Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 1504 threats

linuxprivilege-escalationrace-conditionred-hatcisa-kevlocal-exploit

CVE-2015-3246 is a race condition vulnerability in Red Hat's libuser library that allows authenticated local users to corrupt /etc/passwd, resulting in denial of service or privilege escalation. The flaw has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild despite its age. Organizations still running affected libuser versions on Linux systems should prioritize patching before the specified due date.

deserializationremote-code-executiondotnetlegacy-softwareend-of-lifeCISA-KEV

Ajax.NET Professional (AjaxPro) is affected by a deserialization vulnerability (CVE-2021-23758) that allows remote code execution through instantiation of arbitrary .NET classes. The affected product is end-of-life, meaning no vendor patch is available, and CISA has added it to the Known Exploited Vulnerabilities catalog due to active exploitation.

privacydata-minimizationtool-callsmcpresearchdefensive-toolingpii-leakageASI06 · Memory PoisoningSurface: Tool LayerPropagation: None

This is a defensive research paper, not an active exploit. It quantifies how LLM agents habitually over-share privacy-sensitive data in tool call arguments (81-88% of calls) and proposes ToolMinimize, a middleware that rewrites arguments to the minimum necessary data. The finding highlights a systemic data-hygiene weakness in agent-to-tool interactions rather than describing a novel attack technique.

eval-injectionlangfunllm-code-generationunsandboxed-evalremote-code-executionprompt-injectionpythonASI05 · Unsafe Code ExecutionAML.T0051AML.T0053Surface: ModelPropagation: Single Hop

Google's langfun library (versions before 0.1.2) evaluates Python expressions generated by an LLM in response to lf.query prompts without any sandboxing. A remote unauthenticated attacker who can influence prompt input can cause the model to emit malicious Python code that gets executed directly in the host application, resulting in full arbitrary code execution.

not-a-threatcommentaryai-assisted-programmingcoding-agentsSurface: Human InterfacePropagation: None

This raw data is a blog post quoting commentary about AI's ability to write and refine large amounts of code over time. It contains no information about vulnerabilities, attacks, or security issues involving AI agents, tools, or protocols. This is not a security threat.

MCPrug-pulltrust-horizondelayed-payloadsupply-chainschema-valid-evasionserver-side-attackresearchASI05 · Unsafe Code ExecutionAML.T0051AML.T0053AML.T0043Surface: Tool LayerPropagation: Single Hop

This is an academic research paper (not an active exploit) describing 'TrustShift', a class of attacks where a malicious MCP tool server behaves benignly during an initial conditioning period to build trust, then switches to adversarial behavior once agents rely on it heavily. The researchers built an attack taxonomy and a benchmark showing ~69.5% attack success rate against frontier agents, plus a runtime defense (SHIELD) that reduces this to ~42.7%.

AP2A2AMCPagentic-paymentsmandate-signingresearchMAESTROAIVSSprompt-injectionreplayshopping-agentASI05 · Unsafe Code ExecutionAML.T0051AML.T0054Surface: ProtocolPropagation: Single Hop

This is an academic security analysis (not an active exploit) of Google's Agent Payments Protocol v0.2, which is used by LLM-driven shopping agents to authorize payments. The researchers show that while signed Checkout and Payment Mandates protect transaction integrity after signing, the A2A and MCP interactions that shape the transaction beforehand are unprotected, enabling an agent to be manipulated into signing a mandate that does not reflect the user's true intent. The paper identifies 48 catalogued threats across five attack families, with eight rated High severity, and provides proof-of-concept demonstrations plus a deployment-aware scanner.

defensive-researchprompt-injection-mitigationspan-provenancesteering-vectorsresidual-streamadaptersnot-an-exploitASI01 · Goal HijackingAML.T0051AML.T0054Surface: ModelPropagation: None

This is a defensive research paper, not an active threat or exploit. It proposes 'Semantic Overlays,' a technique using learned adapters on a model's residual stream to help LLMs distinguish trusted instructions from untrusted content (e.g., tool outputs, user input), thereby mitigating prompt injection. The paper reports strong benchmark improvements against known prompt injection attack suites, and severity is low since it describes a mitigation, not a vulnerability or attack.

WebMCPbrowser-agentsame-origin-policytool-provenanceprompt-injectionresearchdefense-proposalquarantine-agentcapability-credentialsASI05 · Unsafe Code ExecutionAML.T0051AML.T0054Surface: Tool LayerPropagation: Single Hop

This is a defensive research paper, not an active exploit: it identifies real trust-boundary gaps in the emerging W3C WebMCP proposal that let malicious web pages spoof tool ownership, manipulate tool lifecycles, and inject prompts via tool metadata/descriptions into browser-integrated LLM agents. The authors propose and empirically validate a dual-layer runtime (cryptographic tool provenance plus a quarantine/privileged agent split) that reduces these attack classes to near-zero success, while also disclosing a residual bypass via malicious tool names invoked before inspection.

researchdefenseprompt-injectiontool-poisoningattention-analysisruntime-detectioninterpretabilityASI01 · Goal HijackingAML.T0051AML.T0054Surface: ModelPropagation: None

This is a defensive research paper, not an active exploit or vulnerability disclosure. It proposes Attnlocate, a runtime framework that analyzes LLM attention patterns to pinpoint which parts of external/tool-provided context are actually driving an agent's tool-calling decisions, helping detect indirect prompt injection and tool poisoning attacks. Since this describes a mitigation technique rather than a new threat, severity is low from a threat standpoint, though the underlying attack classes it addresses (indirect prompt injection, tool poisoning) remain real risks for agentic systems.

authenticationpasskeyssecurity-featurewhatsappmetaphishing-resistant

Meta has expanded WhatsApp's account security by enabling support for multiple passkeys per account across iOS and Android, allowing users to sign in using phishing-resistant authentication methods on multiple devices. This is a defensive security enhancement rather than a threat, aimed at reducing account takeover risk for over 1 billion existing passkey users.

NemoClawOllamalocalhost-exposureCSRFmodel-poisoningdriveby-attacklocal-inferenceagent-securityASI04 · Agentic Supply ChainAML.T0018AML.T0020AML.T0043Surface: ModelPropagation: Single Hop

Researchers at Oasis Security found that a malicious webpage can reach an unauthenticated local Ollama instance running behind NVIDIA NemoClaw and use it to implant hidden instructions into the AI model itself. This effectively lets a remote attacker who only controls a webpage a victim visits achieve persistent, unauthenticated tampering with a locally hosted AI agent's behavior.

iransanctionscritical-infrastructurestate-sponsoredtreasurygeopolitical

The U.S. Department of the Treasury has imposed new sanctions on Iranian cyber actors linked to breaches of critical infrastructure, as part of a broader economic pressure campaign against Iran. This is a policy and enforcement action rather than a newly disclosed technical vulnerability, though it signals continued Iranian state-sponsored targeting of critical infrastructure sectors.

phishing-as-a-servicevoice-AIsocial-engineeringstolen-devicesactivation-lockAI-vishingPhaaSSurface: Human InterfacePropagation: None

AnonyMousKIT is a phishing-as-a-service platform that uses voice AI agents to impersonate Apple support and trick victims into revealing codes needed to unlock stolen iPhones and disable Activation Lock. This is primarily a human-facing social engineering threat that leverages AI voice generation to scale traditional vishing rather than an attack on agent infrastructure or protocols. Severity is high due to real-world financial and privacy harm to victims and the commoditization of AI-driven fraud tooling.

npmphishingsupply-chainfake-captchacloudflare-impersonationagent-relevant

Threat actors are abusing npm and its mirror services to host malicious HTML pages that impersonate Cloudflare CAPTCHA verification screens. Visitors who interact with these fake pages are redirected to attacker-controlled sites, likely for further phishing, malware delivery, or credential theft. The abuse leverages the inherent trust and reachability of npm's infrastructure to evade detection and blocklisting.

data-breachPIISSN-exposuremedical-datamuseum-sectorthird-party-risk

The Los Angeles County Museum of Art (LACMA) disclosed a data breach from the prior year that exposed sensitive personal information, including Social Security numbers and medical data, belonging to customers and employees. Details on the initial attack vector and threat actor attribution have not been publicly confirmed at this time.

CISAKEVGiteacode-injectionactive-exploitationagent-relevantself-hosted-gitRCE

CISA added CVE-2026-60004, a code injection vulnerability in Gitea, to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation. Federal agencies are required under BOD 26-04 to remediate this vulnerability on a prioritized basis, and CISA urges all organizations to do the same given the risk of total asset compromise.

ICSIoTsmart-homecredential-exposureCWE-522vulnerability-disclosure

Rently Smart Home versions 20.1.0 and earlier contain a vulnerability that insufficiently protects credentials, allowing an attacker to retrieve PINs, including the Master PIN, and override standard user permissions. Rently has released a patch as of late June 2026, and no known public exploitation has been reported.

ICSIoTgatewayauthentication-bypassCSRFcleartext-credentialsMQTTunpatchedcritical-infrastructure

The Ebyte NE2-D11 gateway (Firmware FW-9167-0-11) contains eleven distinct vulnerabilities including missing authentication, client-side authentication bypass, cleartext credential and MQTT traffic transmission, CSRF, clickjacking, and missing authorization checks. Several flaws are rated CVSS 9.8, allowing an unauthenticated remote attacker to fully compromise device confidentiality, integrity, and availability. Ebyte has not released a patch or responded to CISA coordination requests, leaving affected deployments in critical manufacturing and energy sectors exposed with no vendor remediation timeline.

nokogirilibxml2use-after-freerubysupply-chainxmldtdxincludeagent-relevant

Nokogiri versions before 1.15.6 and 1.16.x before 1.16.2 bundle a vulnerable version of libxml2 affected by CVE-2024-25062, a use-after-free in the xmlTextReader module. Applications using Nokogiri::XML::Reader with DTD validation and XInclude expansion enabled on untrusted XML input can trigger memory corruption, potentially leading to crashes or code execution.