=sha256:b220b5bda592597e87866eaf29a4aded74923982f7cc4b3b037f55725d8607a8

Observation 16557417-335a-49e2-91ed-a3b236408ba3 · outbound

This paper cites Mini Shai-Hulud Targets AI Coding Agents: What Developers Need to Know,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Mini Shai-Hulud Targets AI Coding Agents: What Developers Need to Know,

Reference 42

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:45.718381Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:41.464750Z digest=sha256:6b96e5cec1fa7cdc4ec3e92fa07081c5fee4648a2d8f5b8edf76e09d8cb5593e

Observation 8d95a65c-3bfe-4bd2-80a0-d4b02a192e85 · outbound

This paper cites Malicious Versions of Nx and Some Supporting Plugins Were Published,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Malicious Versions of Nx and Some Supporting Plugins Were Published,

Reference 43

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:45.658413Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:41.511313Z digest=sha256:0db9e7ddb08efc2a50255825b73c219d3d66f48370d13a5af61baba74deab0f7

Observation be436981-7b99-4150-9824-21f084263a47 · outbound

This paper cites S1ngularity—What Happened, How We Responded, What We Learned,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario S1ngularity—What Happened, How We Responded, What We Learned,

Reference 44

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:45.611636Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:41.564749Z digest=sha256:b128726d9b4e0b754e999f51cb7ae515a51505c452e0b216264529deab24449f

Observation 3118362f-c399-4125-9f87-1379f6c537d1 · outbound

This paper cites s1ngularity’s Aftermath: AI, TTPs, and Impact in the Nx Supply Chain Attack,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario s1ngularity’s Aftermath: AI, TTPs, and Impact in the Nx Supply Chain Attack,

Reference 45

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:45.454870Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:41.614755Z digest=sha256:029d84813a6876c438ed952120a3724a296ac0fab640833063b063e444fa27ff

Observation 6965fcf9-ccdd-4b94-8957-ee503a9a4319 · outbound

This paper cites The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-12T00:27:41.664753Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T00:27:41.664753Z digest=sha256:d8e7b5b44b0ae061bc7865b0c9eb89e597cbf695fb8447ca5aba35b9e3f4c8e8

Observation 45473cc3-8b2c-48a0-aade-579c56545a91 · outbound

This paper cites Defeating Prompt Injections by Design.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Defeating Prompt Injections by Design

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-12T00:27:41.714833Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T00:27:41.714833Z digest=sha256:7c5cf01a6275cce20ea4bb3d9a9dbf3d6d35c7c30194300061c5212de4c3a2f7

Observation aafcb72c-b0e1-4e7e-8b3c-d1338d5b885a · outbound

This paper cites Progent: Securing AI Agents with Privilege Control.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Progent: Securing AI Agents with Privilege Control

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-12T00:27:41.761861Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T00:27:41.761861Z digest=sha256:7507a71e7948a7d5ea03b86e342cf2357fe579c314db183c15a73605f0735f6d

Observation c4b0cd2a-7794-4d12-9b9e-0bca5f34dd36 · outbound

This paper cites SimpleProbesCanCatchSleeperAgents,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario SimpleProbesCanCatchSleeperAgents,

Reference 49

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:45.293751Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:41.805242Z digest=sha256:7e07f23ef5856113b2442827e7042f7af42f35f53c69e5710f7bf38958e9ed49

Observation d6d80a9c-2279-4710-a40c-5e22bea4761c · outbound

This paper cites Latent Adversarial Training Improves Robustness to Persistent Harmful Behaviors in LLMs.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Latent Adversarial Training Improves Robustness to Persistent Harmful Behaviors in LLMs

Reference 50

Resolution
unresolved
no resolver link, observed 2026-08-12T00:27:41.854957Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T00:27:41.854957Z digest=sha256:a317a82c1e42bdacb2a7c4db7992ce1bb6bea345aefadbbd813bacb2b4e385ae

Observation 2bba3fb2-0c36-4420-8b6b-f06ebde0f077 · outbound

This paper cites Agentic Misalignment: How LLMs Could Be Insider Threats,.

Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Agentic Misalignment: How LLMs Could Be Insider Threats,

Reference 51

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T00:27:45.179187Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T00:27:41.904757Z digest=sha256:66e216a4bbb78094349788c722e25da59dd33dd135975b55bcea2ac564e9d56a

Pith citing papers

No inbound Pith citation observations are available.