Guidelines  ·  2026-09-24

MITRE ATLAS content release v2026.09 (new agentic/multimodal techniques + AI Honeypots mitigation)

GuidelinesHigh impactGlobal
MITRE ATLAS published content release v2026.09 (release tag updated ~15 September 2026; current throughout the reporting week per the atlas-data repo atom feed). The release adds 10 new techniques/sub-techniques incl. Triggers in Multimodal Inputs (AML.T0129), AI Agent Response Biasing (AML.T0130), Crafted AI Assistant Links (AML.T0131), Misconfigured or Publicly Exposed AI Services (AML.T0132), Discover AI Agent Runtime Capabilities (AML.T0133), AI Targeted Cloaking (AML.T0134), plus active-scanning sub-techniques for AI targets; adds mitigation AML.M0039 'AI Honeypots' and updates Generative AI Guardrails; adds case study AML.CS0072 (AI Recommendation Poisoning via Crafted AI Assistant Links) and updates ShadowRay and agent-tool exfiltration studies. ATLAS now holds 16 tactics, 120 techniques, 88 sub-techniques, 40 mitigations and 73 case studies.
ATLAS is the de-facto adversarial ML/agentic threat taxonomy that red teams and CISA-style advisories map to. The September release extends coverage to the two dominant 2026 attack vectors — multimodal/indirect injection and exposed agent infrastructure — and codifies AI honeypots as a defence, giving practitioners new technique IDs to model detections and emulations against.
Update threat models, detection rules and red-team plans against the new AML.T**** IDs (esp. multimodal-injection and exposed-AI-services techniques); map MCP-server exposure findings to AML.T0132; consider AI honeypots in cyber-deception design.
MITRE ATLAS atlas-data release v2026.09
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →