Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 1467 threats
The U.S. Department of Justice disrupted Xinbi Guarantee, an online marketplace facilitating scam services for Chinese organized crime groups, seizing associated Telegram channels and freezing $52.8 million in cryptocurrency. The action also included physical disruption of 13 scam compounds in Madagascar linked to romance and investment scam operations (commonly known as 'pig butchering' schemes).
CERT/CC has disclosed that Skullcandy Dime 3 wireless earbuds will accept Bluetooth pairing requests from any nearby device without requiring user confirmation. This flaw could allow an attacker within Bluetooth range to eavesdrop on audio or hijack the connection without the victim's knowledge or consent.
Healthcare company AdaptHealth confirmed that a July cyberattack attributed to the ShinyHunters threat group exposed personal data of 4.1 million individuals. The incident highlights ongoing targeting of healthcare organizations for large-scale data theft and extortion rather than encryption-based ransomware.
Cisco has confirmed active exploitation of CVE-2026-20079, a maximum-severity authentication bypass vulnerability in Secure Firewall Management Center (FMC) software. Attackers exploiting this flaw could gain unauthorized administrative access to centralized firewall management infrastructure, potentially compromising network-wide security controls. Organizations running affected FMC versions should treat this as an urgent patching priority.
CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, affecting Fortinet products, Citrix NetScaler, Google Chromium V8, and Cisco Firewall Management Center. These vulnerabilities include authentication bypass and memory corruption flaws that grant attackers significant post-exploitation control, and federal agencies are required under BOD 26-04 to remediate them on an accelerated timeline.
A critical stack-based buffer overflow vulnerability affects the udhcpcd component of D-Link DIR-895L routers running firmware A1_102b07, specifically within the sendOffer/sendACK functions of serverpacket.c. The flaw is exploitable only by attackers on the local network, but a public exploit is available, significantly increasing the risk of exploitation. Successful exploitation could allow attackers to crash the device or achieve remote code execution on the router.
Dell SCG 5.0 Appliance and Application versions prior to 5.36.00.16 and 5.36.00.00 respectively contain an improper certificate validation flaw that allows unauthenticated remote attackers to gain unauthorized access. This vulnerability likely enables man-in-the-middle attacks or certificate spoofing, undermining trust boundaries within the affected infrastructure.
CVE-2026-80131 is a path traversal vulnerability in Dell SCG 5.0 Appliance and Application prior to versions 5.36.00.16 and 5.36.00.00 respectively. An unauthenticated remote attacker can exploit this flaw to escape restricted directories and achieve remote code execution on the affected system.
A path traversal vulnerability in Dell SCG 5.0 Appliance and Application allows an unauthenticated remote attacker to escape restricted directories, potentially leading to remote code execution. The flaw affects versions prior to 5.36.00.16 (Appliance) and 5.36.00.00 (Application) and carries a CVSS score of 6.5, indicating medium severity despite the RCE potential.
MISP versions up to 2.5.45 contain SSRF vulnerabilities in feed retrieval and TAXII discovery functionality due to insufficient validation of outbound HTTP redirects and DNS resolution. Attackers controlling a malicious or compromised feed/TAXII source can redirect MISP's outbound requests to internal network resources or forward configured authentication credentials to attacker-controlled hosts. This is especially dangerous given MISP's role as a trusted threat-intelligence hub often integrated into automated security and enrichment pipelines.
Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management contain a critical authentication bypass vulnerability that allows unauthenticated remote attackers to execute scripts and gain root access to the underlying operating system. This flaw has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog with a compressed remediation window, indicating active or imminent exploitation in the wild. Organizations using Cisco FMC to manage firewall infrastructure face full compromise risk of their central security management plane.
CVE-2026-87491 is an out-of-bounds write vulnerability in Google Chromium's V8 JavaScript engine that allows remote code execution within the browser sandbox via a crafted HTML page. The flaw is included in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, and affects all Chromium-based browsers including Chrome, Edge, and Opera. Organizations must patch by the September 23, 2026 CISA deadline to mitigate risk of remote compromise.
CVE-2025-25249 is a heap-based buffer overflow affecting FortiOS, FortiSwitchManager, and FortiSASE that allows remote code execution via specially crafted packets. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog with a short remediation window, indicating active exploitation in the wild.
Microsoft released its largest-ever monthly patch batch, addressing approximately 974 security vulnerabilities across Windows and other Microsoft products. The company attributes part of the surge in discovered flaws to AI-assisted vulnerability research, while security experts caution that the scale of the release will strain organizations' ability to test and deploy fixes in a timely manner. Delayed patching windows increase exposure time to any of the disclosed flaws being weaponized.
An attacker exploited a bug in the Elements software underlying the Liquid Network, a Bitcoin sidechain, to steal nearly 4,000 BTC. The following day, 3,400 BTC was returned, leaving approximately 598.5 BTC ($47M reported total held) unaccounted for, with the network still paused and L-BTC redemptions halted.
CrowdStrike has identified a new financially motivated threat actor, dubbed Slim Spider, targeting Brazilian financial institutions since at least March 2026. The group demonstrates deep knowledge of Brazilian financial infrastructure, including instant payment systems, and has been observed stealing crypto custody secrets from a targeted institution.
A maximum-severity (CVSS 10.0) pre-authentication remote code execution vulnerability in N-able N-central, a widely used remote monitoring and management (RMM) platform, is being actively exploited in the wild. CISA has added CVE-2026-86218 to its Known Exploited Vulnerabilities catalog, mandating FCEB agencies remediate by September 11, 2026, underscoring the urgency and severity of the flaw.
This is a regulatory compliance advisory, not an active exploit or malware campaign. The EU Cyber Resilience Act imposes new mandatory vulnerability reporting requirements effective September 11, requiring software vendors to report actively exploited vulnerabilities to authorities within 24 hours of awareness. The article emphasizes that organizations must maintain precise records of software composition and vulnerability discovery timelines to meet these tight deadlines.
DoppelCart is a large-scale fraud operation leveraging over 119,000 fake e-commerce domains to trick consumers into entering payment card details on fraudulent storefronts. The scale of the infrastructure suggests automated domain generation and templated site deployment, enabling rapid scaling and takedown resilience. The primary impact is financial fraud and payment card data theft against consumers and, by extension, brands whose identities may be spoofed.
This item describes a new Microsoft Windows 11 feature that introduces age-awareness APIs, allowing applications to determine whether a user is a child, teenager, or adult without revealing their exact birthdate. This is a product announcement, not a security vulnerability, exploit, or malicious campaign.