Updates ◆ MITRE ATLAS™
Updates
All Updates
Oct 2025 Sep 2025 Aug 2025 Apr 2025 Mar 2025 Oct 2024 Mar 2024 Jan 2024 Oct 2023 Apr 2023 Feb 2023 Jan 2023 Oct 2022 Jul 2022 Mar 2022 Oct 2021 Jul 2021 Jun 2021
September 2025
Website v4.6.0
This website update includes new TTPs focused on Agentic AI developed in collaboration with Zenity and a new case study from a user submissions.
Data v5.0.0
This version of ATLAS data contains 1 matrix, 15 tactics, 66 techniques, 46 sub-techniques, 26 mitigations, and 33 case studies.
General
This version adds the new “Technique Maturity” field to the distributed ATLAS.yaml file. Technique maturity is defined as the level of evidence behind the technique’s use:
- Feasible – The technique has been shown to work in a research or academic setting
- Demonstrated – The technique has been shown to be effective in a red team exercise or demonstration on a realistic AI-enabled system
- Realized – The technique has been used by a threat actor in a real-world incident targeting an AI-enab
Techniques
- Added new techniques
- AI Agent Context Poisoning
- AI Agent Context Poisoning: Memory
- AI Agent Context Poisoning: Thread
- Modify AI Agent Configuration
- RAG Credential Harvesting
- Credentials from AI Agent Configuration
- Discover AI Agent Configuration
- Discover AI Agent Configuration: Embedded Knowledge
- Discover AI Agent Configuration: Tool Definitions
- Discover AI Agent Configuration: Activation Triggers
- Data from AI Services
- Data from AI Services: RAG Databases
- Data from AI Services: AI Agent Tools
- Exfiltration via AI Agent Tool Invocation
- LLM Prompt Injection: Triggered
- Updated existing techniques
- AI Agent Tool Invocation
- (previously LLM Plugin Compromise)
- AI Agent Tool Invocation
Case Studies
- Added a new case study
Release Statement
©2025 The MITRE Corporation. ALL RIGHTS RESERVED
Approved for public release. Distribution unlimited 25-02579-1.