Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 1485 threats
A critical buffer overflow vulnerability exists in the PROFINET service of an industrial device in its default configuration, allowing unauthenticated remote attackers to crash the device or execute arbitrary code. With a CVSS score of 9.8, this flaw poses severe risk to industrial control system (ICS) and operational technology (OT) environments where the affected device is deployed.
A critical Incorrect Authorization vulnerability in Adobe Campaign Classic (ACC) allows an unauthenticated attacker to execute arbitrary code in the context of the current user without any user interaction required. The maximum CVSS score of 10.0 and changed scope indicate the flaw can escalate impact beyond the vulnerable component itself, making this a top-priority patching target for any organization running ACC.
The MCP Atlassian server before version 0.22.0 fails to validate file paths passed to its confluence_upload_attachment tool, allowing an authenticated MCP client (or an AI agent manipulated via untrusted content) to read arbitrary files on the server and exfiltrate them as Confluence attachments. This can expose sensitive server environment variables like CONFLUENCE_API_TOKEN, turning a routine file-upload feature into a credential theft and data exfiltration primitive.
Security researchers at Tracebit demonstrated a defensive technique called 'context bombing,' which plants prompt injections next to decoy secrets (passwords, API keys) in cloud environments. When an autonomous AI hacking agent discovers and reads these decoys, the embedded injection triggers the attacker LLM's own safety guardrails, causing it to refuse and halt the intrusion. This is a legitimate, low-risk defensive use of prompt injection rather than a novel attack, though it highlights the broader unreliability of LLM instruction boundaries.
Researchers found that encrypted reasoning/chain-of-thought blocks returned by proprietary LLM APIs (OpenAI, Anthropic, Google) used the same encryption key across models within a family, allowing an attacker to capture a strong model's encrypted reasoning trace and replay it into a weaker sibling model to trick it into decrypting and outputting the plaintext hidden reasoning. This exposed internal chain-of-thought content never intended for end users, including a related technique to induce models into reasoning about data exfiltration steps. Vendors have since patched the flaw, reducing current risk, but it demonstrates a real and previously unknown extraction/jailbreak vector.
This is an academic research paper (not an active exploit report) systematizing a class of attacks called 'LLM2X', where attacker-controlled input passed through an LLM in a tool-calling or agentic pipeline is transformed and then reaches traditional web backend sinks (SQL, shell, templates, XML parsers, HTTP clients). The LLM acts as a confused deputy, laundering malicious input into classic vulnerabilities like SQLi, XSS, SSRF, SSTI, and command injection. The authors validate this experimentally with a case study (TicketOracle) showing SSRF susceptibility varies significantly across seven different LLMs.
This is a research paper, not an active exploit or vulnerability disclosure. It presents a systematic literature review of 85 papers on agentic LLM security, finding that most research focuses on perception-layer issues like prompt injection while action-layer risks such as tool misuse and sandbox escape are understudied. The severity is low since the raw data itself contains no exploitable technical detail, only meta-analysis of the field.
This is an arXiv research paper describing a defensive gateway architecture that solves an existing enterprise problem: inconsistent, fragmented authentication across internally built MCP servers. It documents a solution (centralized auth gateway with OAuth token exchange) rather than disclosing a new exploit or vulnerability. No active threat, PoC, or attack technique is presented; the underlying risk it addresses (weak/inconsistent MCP auth) is real but already well-known and is being mitigated here.
Microsoft's August 2026 Patch Tuesday addresses nearly 398 vulnerabilities across Windows and supported software, including one flaw already under active exploitation and two others that were publicly disclosed prior to patching. Organizations should prioritize patching the actively exploited vulnerability to reduce risk of compromise.
A flaw in Zoom's screen annotation feature could have allowed any meeting participant to hijack the client of another attendee, including the presenter, without any user interaction. The vulnerability required no click, download, or visible prompt, making it a fully zero-click, in-meeting attack vector. This poses significant risk to organizations relying on Zoom for internal and external communications, including those coordinating distributed teams or automated workflows via meeting integrations.
Kimwolf v7, an evolution of the AISURU Android/IoT botnet, was discovered by Palo Alto Networks Unit 42 in February 2026 with enhanced HTTP/2-based DDoS capabilities designed to blend malicious traffic with legitimate browsing patterns. The improvements increase operational resilience and evasion, making detection and mitigation more difficult for defenders relying on traditional traffic-signature analysis.
The Russian state-linked threat group Sandworm is targeting system administrators and IT professionals with fake job offers designed to lure victims into installing a trojanized WireGuard VPN client. The campaign, active since at least May 2026, aims to compromise privileged accounts and gain persistent access to enterprise networks through social engineering and malicious software.
DeadLock is a ransomware operation that leverages blockchain-backed decentralized infrastructure to host its victim communication portals and data-leak sites, making takedown efforts by law enforcement and security researchers significantly more difficult. This resilience model represents an evolving trend among ransomware groups seeking to evade traditional infrastructure disruption tactics.
Google announced that Chrome's anti-abuse systems are now blocking over 7 billion unwanted push notifications per day on Android as of Q1 2026. This is a defensive product improvement rather than an active threat, reflecting Google's ongoing efforts to curb notification spam and deceptive web push abuse.
CISA disclosed eight vulnerabilities in the Mira Hormone Monitor firmware and companion Mira Android App, including missing BLE authentication, hard-coded credentials, and a broken login endpoint that returns valid session tokens for any password. Successful exploitation could allow attackers to hijack user accounts, exfiltrate or forge sensitive reproductive health data, track users physically via BLE, and cause denial-of-service on the device.
CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog: a heap inspection flaw in Cisco Secure Firewall ASA/FTD, a use-after-free in the Windows Ancillary Function Driver for WinSock, and a SQL injection vulnerability in Metabase. Federal agencies are required under BOD 26-04 to remediate these on a prioritized timeline, and all organizations are strongly encouraged to patch given confirmed in-the-wild exploitation.
The Pulsetto Vagus Nerve Stimulator firmware accepts undisclosed, unauthenticated Bluetooth Low Energy commands that are not issued by the official companion app but are still processed by the device. Successful exploitation could allow a nearby attacker to disable electrical safety mechanisms or alter stimulation output settings, posing a physical safety risk to users. The vendor has not responded to CISA's coordination attempts, and no patch is currently available.
A critical Incorrect Authorization vulnerability in Adobe Campaign Classic (ACC) allows attackers to achieve arbitrary code execution in the context of the current user without any user interaction. With a CVSS score of 10.0 and a changed scope, successful exploitation could lead to full compromise of the marketing automation platform and downstream systems it integrates with.
MaxKey SSO contains a hard-coded JWT signing secret that allows unauthenticated attackers to forge valid admin-level JWT tokens and bypass authentication entirely via the password-skipped login endpoint. This grants full access to SSO application configuration and downstream application secrets, effectively compromising every service federated through the affected MaxKey instance.
A critical vulnerability (CVSS 10.0) in Siemens SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED allows unauthenticated remote attackers to execute arbitrary code with maximum privileges via the exposed Node-RED HTTP interface. Attackers can craft malicious flows to invoke system command nodes, achieving full device compromise with no authentication required.