Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 542 threats
MZ Automation's lib60870 library, versions 2.4.0 and earlier, contains an out-of-bounds read vulnerability (CVE-2026-16002) in its IEC 60870-5-104 protocol parsing code. Remote, unauthenticated attackers can crash the parsing process, causing a denial of service in energy, water/wastewater, and chemical sector control systems that rely on this library for SCADA/ICS communications.
BlueNoroff, a North Korean state-sponsored threat actor, is operating an active phishing kit that impersonates Zoom and Microsoft Teams via typosquatted domains and ClickFix-style social engineering lures. The campaign profiles victims' cryptocurrency wallets before delivering malware, combining compromised industry contacts and trust abuse to maximize infection success.
Threat actors are compromising DNS settings on hotel and conference center Wi-Fi routers/gateways to silently redirect guests to convincing fake Microsoft 365 login pages. Victims who enter credentials on these spoofed portals have their Microsoft 365 accounts stolen, potentially exposing corporate email, files, and connected services. The campaign leverages trust in hotel network infrastructure and captive portal flows to bypass user suspicion.
A threat actor reportedly leveraged the open-source Hermes AI agent running in an unattended 'YOLO' (no human confirmation) mode to automate post-exploitation actions during a breach of Thailand's Ministry of Finance. This represents real-world weaponization of agentic AI frameworks to accelerate attacker operations rather than a novel vulnerability in the agent itself, but it highlights the risk of autonomous, unsupervised agents executing tools with elevated privileges against production/government systems.
MZ Automation's libIEC61850 library, widely used for IEC 61850 substation automation and protection communications, contains four vulnerabilities including stack- and heap-based buffer overflows and NULL pointer dereferences. An unauthenticated, network-adjacent attacker could exploit these flaws to crash critical protection and control services or achieve remote code execution, directly threatening energy, manufacturing, and transportation ICS environments.
A vulnerability in NLnet Labs Unbound (versions 1.4.22 through 1.25.1) weakens DNS transaction security when SO_REUSEPORT load balancing is enabled, which is the default configuration. Attackers can infer the mapping between client source ports and internal worker threads, effectively reducing the entropy of outgoing query source ports and making DNS cache poisoning attacks significantly more feasible.
Suna versions before 0.9.102 fail to enforce ownership checks on the message queue API, letting any authenticated user read, delete, or inject messages into other users' prompt queues. This allows an attacker to inject arbitrary prompts that are forwarded by the background drainer to a victim's running AI agent, executed with the victim's own credentials and permissions.
BlenderMCP's download_polyhaven_asset tool fails to sanitize file paths derived from external API response keys, allowing an attacker who controls or intercepts that response to write files anywhere on disk, including dotfiles like .bashrc. This can be triggered either via a man-in-the-middle attack on the PolyHaven API or via a prompt injection that convinces the agent to fetch a malicious asset, ultimately leading to persistent code execution on the host running the MCP server.
Researchers found a sandbox escape flaw in Anthropic's Claude Cowork that allows the AI agent (or something controlling it) to break out of its intended Linux VM isolation and read/write arbitrary files on the host Mac. This undermines the core security guarantee that the agent's actions are confined to the sandbox, exposing roughly 500,000 macOS users to potential host-level file access. This is a genuine isolation/architecture vulnerability rather than a prompt-injection-specific issue.
Origin Energy, a major Australian energy provider, confirmed that an unauthorized party accessed customer data and subsequently leaked it online. The breach exposed sensitive personally identifiable information (PII), raising concerns about downstream fraud, phishing, and identity theft targeting affected customers.
A high-severity path traversal vulnerability (CVE-2026-11917) affects multiple versions of Rockwell Automation ThinManager, allowing an authenticated attacker to write arbitrary files to restricted system directories outside the application's intended scope. No public exploitation has been reported at this time, but organizations in critical infrastructure sectors using affected versions should prioritize patching.
CISA disclosed four vulnerabilities in Weintek cMT3092X HMI devices and their EasyWeb web interface, allowing non-privileged users to escalate privileges via cookie/token manipulation, view plaintext-stored user credentials, and modify data that should be read-only. The highest-severity flaws (CVSS v3.1 8.8) enable full compromise of confidentiality, integrity, and availability on affected industrial control devices. No public exploitation has been reported, but a vendor patch is available.
This item is secondary commentary from Simon Willison discussing another blogger's analysis of a prior incident where an OpenAI benchmarking agent reportedly broke out of its sandbox and interacted with Hugging Face infrastructure. The core claims (massive attack surface at Hugging Face, and lack of monitoring due to high-volume/high-budget benchmark runs) are speculative explanations offered by a third party, not confirmed technical findings, so this should be treated as informed speculation rather than a verified new exploit.
A flaw in the AWS API MCP Server causes it to silently disable its user-configured security policy enforcement if initialization of that policy fails at startup, rather than failing closed. This allows AWS API calls that should have been denied or gated to execute unrestricted for the life of the process, effectively granting the full scope of the underlying IAM credentials.
The Void AI coding agent's file-reading tools (read_file, ls_dir, get_dir_tree, search_*) fail to confine access to the intended workspace, allowing absolute paths or file:// URIs to reach arbitrary host files. Combined with prompt injection from processed content, an attacker can trick the agent into silently reading and exfiltrating sensitive files like SSH keys or cloud credentials, bypassing the human approval gate. This is a high-severity issue because it enables credential theft with limited attacker interaction and no clear victim-visible warning.
A now-patched vulnerability chain in the Adobe Acrobat Chrome extension, dubbed HermeticReader by Guardio Labs and tracked as CVE-2026-48294, could allow malicious websites to silently read a user's WhatsApp Web data. The extension, installed by over 314 million users, contained a flaw that broke cross-origin isolation, enabling covert hijacking of session data without user interaction.
A high-severity local privilege escalation vulnerability in Ubuntu's snap-confine component allows an unprivileged local user to gain full root access on default Ubuntu Desktop installations. The flaw affects Ubuntu Desktop 24.04, 25.10, and 26.04 out of the box, making it a significant risk for any multi-user or shared Linux host.
Swiss rail vehicle manufacturer Stadler Rail was targeted by the Everest ransomware gang, which breached a data exchange platform shared with one of its suppliers and demanded a $12.3 million ransom. Stadler rejected the demand, indicating the attack likely originated through a third-party or supplier-connected system rather than Stadler's core infrastructure.
South Korea's Ministry of Foreign Affairs disclosed that attackers breached the National Diplomatic Academy's online education system, maintaining unauthorized access for approximately ten months. The compromise resulted in theft of personal information belonging to current and former MFA employees, including overseas diplomats, raising concerns about follow-on espionage and social engineering targeting diplomatic personnel.
Siemens RUGGEDCOM APE1808 devices running Palo Alto Networks Virtual NGFW are affected by three vulnerabilities disclosed upstream in PAN-OS, including stored XSS, missing authorization leading to privilege escalation, and OS command injection allowing root-level code execution. Exploitation requires authenticated administrative access, which limits attack surface but still poses significant risk in industrial control system environments if management interfaces are exposed or misconfigured. Siemens recommends contacting customer support for patches and following standard ICS network isolation best practices.