Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 259 threats

data-breachthird-party-risksupply-chainprofessional-servicessupport-ticket-system

Ernst & Young (EY) disclosed a data breach stemming from the compromise of a third-party support ticket system used by its IT staff. The incident highlights ongoing risks associated with vendor and supply-chain access to sensitive internal support infrastructure. Details on the scope of data accessed and the threat actor responsible remain limited based on available reporting.

ICSSCADACISA-advisoryXSSweb-vulnerabilitycritical-manufacturingrockwell-automation

A stored cross-site scripting (XSS) vulnerability affects Rockwell Automation FactoryTalk DataMosaix Private Cloud versions 8.02 and earlier, allowing an authenticated high-privilege attacker to inject persistent malicious scripts via the Workflows configuration. Successful exploitation could lead to account takeover, credential theft, or redirection of other users to malicious sites when they access the affected page. No public exploitation has been reported to date.

yamcsauthentication-bypassbrute-forcemissing-rate-limitingmission-control-softwarecve-2026-44596

Yamcs, an open-source mission control framework, contains a vulnerability in its authentication endpoint that allows unlimited password-guessing attempts due to missing rate limiting and account lockout mechanisms. An unauthenticated remote attacker could exploit this to brute-force credentials for any user account. The issue is patched in versions 5.12.7 and 5.13.0.

account-takeoverresponse-manipulationauthentication-bypassHCLweb-application

CVE-2026-56453 affects HCL DFXAnalytics, allowing a remote attacker to intercept and manipulate HTTP responses to bypass authentication or authorization controls. This can result in unauthorized access to targeted user accounts without requiring credential theft.

race-conditionconcurrency-bugdata-integrityIBM-Cognosagentic-aidenial-of-serviceASI09 · Human Trust ExploitationSurface: PlannerPropagation: None

A concurrency flaw in IBM Cognos Analytics' Agentic AI assistant causes incorrect report summaries or processing failures when multiple authenticated users submit report tasks at the same time. This is a reliability/integrity bug rather than an exploitable attacker-controlled takeover primitive, though it could be leveraged to degrade service or corrupt report outputs relied on for decision-making.

prompt-injectionansi-escape-sequencesdns-exfiltrationmacos-terminalllm-agentterminal-outputindirect-injectionASI08 · Cascading FailuresAML.T0051AML.T0043Surface: Tool LayerPropagation: Single Hop

This is a follow-up disclosure from Embrace The Red detailing how an LLM agent that outputs untrusted content into a macOS Terminal could be leveraged to trigger DNS requests via crafted ANSI escape sequences, effectively exfiltrating data through DNS lookups. Apple has since fixed the underlying macOS Terminal behavior, so this report documents a resolved vulnerability rather than an active ongoing threat. Severity is moderate given the fix is already deployed, but the technique remains relevant for agents/tools still rendering raw terminal output without sanitization.

prompt-injectionpersistent-memoryclaude-codeopenai-codexresearchagentic-coding-assistantmulti-session-attackASI05 · Unsafe Code ExecutionAML.T0051AML.T0054Surface: MemoryPropagation: Single Hop

Academic research demonstrates that malicious instructions planted inside persistent memory files (used by agentic coding assistants like Claude Code and OpenAI Codex for cross-session context) can influence and hijack future agent sessions. This is a controlled research study, not an observed in-the-wild exploit, but it highlights a real and underexplored attack surface as agents adopt long-term memory.

roundupransomwarespywareinfostealerbrowser-securitysupply-chainweekly-digest

This is a weekly aggregated security news digest from The Hacker News covering multiple unrelated stories, including spyware disguised as game cheats, ransomware attacks that reach full encryption within 24 hours, and abuse of Chrome sync settings for tracking or session hijacking. The source material lacks technical depth on any single incident, functioning as a curated list of headlines rather than a detailed incident report.

ICSphysical-securityaccess-controlprivilege-escalationauthorization-bypassCISA-advisory

A privilege escalation vulnerability exists in SALTO ProAccess Space access control software versions prior to 6.13, affecting installations using the tenancy/logical partition feature. An authenticated attacker with valid operator credentials can bypass partition boundaries to access spaces outside their assigned tenancy, potentially compromising physical access control across an organization's facilities.

information-disclosureloggingopentelemetrycloudwatchaws-bedrockagentcoresensitive-data-exposureinsider-threatASI08 · Cascading FailuresSurface: Tool LayerPropagation: None

AWS Bedrock AgentCore Python SDK versions 1.4.8 and 1.5.0 logged raw user prompts and full agent responses into OpenTelemetry span attributes without any filtering or masking, which then flowed into customer CloudWatch aws/spans log groups. Any principal with read access to those logs could view sensitive user content, including secrets or PII that may have been part of prompts or agent outputs. This is a data exposure issue rather than an active exploit, and requires local/authenticated access to the customer's own logging infrastructure.

