MITRE ATLAS version 5.0.0 added a set of techniques for attacks on AI agents, including agent context poisoning of memory and threads, modifying agent configuration, credential theft from agent configuration, and exfiltration via agent tool invocation, and renamed LLM Plugin Compromise to AI Agent Tool Invocation. Version 5.1.0 (November 6, 2025) added agent-specific mitigations such as tool permission configuration and human-in-the-loop for agent actions.
Why it matters
ATLAS is the ATT&CK-style reference defenders use to map detections, and these versions made agent compromise a first-class part of it.
Key facts
As stated in the sources, with where to find them.
- 5.0.0 (2025-09-30) added AI Agent Context Poisoning (AML.T0080) with Memory and Thread sub-techniques, Modify AI Agent Configuration (T0081), Credentials from AI Agent Configuration (T0083), Discover AI Agent Configuration (T0084), and Exfiltration via AI Agent Tool Invocation (T0086); it also added a technique maturity field (feasible, demonstrated, realized).CHANGELOG, 5.0.0
- 5.1.0 (2025-11-06) added mitigations AML.M0026-M0031, including AI Agent Tools Permissions Configuration, Human In-the-Loop for AI Agent Actions, Restrict AI Agent Tool Invocation on Untrusted Data, and Memory Hardening; that release contained 84 techniques and 42 case studies.CHANGELOG, 5.1.0
Findings that cite this record
No tracked finding cites this record yet.
Key questions this bears on
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
Sources
Related records
Dec 9, 2025
Aug 6, 2025
Sep 11, 2026
Nov 17, 2024
Feb 17, 2026
Dec 8, 2025