Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 542 threats

androidmobile-malwareadbwireless-adbshell-accessprivilege-escalationmobile-security

A new variant of the RedHook Android malware exploits the Android Wireless Debugging (Wireless ADB) feature to obtain shell-level access on infected devices without requiring a wired connection to a computer. This removes a key barrier that previously limited ADB-based attacks, making device compromise more autonomous and scalable. The technique poses a significant risk to Android users and enterprises relying on mobile devices for authentication and access.

zimbraxssstored-xssemail-securitywebmailrceunpatched

Zimbra has issued an advisory for a critical stored cross-site scripting vulnerability in its Classic Web Client that can be triggered by specially crafted emails, allowing attackers to execute malicious scripts within a victim's active session. No CVE identifier has been assigned yet, but customers are urged to apply updates immediately.

cyber-espionagegovernmentlaw-enforcementsouth-asiachina-nexusindia-nexusweb-application-compromisedata-breachcritical-infrastructure

Suspected China- and India-aligned APT groups conducted a sustained, multi-year cyber espionage campaign (February 2024 to April 2026) against Pakistani law enforcement organizations, including the Balochistan Police. Attackers compromised servers hosting public-facing web applications used to manage sensitive police and citizen data, including criminal records.

sharefilestorage-zone-controllerfile-sharingon-premisescredible-threatprogress-software

Progress Software has issued an urgent advisory urging ShareFile customers running on-premises Storage Zone Controllers to immediately shut down their servers due to a credible, unspecified external security threat. No CVE or technical details have been publicly disclosed yet, but the severity of the recommendation (full shutdown) suggests a serious, potentially actively exploited vulnerability. Organizations using ShareFile Storage Zone Controllers should treat this as an active incident and act on vendor guidance without delay.

prompt-injectionimage-steganographymultimodalcoding-agentdata-exfiltrationsecrets-leakCodeRabbitBugbotsupply-chainASI01 · Goal HijackingAML.T0051AML.T0054Surface: ModelPropagation: Single Hop

Researchers demonstrated 'Ghostcommit,' a technique that hides prompt injection instructions inside a PNG image committed to a repository. AI code review tools like CodeRabbit and Bugbot don't inspect image contents, but a downstream coding agent that does process the image can be tricked into reading a repo's .env file and exfiltrating secrets by encoding them as numeric data in code. This shows a real, demonstrated cross-modal injection vector with tangible secret-theft impact, not a theoretical concern.

CMSexploitationweb-shellplugin-vulnerabilityACSCvulnerability-managementpatch-now

The Australian Cyber Security Centre has warned of an ongoing global campaign in which threat actors are exploiting vulnerabilities in content management systems (CMS) and their plugins to gain unauthorized access to web servers. The campaign appears opportunistic, scanning for and exploiting unpatched or misconfigured CMS installations at scale. Organizations running public-facing CMS platforms are urged to patch immediately and audit for signs of compromise.

prompt-injectiondefault-misconfigurationseverity-thresholdsystem-prompt-leaktool-invocationpraisonaiASI01 · Goal HijackingAML.T0051Surface: ModelPropagation: Single Hop

PraisonAI versions before 4.6.78 ship with a prompt injection defense that only blocks CRITICAL-severity threats by default, letting HIGH-severity attacks such as instruction overrides pass through with only logging. This allows attackers to extract system prompts and trigger unauthorized tool calls via single-vector injection attempts that the framework detects but fails to stop.

u-bootbootloaderfirmwareembedded-systemsrcedossupply-chainiotagent-relevant

Security researchers at Binarly disclosed six new vulnerabilities in U-Boot, the widely used open-source bootloader found in routers, IoT devices, and data-center server management chips (BMCs). Four flaws can cause denial-of-service crashes, while two allow arbitrary code execution if an attacker can present a malicious boot image to the device before the OS loads. Exploitation requires local or supply-chain-level access to the boot process, but successful attacks grant persistence below the operating system, making detection and remediation difficult.

supply-chainnpmcryptocurrencywallet-theftgithub-compromisemalicious-packageagent-relevant

Threat actors compromised the Injective Labs SDK GitHub repository and published a malicious version of the @injectivelabs/sdk-ts npm package embedded with fake telemetry code designed to steal cryptocurrency wallet private keys and mnemonic seed phrases. Developers and automated systems that installed the compromised version (1.20.21) are at risk of credential and asset theft.

firmwarebootloaderu-bootembedded-systemspersistencesupply-chainagent-relevant

Six newly disclosed vulnerabilities in the widely used U-Boot bootloader could allow attackers with local or physical access to execute malicious code during the boot process. Exploitation could bypass secure boot protections and enable stealthy, persistent firmware-level malware that survives OS reinstalls and standard remediation. The flaws pose a significant risk to embedded devices, IoT systems, and edge hardware that rely on U-Boot for initialization.

