Executive Summary
In June 2026, the Microsoft AI Red Team released an updated taxonomy of failure modes in agentic AI systems, building upon their initial April 2025 publication. This revision introduces seven new failure mode categories, expands mitigation strategies, and incorporates insights from a year of red team engagements. Key developments prompting this update include the rapid mainstream adoption of open-source agentic frameworks like OpenClaw, which, upon its January 2026 launch, revealed significant vulnerabilities such as CVE-2026-25253—a critical WebSocket hijacking flaw. Additionally, the maturation of the Model Context Protocol (MCP) ecosystem has led to an increase in vulnerabilities, with 99 CVEs reported in 2025 alone. The transition of computer-use agents from research to production has further exposed novel attack surfaces, necessitating a comprehensive reevaluation of existing security frameworks. (microsoft.com)
This update is particularly relevant as agentic AI systems become more integrated into critical domains, amplifying the potential impact of their failure modes. The introduction of new categories like Agentic Supply Chain Compromise and Goal Hijacking underscores the evolving threat landscape. Organizations must proactively adapt their security measures to address these emerging risks, ensuring the safe deployment and operation of agentic AI systems in increasingly complex environments.
Why This Matters Now
The rapid adoption of agentic AI systems in critical sectors has introduced new vulnerabilities, as evidenced by the recent CVE-2026-25253 in OpenClaw. Organizations must urgently update their security frameworks to address these emerging threats and ensure the safe deployment of AI technologies.
Attack Path Analysis
The adversary exploited vulnerabilities in the OpenClaw agentic framework to gain initial access, then escalated privileges by manipulating the Model Context Protocol (MCP) to execute unauthorized commands. They moved laterally by compromising interconnected agents, established command and control through AI-driven architectures, exfiltrated sensitive data via compromised plugins, and ultimately disrupted operations by altering agent behaviors.
Kill Chain Progression
Initial Compromise
Description
Exploited vulnerabilities in the OpenClaw agentic framework, such as CVE-2026-25253, to gain unauthorized access.
Related CVEs
CVE-2026-25253
CVSS 8.8A one-click remote code execution vulnerability via WebSocket hijacking in OpenClaw.
Affected Products:
OpenClaw OpenClaw – 1.0.0
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Supply Chain Compromise
Phishing
Valid Accounts
Modify Authentication Process
Application Layer Protocol
Obfuscated Files or Information
Command and Scripting Interpreter
Account Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Maintain an inventory of system components
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Critical exposure to agentic AI vulnerabilities including supply chain compromise, goal hijacking, and session contamination affecting software development pipelines and autonomous systems.
Information Technology/IT
High risk from MCP protocol vulnerabilities, zero-trust architecture gaps, and HitL bypass attacks compromising enterprise AI deployments and cloud security frameworks.
Financial Services
Severe impact from inter-agent trust escalation and capability disclosure threats enabling unauthorized transactions, data exfiltration, and regulatory compliance violations across banking systems.
Health Care / Life Sciences
Major vulnerability to computer-use agent visual attacks and memory poisoning compromising patient data security, clinical decision systems, and HIPAA compliance requirements.
Sources
- Updating the taxonomy of failure modes in agentic AI systems: What a year of red teaming taught ushttps://www.microsoft.com/en-us/security/blog/2026/06/04/updating-taxonomy-failure-modes-agentic-ai-systems-year-red-teaming-taught-us/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it embeds security directly into the cloud fabric, potentially limiting the attacker's ability to exploit vulnerabilities and move laterally within the environment.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit vulnerabilities in the OpenClaw agentic framework may have been constrained, reducing the likelihood of unauthorized access.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges through MCP manipulation could have been limited, reducing the scope of unauthorized command execution.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally between interconnected agents may have been constrained, limiting the spread of the compromise.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish and maintain command and control channels could have been limited, reducing the effectiveness of automated attacks.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data may have been constrained, reducing the risk of data loss.
The attacker's ability to disrupt operations through agent manipulation could have been limited, reducing the overall impact of the attack.
Impact at a Glance
Affected Business Functions
- AI System Operations
- Software Development
- Security Monitoring
Estimated downtime: 7 days
Estimated loss: $500,000
API keys and credentials of over 1,800 exposed instances.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and limit lateral movement.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation of known vulnerabilities.
- • Utilize Multicloud Visibility & Control to monitor and manage AI-driven command and control architectures.
- • Apply Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
- • Establish Threat Detection & Anomaly Response mechanisms to identify and respond to adversarial manipulations of agent behaviors.



