Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 1504 threats

d-linknasos-command-injectioncginetwork-storagepublicly-disclosedremote-exploitiot

A critical OS command injection vulnerability affects multiple D-Link NAS devices (DNS-320L, DNS-327L, DNS-340L, DNS-345) through the usb_device.cgi CGI handler. The flaw allows unauthenticated remote attackers to execute arbitrary OS commands via the f_ups_ip parameter, and a public exploit is already available, making immediate exploitation highly likely.

captcha-bypassdual-use-researchmllmcomputer-visionmcpautomationdarknetAML.T0043AML.T0048Surface: Tool LayerPropagation: None

This is an academic research paper describing a hybrid AI architecture that combines a multimodal LLM with deterministic computer-vision tools via MCP to solve darknet-style CAPTCHAs with high accuracy. It is not an active exploit or an attack on AI agents/infrastructure itself, but a dual-use capability that could be repurposed to automate access to illicit darknet marketplaces or services. There is no vulnerability in an agent framework, protocol, or inter-agent trust boundary being described here.

indirect-prompt-injectioncapability-confinementagentdojodefense-researchtool-executionllm-agentsASI01 · Goal HijackingAML.T0051AML.T0054Surface: Tool LayerPropagation: Single Hop

This is a defensive research paper, not an active exploit or newly disclosed vulnerability. It describes SkillGuard, a harness-level enforcement mechanism that restricts an LLM agent's future capabilities once untrusted data from a tool/skill enters its context, mitigating indirect prompt injection attacks. Because it presents a mitigation and is evaluated against known benchmark attacks (AgentDojo), it does not represent a new threat to flag as high risk; severity is low from a threat-intelligence perspective, though the underlying attack class it defends against remains relevant.

researchzero-knowledge-proofsdata-minimisationMCPA2Adefensive-architectureattestationGDPRnot-an-exploitASI05 · Unsafe Code ExecutionSurface: Inter Agent CommsPropagation: None

This is a defensive research paper, not an active exploit or vulnerability disclosure. It proposes a system where AI agents exchange zero-knowledge proofs of policy compliance instead of raw data or unverifiable natural-language claims, reducing the prompt-injection-relevant attack surface of 'trust me, I complied' agent-to-agent communication. The authors themselves identify a residual limitation (proofs not bound to the system of record) and propose an enclave-attestation extension to address it.

indirect-prompt-injectioncomputer-use-agentsred-teamingvision-language-modeladaptive-adversaryresearchos-level-exploitationASI01 · Goal HijackingAML.T0051AML.T0054Surface: ModelPropagation: Single Hop

This is a research paper describing SIR, a red-teaming methodology that automatically discovers and refines indirect prompt injection attacks against computer-use agents (CUAs) like Claude Opus and Gemini. It demonstrates that adaptive, self-improving attack composition significantly increases attack success rates over static hand-written injections, revealing that current CUA safety benchmarks likely underestimate real-world risk. No active exploit or in-the-wild campaign is described; this is disclosed academic security research intended to improve defenses.

attestationdelegationprovenancemulti-agentA2AMCPkey-compromiseforensicsresearchASI06 · Memory PoisoningSurface: Inter Agent CommsPropagation: None

This is an academic research paper proposing a defensive attestation scheme to help verify which deployer produced given output bytes and whether cross-agent delegation edges were properly authorized in multi-agent AI systems. It is not describing an active exploit or vulnerability being exploited in the wild; rather it presents cryptographic designs (signed linked list, Merkle-chain, co-signed DAG) to detect unauthorized delegation claims, including after child-key compromise. The severity is low because the content is a proposed mitigation/verification framework, not a threat report.

prompt-injectionlong-horizon-agentstool-chain-hijackstealthy-attackresearchbenchmarkagentic-aiLLM-agentsASI01 · Goal HijackingAML.T0051AML.T0054Surface: PlannerPropagation: Single Hop

Researchers propose ECLIPSE, a framework that combines direct and indirect prompt injection to hijack long-horizon LLM agents (e.g., Codex, Claude Code) into executing multi-step malicious tool chains while evading detection. This is academic red-teaming research with a benchmark (LASE-Bench), not an observed in-the-wild exploit, but it demonstrates high attack success rates (up to 96.7%, 69.2% under defenses) against realistic multi-tool agent workflows.

