Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 1504 threats

clickfixsocial-engineeringpowershellwindows-terminalreverse-tunnelbackdoorfake-captchainitial-accessagent-relevant

Microsoft disclosed a new ClickFix-style social engineering campaign, dubbed TerminalFix, that uses fraudulent Cloudflare CAPTCHA pages to trick users into executing malicious commands in Windows Terminal or PowerShell instead of the traditional Run dialog. Successful execution deploys a reverse-tunnel backdoor granting attackers persistent remote access to the compromised host. This shift to terminal-based execution increases the likelihood that victims run more complex, capability-rich payloads compared to earlier ClickFix variants.

browser-extensionchrome-web-storeedgecryptocurrency-theftclickfixmalware-frameworkdata-exfiltrationagent-relevant

Multiple malicious extensions distributed through the Chrome Web Store and Microsoft Edge Add-ons store delivered a modular malware framework capable of stealing cryptocurrency, browsing history, and other sensitive data. The campaign also deployed ClickFix-style social engineering lures to trick users into executing further malicious commands, expanding the attack's reach beyond simple browser compromise.

infostealersession-hijackingcredential-theftAI-account-abuseagent-relevantLLM-abusetoken-theft

Anthropic has warned that infostealer malware infecting user PCs is exfiltrating active Claude session tokens, allowing attackers to hijack accounts and consume victims' paid usage. This represents a growing trend of infostealers specifically targeting AI service credentials and session cookies rather than just traditional banking or email accounts.

data-breachdata-theftaviationcustomer-dataextortion

The threat actor group FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group (MAG), including detailed customer, booking, and travel records. BleepingComputer validated at least one traveller's record from leaked samples, suggesting the breach scope exceeds what MAG initially disclosed.

iotroutermemory-corruptionremote-code-executionpublicly-disclosedtotolink

A critical remotely exploitable memory corruption vulnerability exists in TOTOLINK A720R routers running firmware 4.1.5cu.630_B20250509, affecting the setMacFilterRules function within cstecgi.cgi. The flaw is triggered via manipulation of the 'desc' argument in MAC filtering rules and has been publicly disclosed with exploit details available, increasing the likelihood of active exploitation.

wordpressauthentication-bypassprivilege-escalationplugin-vulnerabilitycms

The MyHome Core plugin for WordPress (versions up to 4.4.5) contains an authentication bypass vulnerability that allows unauthenticated attackers to hijack unconfirmed user accounts, including administrator accounts, under specific configuration conditions. Successful exploitation grants full administrative access to the WordPress site, enabling complete site takeover.

wordpresswoocommerceprivilege-escalationplugin-vulnerabilityunauthenticatedweb-application-security

The Custom User Registration Fields for WooCommerce WordPress plugin (up to v2.2.3) allows unauthenticated attackers to escalate privileges to Administrator by manipulating the checkout request. The vulnerability arises from unsanitized user-controlled role data being passed directly into WordPress's role assignment function, enabling full site takeover during account registration at checkout.

directory-traversalpath-traversalfile-managerrce-potentialweb-applicationagent-relevant

Cloud Commander before version 19.20.2 contains a critical directory traversal vulnerability in its REST file-operation and markdown endpoints, allowing unauthenticated or minimally privileged attackers to read, write, move, or copy files outside the configured root directory. With a CVSS score of 9.8, this flaw can lead to full system compromise, data exfiltration, or arbitrary file overwrite.

agent-relevantmcpargocdunauthenticated-accessgitopsprivilege-escalationapi-token-exposure

argocd-mcp version 0.8.0 exposes its HTTP transport on all network interfaces without enforcing authentication on incoming MCP sessions, even when an ARGOCD_API_TOKEN is configured. Any attacker with network access to the listener can invoke the full MCP tool surface, leveraging the operator's stored Argo CD token to create applications, trigger syncs, and modify GitOps resources without any credentials of their own.

chatgptproduct-announcementno-threatinformationalSurface: Human InterfacePropagation: None