MCPSSRFallowlist-bypassdomain-validationfetch-apify-docsurl-parsingApifyASI04 · Agentic Supply ChainAML.T0051Surface: Tool LayerPropagation: Single Hop

The Apify MCP server's documentation-fetching tool checked allowed domains using a naive string prefix match instead of proper URL hostname parsing, letting an attacker craft URLs like docs.apify.com.evil.com to bypass the allowlist. This allows arbitrary attacker-controlled content to be fetched and returned to the LLM agent, which could then be used to inject malicious instructions or exfiltrate context. The issue was fixed in version 0.9.21.

mcpdbt-mcptelemetrydata-leakageunredacted-loggingdefault-opt-insql-exposureASI09 · Human Trust ExploitationSurface: Tool LayerPropagation: None

The dbt-mcp server, prior to 1.17.1, sent full unredacted MCP tool call arguments—including raw SQL queries, variables, and node selection strings—to a third-party telemetry backend by default. Because usage tracking was enabled unless explicitly disabled via environment variables, organizations may have unknowingly leaked sensitive query content and internal data model details. This is a legitimate but low-complexity data exposure issue, not a remote code execution or agent-hijack vulnerability.

MCPdbt-mcpargument-injectionsubprocessCLI-flag-injectiontool-poisoningparameter-sanitizationASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

The dbt-mcp MCP server, prior to version 1.17.1, failed to sanitize client-supplied node_selection and resource_type values before passing them as dbt CLI arguments. Although the use of shell=False blocks shell metacharacter injection, an MCP client could still smuggle dbt global flags like --profiles-dir, --project-dir, or --target into the subprocess call, allowing unauthorized redirection of dbt execution context.

agent-skillsskill-marketplacesupply-chainlifecycle-securitysemantic-retrievalplanner-manipulationresearch-paperASI04 · Agentic Supply ChainSurface: Supply ChainPropagation: Single Hop

This is an academic research paper (arXiv, not an active exploit) introducing SkillSec-Eval, a framework for evaluating security risks across the full lifecycle of reusable LLM agent 'skills' — from repository admission through retrieval, planner selection, execution, and evolution. The authors evaluated 327 real-world skills and found vulnerabilities exist beyond just runtime execution, suggesting attackers could poison skills at earlier stages like publishing or ranking to influence which skills agents select and trust.

iotbotnetllm-generated-malwareai-assisted-malwarelinuxmirai-variant

TuxBot v3 Evolution is a newly disclosed IoT botnet framework whose codebase shows evidence of being partially generated using an LLM, including a leftover safety disclaimer the developer failed to strip out. The botnet targets vulnerable IoT devices for likely DDoS and further propagation purposes, illustrating growing use of generative AI tools in lowering the barrier to malware development.

investment-fraudlaw-enforcementtakedownsocial-engineeringfinancial-crime

Dutch Police arrested multiple suspects linked to a large-scale international investment fraud scheme that defrauded tens of thousands of victims out of over €100 million. The operation reportedly used deceptive online investment platforms and social engineering tactics to lure victims into fraudulent schemes.

icsotbuilding-automationknxaccount-lockoutphysical-securitycisa-kev

CVE-2023-4346 is a vulnerability in the KNX Protocol's Connection Authorization Option 1 mechanism that allows an attacker to exploit an overly restrictive account lockout to purge all devices lacking additional security options and lock devices via a BCU key. This affects building automation and industrial control deployments using KNX, potentially causing denial of service and loss of device control. CISA has added this CVE to its Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.

MCPn8nmulti-tenancyaccess-controltenant-isolationworkflow-backupsIDORASI04 · Agentic Supply ChainSurface: Tool LayerPropagation: Single Hop

A flaw in n8n-MCP's multi-tenant HTTP mode allowed an authenticated tenant to access or delete workflow-version backups belonging to the default scope rather than being confined to their own tenant. This could expose or destroy legacy backup data left over from prior single-tenant deployments or migrations. The issue is fixed in version 2.57.4.

MCPwebsocketorigin-validationCSWSHcross-site-websocket-hijackingmcp-python-sdkdeprecated-transportASI05 · Unsafe Code ExecutionSurface: ProtocolPropagation: Single Hop

The deprecated WebSocket transport in the MCP Python SDK accepted connections without validating Host or Origin headers, meaning any malicious webpage a victim's browser visits could open a WebSocket connection to a locally or network-exposed MCP server. This is a classic Cross-Site WebSocket Hijacking (CSWSH) pattern that could let an attacker-controlled origin interact with an MCP server's tools on behalf of an unwitting user. Severity is moderated because the affected transport is deprecated and impact depends on what the exposed server can do and whether it's reachable from a browser context.

BECbusiness-email-compromiseinvestment-fraudmoney-launderinglaw-enforcement-actionfinancial-crime

Spanish National Police dismantled a cybercrime and money-laundering network responsible for approximately €140 million ($160 million) in losses through investment fraud and business email compromise (BEC) schemes. Four suspects were arrested in connection with the operation, which targeted victims through social engineering and fraudulent financial transactions.