SSRFMCPfetch-toolsMcpControllerunauthenticated-or-remotepublic-exploitunpatchedASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

The sdcb 'chats' application (up to v1.12.0) contains a server-side request forgery (SSRF) vulnerability in its MCP-related fetch-tools endpoint, allowing a remote attacker to make the server issue arbitrary HTTP requests. A public exploit exists and the vendor has not responded to disclosure, so this remains unpatched. Severity is moderate given the network-based attack vector but no confirmed data exfiltration or code execution in the description.

backdoorValleyRATSilver Foxadwarecode-signing-abuseantivirus-evasionRATChina

The Silver Fox threat actor is distributing the ValleyRAT backdoor concealed within a digitally signed Chinese desktop-wallpaper application called QN Wallpaper. By running under a trusted, signed process that users commonly whitelist in antivirus exclusions, the malware evades detection and establishes persistent remote access on infected hosts.

news-recapdigestno-technical-detailweekly-summarySurface: Human InterfacePropagation: None

This item is a weekly news roundup from The Hacker News that briefly mentions various unrelated stories, including a passing reference to 'an AI agent deciding its assigned task was optional.' It contains no technical details, indicators, or reproducible information about any specific agentic AI vulnerability or attack. As presented, this is not an actionable security threat but rather a link aggregator teaser.

insider-threatdprkfraudulent-employmentsocial-engineeringsanctions-evasionidentity-fraud

North Korean threat actors are expanding their long-running fraudulent IT worker employment scheme into new sectors, including healthcare and sales/marketing roles. This insider threat operation uses stolen or fabricated identities to secure remote employment, generating revenue for the DPRK regime while creating potential access and data exposure risks for employers.

outageavailabilityexchange-onlinemicrosoft365authentication-failureemail-delivery

Microsoft Exchange Online experienced a widespread service disruption causing authentication failures, email delays, and delivery failures for customers. This is an availability incident rather than a malicious attack, but it can disrupt business email operations and any downstream services relying on Exchange authentication or mail flow.

clickfixsocial-engineeringpowershellreverse-tunnelfake-captchainitial-accessagent-relevant

Microsoft has identified a new ClickFix variant called TerminalFix that uses fake Cloudflare CAPTCHA verification prompts on compromised websites to trick users into copy-pasting and executing malicious PowerShell commands in Windows Terminal. The attack establishes reverse tunnels for persistent remote access, enabling attackers to bypass network perimeter defenses.

deficryptocurrencyprice-oracle-manipulationflash-loancronossmart-contract-exploitblockchain

An attacker exploited a price-manipulation vulnerability in the Tectonic cryptocurrency lending platform on the Cronos blockchain, enabling fraudulent borrowing of approximately $74 million. The exploit forced validators to halt and restart the Cronos network to contain the incident, disrupting trading activity network-wide.

CISAKEVPaperCutauthentication-bypassunsafe-reflectionprint-managementfederalvulnerability-managementBOD-26-04

CISA has added two actively exploited PaperCut NG/MF vulnerabilities to its Known Exploited Vulnerabilities catalog, one involving missing authentication for a critical function and another involving unsafe reflection. These flaws pose significant risk to organizations running PaperCut print management software, with federal agencies required to remediate under BOD 26-04.

iaciamprivilege-escalationcloud-securitypulumiinfrastructure-as-codeagent-relevant

A critical privilege escalation vulnerability in hulumi (versions prior to v1.3.2) allows attackers with access to a documented IAM principal to abuse an overly permissive weekly integration policy. This enables creation of persistent, higher-privilege af-e2e-* roles in sandbox accounts, potentially leading to full account compromise.

iam-misconfigurationoidcawsgithub-actionssupply-chaincicd-securityagent-relevant

A critical flaw in @hulumi/policies before version 1.3.2 allows attackers to craft AWS IAM condition operators (ForAnyValue:StringLike) that evade security guardrails designed to detect overly permissive GitHub Actions OIDC trust policies. This enables attackers to establish stealthy, wildcard-based trust relationships between arbitrary GitHub repositories/workflows and AWS IAM roles, potentially leading to unauthorized cross-account access.

iotrouterbuffer-overflowrcetotolinkpublic-exploitunauthenticated

A critical stack-based buffer overflow vulnerability affects the TOTOLINK NR1800X router firmware, exploitable remotely via the setUploadSetting function without authentication. A public exploit exists, making this an immediate risk for internet-exposed devices.

d-linkrouteriotrcebuffer-overflownetwork-deviceunauthenticatedexploit-published

A critical remote code execution vulnerability exists in D-Link DIR-825M 1.1.8 routers, caused by a stack-based buffer overflow in the LTE Module Firmware Upgrade handler (formLtefotaUpgradeFibocom). An attacker can remotely manipulate the fota_url parameter to trigger the overflow, with a public exploit already available, making this an immediate risk to exposed devices.

buffer-overflowrouteriotremote-code-executionpublic-exploittendaboa-web-server

A critical, publicly disclosed vulnerability affects the Tenda HG10 router (firmware 300001138) via its Boa Web Server admin interface. The flaw allows remote, unauthenticated attackers to trigger a buffer overflow through the destNet parameter in the formIPv6Routing function, potentially leading to full device compromise. With a CVSS score of 10.0 and public exploit code available, active exploitation is highly likely.