Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 1485 threats

data-breachhealthcareShinyHuntersPIIextortion

Healthcare company AdaptHealth confirmed that a July cyberattack attributed to the ShinyHunters threat group exposed personal data of 4.1 million individuals. The incident highlights ongoing targeting of healthcare organizations for large-scale data theft and extortion rather than encryption-based ransomware.

ciscofmcauthentication-bypassfirewallnetwork-securityactive-exploitationagent-relevant

Cisco has confirmed active exploitation of CVE-2026-20079, a maximum-severity authentication bypass vulnerability in Secure Firewall Management Center (FMC) software. Attackers exploiting this flaw could gain unauthorized administrative access to centralized firewall management infrastructure, potentially compromising network-wide security controls. Organizations running affected FMC versions should treat this as an urgent patching priority.

kev-catalogcisaactive-exploitationnetwork-securityedge-devicesauthentication-bypassbrowser-exploitagent-relevant

CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, affecting Fortinet products, Citrix NetScaler, Google Chromium V8, and Cisco Firewall Management Center. These vulnerabilities include authentication bypass and memory corruption flaws that grant attackers significant post-exploitation control, and federal agencies are required under BOD 26-04 to remediate them on an accelerated timeline.

iotrouterbuffer-overflowd-linklocal-networkfirmwarepublic-exploit

A critical stack-based buffer overflow vulnerability affects the udhcpcd component of D-Link DIR-895L routers running firmware A1_102b07, specifically within the sendOffer/sendACK functions of serverpacket.c. The flaw is exploitable only by attackers on the local network, but a public exploit is available, significantly increasing the risk of exploitation. Successful exploitation could allow attackers to crash the device or achieve remote code execution on the router.

dellscgcertificate-validationman-in-the-middleunauthenticatednetwork-appliance

Dell SCG 5.0 Appliance and Application versions prior to 5.36.00.16 and 5.36.00.00 respectively contain an improper certificate validation flaw that allows unauthenticated remote attackers to gain unauthorized access. This vulnerability likely enables man-in-the-middle attacks or certificate spoofing, undermining trust boundaries within the affected infrastructure.

path-traversalrceunauthenticateddellnetwork-applianceedge-device

CVE-2026-80131 is a path traversal vulnerability in Dell SCG 5.0 Appliance and Application prior to versions 5.36.00.16 and 5.36.00.00 respectively. An unauthenticated remote attacker can exploit this flaw to escape restricted directories and achieve remote code execution on the affected system.

path-traversalunauthenticatedremote-code-executiondellscgvulnerabilitynetwork-appliance

A path traversal vulnerability in Dell SCG 5.0 Appliance and Application allows an unauthenticated remote attacker to escape restricted directories, potentially leading to remote code execution. The flaw affects versions prior to 5.36.00.16 (Appliance) and 5.36.00.00 (Application) and carries a CVSS score of 6.5, indicating medium severity despite the RCE potential.

SSRFMISPthreat-intel-platformcredential-leakDNS-rebindingredirect-abuseagent-relevant

MISP versions up to 2.5.45 contain SSRF vulnerabilities in feed retrieval and TAXII discovery functionality due to insufficient validation of outbound HTTP redirects and DNS resolution. Attackers controlling a malicious or compromised feed/TAXII source can redirect MISP's outbound requests to internal network resources or forward configured authentication credentials to attacker-controlled hosts. This is especially dangerous given MISP's role as a trusted threat-intelligence hub often integrated into automated security and enrichment pipelines.

ciscofirewallauthentication-bypassroot-accesskevnetwork-securityedge-device

Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management contain a critical authentication bypass vulnerability that allows unauthenticated remote attackers to execute scripts and gain root access to the underlying operating system. This flaw has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog with a compressed remediation window, indicating active or imminent exploitation in the wild. Organizations using Cisco FMC to manage firewall infrastructure face full compromise risk of their central security management plane.

chromiumv8browserout-of-bounds-writesandbox-escapecisa-kevagent-relevantrce

CVE-2026-87491 is an out-of-bounds write vulnerability in Google Chromium's V8 JavaScript engine that allows remote code execution within the browser sandbox via a crafted HTML page. The flaw is included in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, and affects all Chromium-based browsers including Chrome, Edge, and Opera. Organizations must patch by the September 23, 2026 CISA deadline to mitigate risk of remote compromise.

fortinetfortiosheap-overflowrcenetwork-perimetercisa-kevedge-deviceagent-relevant

