Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 13 of 533 threats
Researchers reported what they describe as the first documented ransomware campaign, dubbed JadePuffer, allegedly executed end-to-end by an autonomous LLM agent rather than human operators. The article provides limited technical detail, so key claims (full autonomy, novelty, actual impact) cannot be independently verified from the source alone.
Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M versions 1.000A through 1.014Q contain four vulnerabilities in its bundled 7-Zip component, including a heap-based buffer overflow, NULL pointer dereference, link following, and path traversal issue. Successful exploitation requires local access and user interaction to decompress a specially crafted archive, and could lead to denial-of-service, data tampering, or arbitrary code execution. No public exploitation has been observed, and the vulnerabilities are not remotely exploitable.
The FBI, working with industry partners, seized hundreds of domains linked to NetNut, a residential proxy service operated by publicly-traded Israeli firm Alarum Technologies. The takedown follows security research connecting NetNut to the Popa botnet, a network of at least two million devices compromised without meaningful user consent. This represents a significant disruption to a large-scale proxyware/botnet infrastructure used to monetize unwitting victims' internet connections.
Schneider Electric EasyLogic T150 and Saitel DP RTU devices contain two vulnerabilities that could allow unauthorized access to sensitive credentials and password hashes. CVE-2026-9650 allows an unauthenticated attacker with physical access to extract credentials from firmware or system files, while CVE-2026-9651 allows a privileged local attacker to read improperly protected system files containing password hashes. No public exploitation has been reported to CISA at this time.
CISA added CVE-2026-45659, a deserialization of untrusted data vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog due to confirmed active exploitation. Federal civilian agencies are required under BOD 26-04 to remediate this vulnerability on an expedited basis given its potential for full system compromise on publicly exposed assets. All organizations, not just federal agencies, are strongly encouraged to prioritize patching.
The Popa botnet is a large-scale Android-based malware network that has compromised millions of consumer TV boxes over the past four years, using them as unwitting relays for internet traffic. Security researchers have linked this infrastructure to NetNut, a residential proxy service operated by publicly-traded Israeli company Alarum Technologies Ltd (NASDAQ: ALAR), raising concerns about corporate involvement in facilitating malicious traffic relay networks.
Two high-severity vulnerabilities affect ST Engineering iDirect iQ-Series satellite terminals (Evolution iQ, 3315-Series, 9-Series) running firmware <=4.5.2.1. Successful exploitation could allow an unauthenticated attacker to retrieve sensitive device credentials or force device reboots via CSRF, potentially causing terminal impersonation or denial-of-service on satellite links. No known public exploitation has been reported to CISA at this time.
Attackers seed false facts or standing instructions into an agent's long-term memory or RAG store, quietly steering decisions across future sessions long after the original malicious input is gone.
Adversarial instructions planted in content processed by one agent can replicate into its outputs and infect downstream agents, spreading through normal inter-agent messaging the way the Morris II research worm spread through AI email assistants.
Malicious or compromised MCP servers embed hidden instructions in tool metadata that the model reads but the human approving the tool never sees, steering agents into data exfiltration or unauthorized actions. First documented publicly by Invariant Labs in 2025 and since reproduced across many clients.
Coordinated campaign publishing typosquatted Python packages to steal environment variables, SSH keys, and cloud credentials from developer workstations and CI/CD pipelines.
English-speaking group using SIM-swapping and MFA fatigue attacks to compromise enterprise identity providers via IT help desk impersonation calls.
Chinese state-sponsored group maintaining persistent access in US energy, water, and telecom networks using living-off-the-land techniques that blend with normal admin activity.