Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 542 threats

icsscadadenial-of-servicenasacfscwe-476aerospacetransportation

A NULL pointer dereference vulnerability (CVE-2026-15352) in NASA's Core Flight System (cFS) Health & Safety (HS) Application allows a remote, unauthenticated attacker to crash the application via a crafted Housekeeping Telemetry request, causing a denial-of-service condition. The flaw affects versions prior to v7.0.1 and has been patched by NASA; no known public exploitation has been reported.

MCPbroken-access-controlprivilege-escalationCRMtool-authorizationIDORASI04 · Agentic Supply ChainSurface: Tool LayerPropagation: Single Hop

NextCRM's MCP server exposes product catalog management tools (create, update, archive, delete) without enforcing the same role-based restrictions applied to the normal web application. Any authenticated low-privileged user who can obtain an MCP Bearer token can tamper with the shared CRM product catalog, an action normally reserved for managers and admins. This is a broken access control flaw surfaced through an agent-facing tool interface, not a novel AI-specific attack.

broken-access-controlIDORcapability-leakagent-to-agenttask-hijackauthorization-bypassASI05 · Unsafe Code ExecutionSurface: Inter Agent CommsPropagation: Single Hop

AgenticMail's task API let any authenticated low-privileged agent enumerate and hijack tasks belonging to other agents by guessing/looking up their names and task IDs. This breaks the intended per-agent task isolation, allowing one agent to claim, complete, or fail work assigned to another. The vendor fixed this in version 0.9.64.

SQL-injectionSMTP-injectionTLS-verification-bypassagent-identityfail-openinactive-agentstorage-metadatasupply-chainASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

AgenticMail, a platform that gives AI agents real email addresses and phone numbers, contained a cluster of validation and security-control weaknesses across its API and core packages. These include SQL identifier injection risks, insufficient SMTP header/envelope sanitization enabling command injection, fail-open secret handling, and TLS verification defaulting incorrectly in some configurations. Combined, these flaws could let an attacker manipulate agent-controlled email infrastructure, access or corrupt storage metadata, inject SMTP commands, or intercept traffic via weakened TLS defaults.

sandbox-escapelandlockseccompdbusprivilege-escalationagent-sandboxcontainer-escapeASI06 · Memory PoisoningSurface: Tool LayerPropagation: Single Hop

nono, a sandboxing framework for running AI agents with reduced privileges, failed to block access to local Unix domain sockets prior to version 0.55.0. This allowed a sandboxed AI agent to reach the per-user systemd D-Bus socket and escape the intended isolation boundary, potentially gaining broader system access than intended. Users should upgrade to 0.55.0 immediately.

MCPauthentication-bypassCORS-misconfigurationdefault-credentialsCSRFlocalhost-exposureagent-orchestrationASI08 · Cascading FailuresAML.T0049AML.T0053Surface: ProtocolPropagation: Single Hop

Network-AI's MCP SSE server ships with an empty default authentication secret, meaning every request is treated as authorized regardless of whether an Authorization header is present. Combined with a wildcard CORS policy on all responses, this lets a malicious webpage silently invoke any of the 22 exposed MCP tools on a victim's local server, including spawning agents and writing to shared blackboard state. This is a classic drive-by CSRF-style attack against a locally running privileged agent orchestrator.

MCPWhatsAppSSRFDNS-rebindingpath-traversalunauthenticated-apidata-exfiltrationlocal-privilege-abuseASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

The WhatsApp MCP server's local bridge API (port 8080) had no authentication, no Host header validation, and allowed arbitrary file paths in message attachments. This let any local process, sibling MCP server, or even a malicious webpage (via DNS rebinding) send WhatsApp messages as the paired user and exfiltrate sensitive local files like SSH keys as WhatsApp attachments. It is fixed in v0.2.1 with bearer token auth, host allow-listing, and path confinement.

autonomous-agentsagentic-ransomwareai-intrusiondefensive-asymmetrymissing-iocshuggingfacejadepufferASI01 · Goal HijackingAML.T0053AML.T0048Surface: PlannerPropagation: Single Hop

Hugging Face disclosed a security incident it attributes to an autonomous AI agent conducting an intrusion end-to-end, and a separate report describes 'JADEPUFFER,' an alleged agent-driven ransomware capable of real-time adaptation. Both reports indicate a shift toward AI systems autonomously executing attack chains, but the JADEPUFFER report lacks victim identification and methodology transparency, limiting verifiability. Severity is high due to the plausibility and real-world implications of autonomous offensive agents, but confidence is tempered by sparse technical detail in the secondary source.

supply-chainrubygemsrubydeveloper-toolsmalicious-packageagent-relevant

Researchers identified a software supply chain attack dubbed SleeperGem involving three malicious RubyGems packages published to the official RubyGems registry. The packages, including one impersonating the legitimate 'git-credential-manager' tool, were designed to deliver additional payloads to developer machines. The attack targets Ruby developers and CI/CD pipelines that pull dependencies directly from RubyGems.

hugging-faceautonomous-agentcredential-theftdata-exfiltrationai-supply-chainproduction-breachASI08 · Cascading FailuresSurface: Supply ChainPropagation: Single Hop

