Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 542 threats

ICSmedical-devicehardcoded-credentialsbluetoothCWE-798healthcareIoT

Flow Neuroscience FL-100 (and rebranded Halo Neuroscience FL-100) tDCS devices contain an undocumented hard-coded credential shared across all units, allowing any attacker within Bluetooth range to bypass authentication. Exploitation could let an attacker arbitrarily manipulate brain stimulation parameters and override built-in safety limits, posing direct physical harm risk to patients.

macOSauthentication-bypasscryptominingmoneroexploit-code-publicagent-relevant

Hackers are actively exploiting a macOS Screen Sharing authentication bypass vulnerability following the release of public exploit code, according to the Netherlands' NCSC. Attackers use the flaw to gain unauthorized remote access to macOS systems and deploy Monero (XMR) cryptocurrency miners. Organizations running exposed macOS Screen Sharing services are at immediate risk of unauthorized access and resource hijacking.

icsotbuilding-automationxsscwe-79johnson-controlsmetasyscisa-advisory

A high-severity persistent cross-site scripting vulnerability affects Johnson Controls Metasys building automation systems (versions 12–15), allowing a low-privilege user to inject a malicious payload via a crafted URL that executes in other users' sessions, including administrators. This could lead to session hijacking and unauthorized access within critical infrastructure environments such as commercial facilities, manufacturing, energy, and government sites. No public exploitation has been reported to CISA at this time, but patches or vendor guidance are available for supported versions.

path-traversalpresigned-urlidormulti-tenancyobject-storagetrigger-devcross-tenant-accessASI04 · Agentic Supply ChainSurface: Tool LayerPropagation: Single Hop

Trigger.dev, a platform for managing AI agent workflows, contains a path traversal vulnerability in its packet/object-store signing logic that lets an authenticated caller with any valid environment API key generate presigned URLs pointing into other tenants' storage. This allows reading or overwriting another tenant's task payloads, breaking tenant isolation. The vendor has fixed this in 4.5.0-rc.5.

MCPpath-traversaltrust-boundarysubprocess-executionclaude-codesupply-chainlocal-privilegedirectory-spoofingASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

The Cortex MCP server incorrectly trusts the CLAUDE_PROJECT_DIR environment variable to identify a legitimate Cortex source checkout, using only two file-presence checks as validation. An attacker who convinces a victim to open a malicious repository as their active project in Claude Code can plant these marker files and cause Cortex's open_visualization tool to execute an arbitrary attacker-controlled Python script with the victim's local user privileges.

ransomwareEDR-evasionsafe-modedata-exfiltrationakiradouble-extortion

An Akira ransomware affiliate compromised a target network and rebooted a system into Safe Mode with Networking to disable endpoint detection and response (EDR) protections. The attacker successfully exfiltrated data but failed to deploy the encryption payload, resulting in a partial (extortion-only) compromise rather than full ransomware impact.

spywaremercenary-spywaremobile-securityiosnation-statesurveillancetargeted-attack

Apple has issued new 'Threat Notification' alerts warning select iPhone users that they have been targeted by mercenary spyware attacks. These notifications, part of Apple's ongoing threat intelligence program, indicate highly targeted, sophisticated attacks typically associated with commercial spyware vendors like NSO Group or Intellexa rather than broad-based malware campaigns.

ICSSiemensprivilege-escalationpath-traversalvulnerabilityCVECISA-advisorylicensing-server

Siemens License Server (SLS) versions prior to 5.1 and 5.3 are affected by two vulnerabilities: an insecure sudoers policy enabling local privilege escalation to root, and a path traversal flaw allowing remote unauthenticated attackers to read arbitrary files. Siemens has released patched versions and CISA has published an advisory recommending immediate updates.

ICSCISA-advisorySiemensout-of-bounds-readfile-parsingCVE-2026-64629critical-manufacturing

Siemens Parasolid, a 3D geometric modeling kernel used in CAD/CAM/CAE software across critical manufacturing, contains an out-of-bounds read vulnerability (CVE-2026-64629) triggered when parsing malformed X_T files. Successful exploitation could crash the application or allow arbitrary code execution in the context of the current process. Siemens has released patched versions (V38.0.235 and V38.1.230) and users are advised to update.

oauthaccount-takeoverauthentication-bypassemail-verificationidentity-spoofingtrigger.devagent-platformASI08 · Cascading FailuresSurface: Human InterfacePropagation: Single Hop

Trigger.dev, a platform for managing AI agent workflows, fails to check Google's email_verified flag during OAuth login, allowing an attacker to create a Google account with an email matching an existing victim's account and take it over. Because Trigger.dev orchestrates AI agent deployments, compromising an account gives an attacker control over that user's agents, workflows, secrets, and API keys. This is a classic identity-spoofing/authentication flaw rather than a novel agentic attack, but it has serious downstream impact on agent supply-chain trust.

prototype-pollutionmulti-tenantdenial-of-serviceprivilege-abuseai-agent-platformtrigger.devjsonheropathASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

A vulnerability in Trigger.dev, a platform for orchestrating managed AI agents and workflows, allows any authenticated tenant to pollute Object.prototype in the shared webapp process via a metadata update API. This corrupts database queries and metrics across all tenants and can break worker authentication or crash the process, resulting in a cross-tenant denial-of-service condition. The issue is fixed in version 4.5.6.