CISAKEVAdobeColdFusionpath-traversalactive-exploitationfederal-agenciesBOD-26-04

CISA has added CVE-2026-48282, a path traversal vulnerability in Adobe ColdFusion, to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation in the wild. Federal civilian agencies must remediate per BOD 26-04, and CISA urges all organizations to prioritize patching this flaw due to its demonstrated attractiveness to threat actors.

CISAKEVfile-uploadweb-applicationCMSpluginJoomlaactive-exploitationBOD-26-04

CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: an unrestricted file upload flaw in iCagenda (CVE-2026-48939) and a similar flaw in Balbooa Forms (CVE-2026-56291). Both vulnerabilities allow attackers to upload dangerous file types, potentially leading to remote code execution on affected web servers.

open-webuipyodidesandbox-escapecsrfprivilege-escalationself-hosted-llmagent-relevantragllm-tool-use

Open WebUI versions prior to 0.10.0 execute client-side Python via Pyodide inside a same-origin web worker, which lacks proper isolation from the host page's authenticated session. A malicious stored chat payload can leverage pyodide.http.pyfetch or JS-exposed fetch/XMLHttpRequest APIs to make authenticated same-origin requests when a victim runs the code, enabling access to admin-only endpoints and server-side tool execution. This effectively turns a chat message into a stored XSRF/RCE primitive against self-hosted AI deployments.

default-credentialsapi-securityunauthorized-accessagent-relevant

IBM API Connect versions 12.1.0.0 through 12.1.0.3 ship with default credentials that remain active until an administrator manually enforces a password change. Attackers aware of these default credentials can gain unauthorized access to the API management platform before remediation occurs, potentially compromising API gateways, backend integrations, and associated secrets.

sql-injectionlangchain4jvector-databaseembedding-storemetadata-filterragjavamariadbpgvectorASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

LangChain4j's MariaDB and pgvector embedding store integrations build SQL queries by unsafely concatenating metadata filter keys (and MariaDB string values) into query strings, allowing an attacker who controls filter input to inject SQL. This can lead to blind data exfiltration, denial of service, and mass deletion of vector store data via crafted EmbeddingSearchRequest filters.

wiperdestructive-malwarefake-ransomwarespywarewindowsbackdoormicrosoft-research

Microsoft has identified GigaWiper, a modular Windows backdoor that combines three legacy destructive tools into a single operator-controlled framework. The malware offers command-selectable payloads including full disk wiping, Windows drive overwriting, and fake ransomware that encrypts files without retaining decryption keys, making recovery impossible even if a ransom is paid.

vishingvoice-phishingdevice-code-phishingMFA-abuseSharePointdata-extortionidentity-attacksocial-engineeringcloud-securityagent-relevant

A newly identified data-extortion group called Helix is targeting organizations' SharePoint environments using identity-focused attack techniques, including voice phishing (vishing), device code phishing, and MFA abuse. The group's approach bypasses traditional malware-based detection by exploiting human trust and authentication weaknesses to gain access and exfiltrate sensitive data for extortion purposes.

npmsupply-chaincryptocurrencywallet-stealergithub-compromiseagent-relevant

Attackers compromised the GitHub repository of Injective Labs' SDK project and published a malicious version of the package to npm. The trojanized package harvested cryptocurrency wallet private keys and mnemonic seed phrases from developers and downstream applications that installed it.

opensshuse-after-freeclient-sidesshmemory-corruptionagent-relevant

CVE-2026-60002 is a use-after-free vulnerability in OpenSSH clients prior to version 10.4, triggered when a malicious or compromised server changes its host key during a key re-exchange. Exploitation could lead to client-side memory corruption, potentially enabling denial of service or code execution on systems initiating SSH connections.

account-takeoverauthentication-bypasspassword-recoveryesriarcgisgisweb-application

CVE-2026-13020 is a weak password recovery mechanism vulnerability in Esri Portal for ArcGIS (versions 12.1 and earlier) that allows a remote, unauthenticated attacker to hijack a user's account by manipulating the forgotten-password flow. Organizations running ArcGIS Enterprise on Windows, Linux, or Kubernetes are at risk of unauthorized account access without prior credentials.