This article is a descriptive walkthrough by Simon Willison explaining OpenAI's new 'ChatGPT Work' feature set, covering model selection, code execution, browser access, and sub-agents. It contains no evidence of a vulnerability, exploit, or malicious activity involving AI agents.

ownCloudCISA-KEVCVE-2023-49105pre-authenticationwebdavchina-nexuscritical-infrastructurenuclear-sectordata-theft

A critical pre-authentication vulnerability in ownCloud (CVE-2023-49105, CVSS 9.8) was actively exploited by a suspected Chinese-speaking threat actor to breach a nuclear research institute in the Philippines and exfiltrate sensitive records. CISA has added the flaw to its Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation and prompting mandated remediation for federal agencies.

androidprivacyencryptionechtlsmobile-securitydefensive-feature

This is not a threat but a defensive feature announcement: Google's Android 17 introduces OS-wide support for Encrypted Client Hello (ECH), preventing network providers and on-path observers from seeing which websites a device connects to. The update also includes additional protections against cellular network vulnerabilities and home network privacy risks.

wordpressplugin-vulnerabilityauthentication-bypassrceaccount-takeovercms-security

Five critical vulnerabilities have been disclosed across popular WordPress plugins and themes—WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP—that can lead to authentication bypass, account takeover, and remote code execution. The most severe flaw, CVE-2026-76581, carries a CVSS score of 9.8 and allows attackers to bypass authentication controls entirely. These issues pose significant risk to any organization running affected WordPress installations, as exploitation could lead to full site compromise.

piracyiptvlaw-enforcementcopyright-infringement

A 68-year-old individual in the U.K. was sentenced to over six years in prison for running an illegal IPTV service that generated approximately $1.3 million over three years. This is a law enforcement action against digital piracy infrastructure rather than a cybersecurity threat targeting organizations or systems.

privacybrowser-updateemail-aliasingnot-a-vulnerability

This report describes a new privacy feature in Brave browser version 1.94 called 'Email Aliases,' which allows users to generate disposable email addresses to reduce tracking when signing up for online services. This is a legitimate product feature announcement, not a security threat, vulnerability, or malicious campaign.

non-securitybusiness-policypricingusage-limitsSurface: Human InterfacePropagation: None

This article is a business/product news item about Anthropic adjusting Claude Code's weekly usage limits and pricing tiers. It does not describe any security vulnerability, attack, or threat involving AI agents, tools, or protocols.

icsscadaxxetlscertificate-validationlog4netiec-60870-5-104critical-infrastructure

ASE2000 V2 Communications Test Set versions 2.25 through 2.37 contain two vulnerabilities: an XML External Entity (XXE) flaw inherited from a bundled outdated Apache log4net library, and an improper TLS certificate validation flaw affecting IEC 60870-5-104 secure communications. Successful exploitation could allow attackers to read/write arbitrary local files, trigger outbound network requests, or perform man-in-the-middle attacks to intercept and modify protected substation/grid communications.

authentication-bypassjwtalgorithm-confusionapi-securityaccount-takeoverrce-adjacentagent-relevant

A critical authentication bypass exists in Omnivore's API where the Apple sign-in JWT verification logic trusts the attacker-controlled 'alg' header field, enabling a classic RS256-to-HS256 algorithm confusion attack. An attacker can forge valid authentication tokens for any Apple-linked account by signing them with Apple's public RSA key treated as an HMAC secret, resulting in full account takeover without valid credentials.

authentication-bypassbroken-access-controliotrest-apiunauthenticated-rce-riskagent-relevant

rust-iot-platform contains a critical authentication bypass vulnerability in which most REST API endpoints lack authentication checks in their handler code. Unauthenticated attackers can fully manage user accounts—creating, listing, retrieving, updating, and deleting them—leading to complete account and access control compromise.

shinobicctvsql-injectionhardcoded-credentialswebsocketunauthenticated-rcevideo-surveillance

Shinobi, an open-source video surveillance/NVR platform, ships with a hardcoded connection key in its child node service that allows unauthenticated attackers to authenticate via WebSocket handshake and execute arbitrary SQL queries. This grants full read/write access to user records and camera configuration, enabling account takeover and surveillance system compromise.