Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 542 threats
A threat actor has created nearly 300 fake GitHub repositories impersonating legitimate software and security tools to distribute infostealer malware. Developers and security researchers searching for these tools risk downloading and executing malicious code disguised as trusted projects.
A high-severity local privilege escalation vulnerability (CVE-2026-31431, 'Copy Fail') affects ABB Ability Edgenius edge computing platforms due to a flaw in the Linux kernel's algif_aead cryptographic interface. A locally authenticated user or compromised container workload could exploit incorrect in-place memory operations to gain full root access on affected devices. ABB has released version 3.2.4.1 to remediate the issue.
A flaw in Perl's regex engine (Perl_study_chunk) causes silent match corruption when an alternation pattern contains more than 65535 fixed-string branches, due to a 16-bit field overflow during trie compilation. This can produce false positive or false negative matches with no warning, undermining any security or filtering logic that relies on such patterns.
CVE-2026-57830 is a critical vulnerability in the Helix Ultimate Joomla extension that allows unauthenticated attackers to delete arbitrary files on the underlying server. This could lead to denial of service, configuration file loss, or destruction of critical application data without requiring any authentication.
CVE-2026-15410 is a code injection vulnerability in SonicWall SMA1000 Appliances that allows an authenticated remote attacker with administrator privileges to execute arbitrary OS commands. The flaw has been added to CISA's Known Exploited Vulnerabilities catalog, indicating confirmed active exploitation in the wild. Organizations using SMA1000 for secure remote access are urged to remediate under an accelerated timeline.
CVE-2026-56155 is a known-exploited privilege escalation vulnerability in Microsoft Active Directory Federation Services (ADFS) caused by insufficient granularity of access control. It allows an authorized but low-privileged attacker to elevate privileges locally, potentially leading to compromise of federated identity infrastructure. CISA has added it to the Known Exploited Vulnerabilities catalog with a remediation deadline of July 28, 2026.
The AWS HealthLake MCP Server fails to validate that pagination URLs returned via the next_token parameter point back to the legitimate HealthLake endpoint, enabling an authenticated user to redirect the server's outbound requests to an attacker-controlled endpoint. This can leak AWS temporary security credentials used by the MCP server, giving an attacker a foothold to access AWS resources tied to those credentials. Fixed in version 0.0.14.
Researchers demonstrate that malicious text placed in the physical environment (e.g., signs, labels) can be captured by camera-equipped smart glasses and hijack the behavior of Vision-Language Models, causing them to ignore true visual context and produce harmful, biased, or false outputs. This is a research paper describing a demonstrated but not actively exploited class of attack, with success rates up to 96% in simulation and 60% in real-world tests across 12 VLM models.
Researchers demonstrate that an adversary can poison an open dataset with misleading metadata and upload it to a public repository, causing autonomous AI research agents (built on Claude, GPT, Gemini) to unknowingly retrieve and use the poisoned data, producing fraudulent scientific conclusions in nearly half of tested runs. No prompt injection, agent compromise, or fabricated papers are needed — only manipulation of the open data ecosystem — and current agents rarely detect the poisoning (6% detection rate), though provenance auditing fully mitigates it in testing.
A CISA contractor inadvertently published dozens of sensitive internal credentials, including AWS GovCloud keys, in a public GitHub repository where they remained exposed for nearly six months before external notification by a security journalist. The incident highlights systemic weaknesses in secrets management, contractor oversight, and detection capability within a federal cybersecurity agency, raising concerns about the broader public and private sector's exposure to similar risks.
This weekly recap highlights multiple concurrent threats including exploitation of ShareFile vulnerabilities, ransomware campaigns leveraging the 'Citrix Bleed 2' flaw, and a rising trend of attackers using AI coding tools to accelerate exploit development. The report underscores how unpatched, previously disclosed vulnerabilities continue to be actively exploited due to delayed remediation, and how trusted software supply chains are increasingly weaponized against their own users.
CrashStealer is a newly identified macOS information stealer written in native C++ that uses a notarized dropper to bypass Gatekeeper security checks. Unlike typical macOS stealers built with AppleScript or Objective-C wrappers, its native implementation and local password validation suggest a more sophisticated, evasion-focused development approach. The malware is designed to harvest sensitive data from compromised systems, including credentials and stored secrets.
CrashStealer is a newly identified macOS information-stealing malware that disguises itself as Apple's legitimate crash-reporting utility to gain user trust and system access. Once executed, it harvests saved credentials, macOS Keychain data, and cryptocurrency wallet files, exfiltrating them to attacker-controlled infrastructure. Its impersonation of a trusted system tool makes it likely to evade casual user scrutiny and some endpoint defenses.
A threat actor compromised the Jscrambler npm package and published a malicious version containing infostealer malware, which was downloaded nearly 1,500 times before detection. This represents a supply chain attack targeting developers and CI/CD pipelines that depend on the Jscrambler client-side web security tooling.
Russian FSB Center 16 (aka Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, Static Tundra) is conducting a long-running, opportunistic global campaign exploiting poorly configured and vulnerable networking devices, primarily routers, using SNMP abuse and known Cisco CVEs. Targeting spans critical infrastructure sectors including communications, energy, financial services, defense industrial base, government, and healthcare. A joint advisory from CISA, NSA, FBI, and 15 international partner agencies urges organizations to harden router/SNMP configurations and disable legacy protocols.
A vulnerability in gawk's builtin.c (do_sub() routine) allows an integer overflow that corrupts heap metadata and objects, causing crashes on 32-bit builds of gawk version 5.4.0 and earlier. The flaw could potentially be leveraged for further exploitation beyond denial of service depending on heap layout and attacker control over input strings passed to gawk substitution functions.
Cisco IOS 12.4 contains cross-site request forgery vulnerabilities in its HTTP-based management interface, allowing remote attackers to trick authenticated administrators into executing arbitrary privileged commands. This flaw is included in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. Successful exploitation could lead to full device reconfiguration or compromise of network infrastructure.
MCP Appium, an MCP server for automating mobile app testing, fails to sanitize attacker-controlled UI element attributes before embedding them in an HTML template returned by its generate_locators tool. A malicious mobile app under test can inject HTML/JavaScript that executes in the MCP client's rendering context and calls arbitrary MCP tools via postMessage, effectively letting the app-under-test hijack the testing agent's capabilities.
The China-linked threat actor Silver Fox has been attributed a new Rust-based remote access trojan called MODBEACON, which uses gRPC streaming to encrypt and obfuscate its command-and-control traffic. Despite appearing as an opportunistic, low-sophistication campaign relying on SEO poisoning and trojanized installers for distribution, researchers assess the group demonstrates notable organizational and technical maturity.
Security researchers disclosed a chained exploit involving three now-patched vulnerabilities in the OpenClaw personal AI assistant that could be triggered via WhatsApp messages to achieve credential theft, privilege escalation, and arbitrary code execution on the host system. The attack chain leverages the assistant's integration with messaging platforms as an entry point, ultimately compromising the underlying host running the AI agent.