Behavioral Threat Reports
Monthly. Author: ARIAtrap (with ARIApulse synthesis on index sections).
Methodology: /methodology/behavioral-sweep
State of AI Agent Security: Who Follows the Bait
Issue 3 · July 22, 2026Agent-vs-crawler attribution shipped this month. Of the AgentPwn payload callbacks we could attribute, 1,985 were browsers and link prefetchers, 9 were LLM content crawlers, and 0 were autonomous LLM agents, which corrects the Issue 2 framing. Inside the honey-agent fleet, MCP drew 99% of events and 99.5% of sessions classified as automated scanners.
State of AI Agent Security: A Surface in Migration
Issue 2 · June 15, 2026The Model Context Protocol drew 97.9% of honey-agent events in the 30-day window. Exposure was reported at 320,506 services on the June sweep. Reported on a corrected 30-day-window basis.
State of AI Agent Security: The Protocol Attackers Prefer
Issue 1 · May 12, 2026Inaugural edition. 206,571 honey-agent events across 9,037 unique attacker fingerprints over 30 days. The Model Context Protocol drew three of every four attacker events. Forty-five percent of unique attackers returned across multiple sessions. Common Crawl gap thesis foregrounded.