Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-12T00:27:41.904757Z
Paper Citation Record · LEDGER
As of 15 August 2026, this Paper Citation Record lists 51 of 51 outbound references and 0 inbound Pith citation observations for arXiv:2608.08131.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-12T00:27:41.904757Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-15T06:32:42.880941+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links
A source-named dated measurement, never combined with another source.
Source: cited_works
51 of 51 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation 9b442563-4922-47c9-85cc-b4c8858ed49e · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 309e5243-f2cf-4c56-9691-9e60d0382dfd · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Poisoning Attacks on LLMs Require a Near-constant Number of Poison Samples,
Reference 2
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 956ce005-9583-4196-a8d1-79c6a4d7b282 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario BadAgent: Inserting and Activating Backdoor Attacks in LLM Agents,
Reference 3
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c2e9abdf-113b-4826-89be-c03f17de142f · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases,
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation 9dc28dc3-f513-470d-8c30-27ff1fdfcfe4 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario MemoryGraft: Persistent Compromise of LLM Agents via Poisoned Experience Retrieval,
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 02791b60-b0b8-4fb7-ab4d-e39b756280c3 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario MemMorph: Tool Hijacking in LLM Agents via Memory Poisoning
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 41fdd77f-ba8c-4212-8d29-5b27157f952e · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Your LLM Agent Can Leak Your Data: Data Exfiltration via Backdoored Tool Use,
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation 863a6853-327a-4029-befe-468aefb5cf7e · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario TrojanStego: Your Language Model Can Secretly Be A Steganographic Privacy Leaking Agent,
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c8d20b37-935f-480c-aac7-04448fb7bdf1 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario BackdoorLLM: A Comprehensive Benchmark for Backdoor Attacks and Defenses on Large Language Models,
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation d0603caf-fb05-4bc1-969b-7889702e85ce · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Not What You’ve Signed Up For: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection,
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b8f36127-fa5a-4672-aba4-460fd160a830 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 11
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 90e09d21-ab08-4f6f-bdc5-07fb1cc706b1 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario The UNSTOPPABLE Computer Virus is HERE...,
Reference 12
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation 28cf8109-f145-4469-93e5-b9c6cc521c6f · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Inhibitor Chip,
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation 5545133a-5795-413f-89f0-c74741f32cce · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 28840d74-d48d-450b-82b2-9c346948f179 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario AgentWorm: Self-Propagating Attacks Across LLM Agent Ecosystems
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4eaffcdb-2844-426b-8fa3-1d5e56c9b88c · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Agent Harness Plugins,
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation 56dbd000-8080-4d1a-9661-08e9fd42b32b · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Sandboxing,
Reference 17
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation f08083ad-512a-4fea-849c-1f0fcac7ae78 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario AI Agents Enable Adaptive Computer Worms
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6c56bdc4-213e-4f59-9a2b-b4bc8351a96b · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Unresolved cited work
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation 7e82f5d8-4a84-4efe-bcbf-ebe065d46d41 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario "Do Not Mention This to the User": Detecting and Understanding Malicious Agent Skills in the Wild
Reference 20
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2003454a-7efe-4ef3-8e63-347f64e90bb7 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario The Promptware Kill Chain: How Prompt Injections Gradually Evolved Into a Multistep Malware Delivery Mechanism,
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 19e34c6d-af88-4013-ac20-e54116b07705 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario The Trigger in the Haystack: Extracting and Reconstructing LLM Backdoor Triggers,
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0d6a537f-752f-4b1f-820e-cd9af7f1dfb4 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Unresolved cited work
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation 4d6b4293-8dd0-4f9f-9f70-1d5c1573410b · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Data Scientists Targeted by Malicious Hugging Face ML Models with Silent Backdoor,
Reference 24
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation 82a30afb-a12e-442f-ae1d-9ad47e106730 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Malicious ML Models Discovered on Hugging Face Platform,
Reference 25
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation 36629ec0-20e0-47c0-9741-962c43c5f3cd · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Vassilev, A
Reference 26
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 61973191-b00b-4015-97bc-139ac8f0acb1 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario OpenAI and Hugging Face Partner to Address Security Incident During Model Evaluation,
Reference 27
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation e055b162-a25d-45f2-a4b9-830aa4120bc4 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Third-Party Cyber Evaluations Involving OpenAI Models,
Reference 28
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation c788fb0b-dc77-430c-80c3-009f7d47f6b1 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Security Incident Disclosure—July 2026,
Reference 29
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation f4312c69-80d4-4956-9d95-51246b8ea4b5 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident,
Reference 30
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation aa867b46-3ae5-4694-a18a-155bf11a5e6a · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Investigating Three Real-World Incidents in Our Cybersecurity Evaluations,
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation 9f1afd4d-e07f-4588-bac1-3404a195b73a · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario CVE-2025-32711 Detail,
Reference 32
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation 9388d3cc-4e1f-4e0c-bcda-c6099742e650 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario CVE-2025-32711: AI Command Injection in M365 Copilot,
Reference 33
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation db074430-105e-4bec-b1c9-00adb4c43d7f · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Microsoft 365 Copilot: New Zero-Click AI Vulnerability Allows Corporate Data Theft,
Reference 34
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation 63282f5e-41cd-41f0-be87-99ca0a7db54c · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario ShadowLeak: A Zero-Click, Service-Side Attack Exfiltrating Sensitive Data Using ChatGPT’s Deep Research Agent,
Reference 35
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation 275b5edd-67ca-48af-8abb-07aa01d72b09 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario MCP Security Notification: Tool Poisoning Attacks,
Reference 36
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation 2c918cec-6937-4f0f-9753-7749515e1915 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Memory Injection Attacks on LLM Agents via Query-Only Interaction,
Reference 37
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9d260514-6c10-4e62-a59f-3dc253b05baf · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Hidden in Memory: Sleeper Memory Poisoning in LLM Agents
Reference 38
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ece7a236-3d8c-492c-93d0-0049317b5277 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario From Untrusted Input to Trusted Memory: A Systematic Study of Memory Poisoning Attacks in LLM Agents
Reference 39
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 72c09d27-fabc-483a-99d9-d59ee8df0cdb · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Malicious Script Injected into Amazon Q Developer for Visual Studio Code Extension,
Reference 40
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation 206df232-0946-48f4-9c81-a7f626d399b0 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario The Shai-Hulud 2.0 npm Worm: Analysis, and What You Need to Know,
Reference 41
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation 16557417-335a-49e2-91ed-a3b236408ba3 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Mini Shai-Hulud Targets AI Coding Agents: What Developers Need to Know,
Reference 42
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation 8d95a65c-3bfe-4bd2-80a0-d4b02a192e85 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Malicious Versions of Nx and Some Supporting Plugins Were Published,
Reference 43
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation be436981-7b99-4150-9824-21f084263a47 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario S1ngularity—What Happened, How We Responded, What We Learned,
Reference 44
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation 3118362f-c399-4125-9f87-1379f6c537d1 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario s1ngularity’s Aftermath: AI, TTPs, and Impact in the Nx Supply Chain Attack,
Reference 45
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation 6965fcf9-ccdd-4b94-8957-ee503a9a4319 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections
Reference 46
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 45473cc3-8b2c-48a0-aade-579c56545a91 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Defeating Prompt Injections by Design
Reference 47
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation aafcb72c-b0e1-4e7e-8b3c-d1338d5b885a · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Progent: Securing AI Agents with Privilege Control
Reference 48
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c4b0cd2a-7794-4d12-9b9e-0bca5f34dd36 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario SimpleProbesCanCatchSleeperAgents,
Reference 49
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
Observation d6d80a9c-2279-4710-a40c-5e22bea4761c · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Latent Adversarial Training Improves Robustness to Persistent Harmful Behaviors in LLMs
Reference 50
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2bba3fb2-0c36-4420-8b6b-f06ebde0f077 · outbound
Compositional Threat Analysis of Latent Compromise in LLM Agent Systems: The Order 66 Scenario Agentic Misalignment: How LLMs Could Be Insider Threats,
Reference 51
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.
No inbound Pith citation observations are available.