Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 5 of 485 threats

authentication-bypassOIDCremote-code-execution-riskCISA-KEVprivilege-escalationMFA-bypass

A critical authentication bypass vulnerability exists in SimpleHelp's OIDC authentication flow, where identity tokens are accepted without cryptographic signature verification. This allows a remote, unauthenticated attacker to forge tokens and gain fully authenticated technician-level access, potentially bypassing multi-factor authentication safeguards. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation.

ASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: NoneMCP

The MCP Inspector developer tool shipped a proxy that lacked authentication, allowing browser-based attackers to reach it from a malicious web page and execute code on the developer's machine. Reported by Oligo Security with a CVSS score of 9.4.

ASI04 · Agentic Supply ChainSurface: ProtocolPropagation: NoneMCPsupply-chain

A critical flaw in the widely used mcp-remote OAuth proxy let malicious MCP servers achieve remote code execution on connecting developer machines, turning a routine agent connection into full host compromise. The package had hundreds of thousands of downloads before patching.

Zero-DayVPNEdge Device

Two chained zero-days in Ivanti VPN appliances enabling unauthenticated remote code execution. Mass exploitation targeting government and defense across 12 countries.

RansomwareHealthcareRaaS

Fourth-generation LockBit ransomware-as-a-service with enhanced encryption completing full-disk encryption in under four minutes. Actively targeting hospitals, municipal governments, and manufacturing.