Hugging Face disclosed that an autonomous AI agent was used to breach its production infrastructure, resulting in unauthorized access to internal datasets and credentials. The incident is notable because the attack vector was an AI agent operating with some degree of autonomy rather than a purely manual intrusion, highlighting real-world risk of agentic systems being weaponized against AI platform infrastructure. Details remain limited, as the source article is truncated and lacks technical specifics on the agent's tooling or exploitation method.

supply-chainaptrussiagovernmentsoftware-update-abuseespionage

An advanced threat actor is abusing the legitimate update mechanism of ViPNet, a widely used private networking/VPN software suite in Russia, to deliver malicious payloads to government agencies and other organizations. The attack leverages trust in software update channels, a classic supply-chain technique, to gain persistent access to sensitive networks.

north-korealazaruscontagious-interviewottercookiesteganographyfake-job-lurecredential-theftcrypto-theftagent-relevant

North Korean threat actors behind the Contagious Interview campaign are using fake coding tests and job postings to lure developers into running malicious projects. The payloads are hidden via steganography in SVG flag images, ultimately deploying a four-stage OtterCookie-aligned malware chain that steals browser credentials, crypto wallets, and files.

code-signingcertificate-theftsupply-chainGoldenEyeDogAPT-Q-27Dragon BreathDigiCertChina-nexusagent-relevant

A threat cluster dubbed CylindricalCanine, attributed as a sub-group of the Chinese cybercrime actor GoldenEyeDog (aka APT-Q-27, Dragon Breath, Miuuti Group), was linked to the April 2026 breach of certificate authority DigiCert and the theft of code-signing certificates. Stolen certificates can be used to sign malware so it appears trusted, enabling supply-chain compromise across downstream software consumers.

botnetexposed-servicescredential-theftcloud-keyskubernetesComfyUIOllaman8nOpen WebUILangflowGradioshodan-scanninggo-malwareASI08 · Cascading FailuresAML.T0025AML.T0048Surface: Tool LayerPropagation: Self Propagating

NadMesh is a Go-based botnet that scans the internet for unauthenticated, publicly exposed AI infrastructure (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) and abuses them to harvest cloud credentials, including a claimed 3,811 unique AWS keys, as well as Kubernetes tokens. This is not an attack on agent reasoning or protocols themselves, but exploitation of poor deployment hygiene around AI tooling that teams stand up quickly without adequate authentication or network controls. Severity is high because successful compromise yields direct cloud/infrastructure takeover, not just AI misuse.

infostealercredential-theftagent-relevantbrowser-securitydata-exfiltration

Microsoft has identified a significant surge in attacks deploying ACR Stealer, an information-stealing malware targeting enterprise customers. The malware harvests browser-stored passwords, authentication tokens, and sensitive documents, posing a serious risk to organizational credential security and downstream account compromise.

7-ziprcearchive-exploitfile-parsingpatch-availableagent-relevant

7-Zip version 26.02 patches a remote code execution vulnerability that can be triggered when a user opens a specially crafted compressed archive. Attackers could leverage social engineering to deliver malicious archives and gain code execution on victim systems. Users and organizations should update immediately to mitigate risk.

ICSOTdenial-of-serviceCISA-advisoryRockwell-AutomationCIP-protocoldouble-free

A high-severity denial-of-service vulnerability (CVE-2026-12659) affects Rockwell Automation Flex 5000 Adapter version 6.011 due to a double-free condition triggered by crafted CIP packets. Successful exploitation halts the affected module, requiring a manual power cycle to restore operation, posing operational risk to industrial control environments.

ICSSCADAPLCengineering-workstationdriver-vulnerabilitykernel-memory-corruptionlocal-privilege-escalationcritical-manufacturingCISA-advisory

AutomationDirect Productivity Suite versions up to v4.6.2.2 contain six vulnerabilities including out-of-bounds write/read flaws and a divide-by-zero condition, primarily triggered via crafted IOCTL requests to a kernel driver or malicious USB devices. Exploitation requires local or physical access and could lead to kernel memory corruption, privilege escalation, information disclosure, or denial-of-service on engineering workstations. No known public exploitation has been reported, and the vulnerabilities are not remotely exploitable.

ICSOTcritical-manufacturingmemory-corruptionout-of-bounds-writearbitrary-code-executionlocal-exploituser-interaction-required

Rockwell Automation Arena versions up to and including V17.00.00 contain four out-of-bounds write vulnerabilities (CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, CVE-2026-8314) in the model.exe, expmt.exe, linker.exe, and siman.exe (Siman) components. Successful exploitation requires a user to open a malicious file, potentially allowing arbitrary code execution in the context of the current process. No public exploitation has been reported as of publication.

MCPmcp.jsonauto-executionmalicious-reposupply-chainCLI-tooldeveloper-toolingarbitrary-command-executionASI04 · Agentic Supply ChainAML.T0011AML.T0053Surface: Supply ChainPropagation: Single Hop

ForgeCode, an AI pair-programming CLI, automatically parses and executes MCP server configurations from a repository's .mcp.json file without any user confirmation. A malicious or compromised repository can embed arbitrary OS commands in this file, achieving code execution with the developer's privileges the moment they run forge inside the cloned repo. This turns routine repository evaluation into a reliable initial-access vector for supply-chain attacks against developers.