MCPSSRFmcp-rdf-explorerunpatchedpublic-exploitserver-side-request-forgeryASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

An MCP server component (mcp-rdf-explorer 1.0.0) contains a server-side request forgery vulnerability in its explore_url tool function, allowing a remote attacker to make the server issue arbitrary HTTP requests by manipulating the url argument. A public exploit exists and the vendor has not responded to disclosure, leaving the issue unpatched.

SSRFMCPinput-validation-bypassIPv6loopbackIP-normalizationfetch-toolASI05 · Unsafe Code ExecutionAML.T0053Surface: Tool LayerPropagation: Single Hop

The auth-fetch-mcp server, which lets AI assistants fetch authenticated web content, has a flawed SSRF blocklist that fails to catch IPv4-mapped IPv6 loopback addresses in their hex-normalized form. An attacker who can influence the URL passed to the fetch tool (directly or via prompt injection) can reach internal loopback services that the security control was explicitly designed to block. This is exploitable out-of-the-box with no special configuration.

AI-securityLLMreasoning-APIsession-replaycredential-exposureAPI-key-leakageagent-relevantOpenAIAnthropicGoogle

Researchers disclosed a flaw in how OpenAI, Anthropic, and Google encode and carry hidden chain-of-thought reasoning between API calls, allowing encrypted reasoning objects from one session to be replayed into another session. This cross-session replay allowed weaker models to decode or expose internal reasoning content from stronger models, including sensitive data such as API keys and passwords captured in session logs.

androidmobile-malwarenfc-relayratbanking-trojancredit-card-fraudfraud

A newly identified Android malware campaign pairs a novel NFC relay tool called WindRelay with the established SpyNote RAT to capture and relay victims' live credit card data to attackers in real time. The combo also facilitates taking out fraudulent loans using stolen victim information, indicating a financially motivated criminal operation targeting mobile banking users.

data-theftsalesforceservicenowmisconfigurationcustomer-portalexposed-dataanonymous-accesssaas-security

A campaign dubbed 'City-Forum' is using custom tooling to systematically harvest data exposed to anonymous/unauthenticated users through misconfigured Salesforce Experience Cloud sites and ServiceNow customer portals. The attackers exploit overly permissive guest-user access controls rather than a software vulnerability, allowing bulk extraction of sensitive records without authentication.

MCPpath-traversalarbitrary-file-readcredential-exposureconfluencejiratool-poisoning-vectorprompt-injection-vectorASI05 · Unsafe Code ExecutionAML.T0053AML.T0025Surface: Tool LayerPropagation: Single Hop

The MCP Atlassian server before version 0.22.0 fails to validate file paths passed to its confluence_upload_attachment tool, allowing an authenticated MCP client (or an AI agent manipulated via untrusted content) to read arbitrary files on the server and exfiltrate them as Confluence attachments. This can expose sensitive server environment variables like CONFLUENCE_API_TOKEN, turning a routine file-upload feature into a credential theft and data exfiltration primitive.

chain-of-thoughtreasoning-extractionencrypted-tokensjailbreakcross-model-replayprompt-prefillopenaianthropicgooglekey-reuseASI02 · Tool MisuseAML.T0051AML.T0048Surface: ModelPropagation: Single Hop

Researchers found that encrypted reasoning/chain-of-thought blocks returned by proprietary LLM APIs (OpenAI, Anthropic, Google) used the same encryption key across models within a family, allowing an attacker to capture a strong model's encrypted reasoning trace and replay it into a weaker sibling model to trick it into decrypting and outputting the plaintext hidden reasoning. This exposed internal chain-of-thought content never intended for end users, including a related technique to induce models into reasoning about data exfiltration steps. Vendors have since patched the flaw, reducing current risk, but it demonstrates a real and previously unknown extraction/jailbreak vector.

prompt-injectionconfused-deputySSRFSQLiXSSSSTIcommand-injectionIDORCSRFXXELLM-integrated-appsresearchASI05 · Unsafe Code ExecutionAML.T0051AML.T0054Surface: Tool LayerPropagation: Single Hop

This is an academic research paper (not an active exploit report) systematizing a class of attacks called 'LLM2X', where attacker-controlled input passed through an LLM in a tool-calling or agentic pipeline is transformed and then reaches traditional web backend sinks (SQL, shell, templates, XML parsers, HTTP clients). The LLM acts as a confused deputy, laundering malicious input into classic vulnerabilities like SQLi, XSS, SSRF, SSTI, and command injection. The authors validate this experimentally with a case study (TicketOracle) showing SSRF susceptibility varies significantly across seven different LLMs.

patch-tuesdaymicrosoftwindowszero-dayvulnerability-managementagent-relevant

Microsoft's August 2026 Patch Tuesday addresses nearly 398 vulnerabilities across Windows and supported software, including one flaw already under active exploitation and two others that were publicly disclosed prior to patching. Organizations should prioritize patching the actively exploited vulnerability to reduce risk of compromise.