CVE-2025-25249 is a heap-based buffer overflow affecting FortiOS, FortiSwitchManager, and FortiSASE that allows remote code execution via specially crafted packets. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog with a short remediation window, indicating active exploitation in the wild.

patch-tuesdaymicrosoftwindowsvulnerability-managementpatch-managementai-assisted-discoveryagent-relevant

Microsoft released its largest-ever monthly patch batch, addressing approximately 974 security vulnerabilities across Windows and other Microsoft products. The company attributes part of the surge in discovered flaws to AI-assisted vulnerability research, while security experts caution that the scale of the release will strain organizations' ability to test and deploy fixes in a timely manner. Delayed patching windows increase exposure time to any of the disclosed flaws being weaponized.

cryptocurrencybitcoinsidechainblockchainexploitfinancial-theft

An attacker exploited a bug in the Elements software underlying the Liquid Network, a Bitcoin sidechain, to steal nearly 4,000 BTC. The following day, 3,400 BTC was returned, leaving approximately 598.5 BTC ($47M reported total held) unaccounted for, with the network still paused and L-BTC redemptions halted.

financial-fraudbrazilcrypto-theftthreat-actorinstant-payment-fraudsocial-engineering

CrowdStrike has identified a new financially motivated threat actor, dubbed Slim Spider, targeting Brazilian financial institutions since at least March 2026. The group demonstrates deep knowledge of Brazilian financial infrastructure, including instant payment systems, and has been observed stealing crypto custody secrets from a targeted institution.

RMMpre-auth-rceCISA-KEVN-ableexploited-in-the-wildsupply-chain-riskagent-relevant

A maximum-severity (CVSS 10.0) pre-authentication remote code execution vulnerability in N-able N-central, a widely used remote monitoring and management (RMM) platform, is being actively exploited in the wild. CISA has added CVE-2026-86218 to its Known Exploited Vulnerabilities catalog, mandating FCEB agencies remediate by September 11, 2026, underscoring the urgency and severity of the flaw.

complianceregulatoryEU-CRAvulnerability-disclosureSBOMsoftware-supply-chain

This is a regulatory compliance advisory, not an active exploit or malware campaign. The EU Cyber Resilience Act imposes new mandatory vulnerability reporting requirements effective September 11, requiring software vendors to report actively exploited vulnerabilities to authorities within 24 hours of awareness. The article emphasizes that organizations must maintain precise records of software composition and vulnerability discovery timelines to meet these tight deadlines.

fraudphishingfake-shopspayment-card-thefte-commerce-frauddomain-abuse

DoppelCart is a large-scale fraud operation leveraging over 119,000 fake e-commerce domains to trick consumers into entering payment card details on fraudulent storefronts. The scale of the infrastructure suggests automated domain generation and templated site deployment, enabling rapid scaling and takedown resilience. The primary impact is financial fraud and payment card data theft against consumers and, by extension, brands whose identities may be spoofed.

not-a-vulnerabilityproduct-featurewindows-11privacyinformational

This item describes a new Microsoft Windows 11 feature that introduces age-awareness APIs, allowing applications to determine whether a user is a child, teenager, or adult without revealing their exact birthdate. This is a product announcement, not a security vulnerability, exploit, or malicious campaign.

kevcisaactively-exploitedadobe-commercemagentowindowsn-ablermmtemplate-injectionprivilege-escalationfederal-mandate

CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog affecting Adobe Commerce/Magento, Microsoft Windows, and N-able N-central, all confirmed under active exploitation. FCEB agencies must remediate per BOD 26-04, and CISA urges all organizations to prioritize patching given the demonstrated real-world attack activity.

knowledge-distillationmodel-extractionprompt-injectionchain-of-thought-extractionAPI-abusegray-market-proxiesnation-stateChinaIP-theftCoT-leakageASI08 · Cascading FailuresAML.T0008AML.T0040AML.T0051AML.T0054AML.TA0008AML.T0042AML.TA0009AML.T0024.002AML.T0048Surface: ModelPropagation: None

A joint NSA/CISA/FBI advisory describes China-based AI companies (DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, Z.AI) conducting large-scale, systematic extraction of proprietary capabilities from U.S. frontier AI models (Claude, GPT, Gemini, Grok) via automated API abuse, evasion of geographic/usage restrictions, and prompt-based chain-of-thought extraction. This is a genuine, well-documented threat to model IP and competitive advantage rather than a fabricated or exaggerated claim, though it is an economic/espionage concern rather than a direct system-compromise vulnerability.