Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 1485 threats

vendor-contentnot-a-threatapplication-securitydevsecopsAI-generated-codeinformational

This item is promotional content advertising a webinar about managing security risks introduced by AI-accelerated software development, rather than an active threat, vulnerability, or campaign. It highlights a legitimate industry concern: as AI coding assistants increase code output volume, security teams may struggle to keep pace with vulnerability review, dependency management, and risk prioritization.

product-launchai-security-toolingvulnerability-researchpentestingnot-a-threatagent-relevant

This is a product announcement rather than an active threat: OpenAI has released 'GPT-5.6 Cyber,' a specialized model for vulnerability research, penetration testing, incident response, and remediation, gated to approved users. The release has security implications for both defenders and potential misuse by threat actors if access controls are bypassed or credentials are compromised.

wordpresssupply-chainplugin-compromiseadmin-takeoverweb-security

A threat actor compromised the upstream infrastructure of BdThemes, a premium WordPress plugin developer, and tampered with a remote JSON feed served to site administrators. This modified feed was used to silently create rogue administrator accounts on affected WordPress installations, granting attackers persistent backend access.

OTICScritical-infrastructureenergyAPNcellular-networkremote-accessindustrial-control-systems

Hackers breached the operational technology (OT) network of a small Polish heat-and-power plant serving approximately 50,000 residents by exploiting a private Access Point Name (APN) used for remote cellular connectivity. The incident, disclosed as having occurred the prior year, highlights how insufficiently secured private cellular networks can serve as an overlooked pathway into critical infrastructure control systems.

SAPcommand-injectionRCEmanufacturinginput-validationcritical-infrastructure

A critical command injection vulnerability affects SAP Manufacturing Integration and Intelligence (MII), allowing a high-privileged attacker to submit crafted input that is insufficiently validated, leading to arbitrary OS command execution. Exploitation could fully compromise confidentiality, integrity, and availability of the affected system. Organizations running SAP MII in manufacturing or industrial environments should prioritize patching.

sapnetweavermemory-corruptionunauthenticated-rcedoserpcritical-infrastructure

A critical unauthenticated vulnerability (CVE-2026-34265) affects SAP NetWeaver Application Server ABAP, stemming from logical errors in DIAG protocol parsing that lead to memory corruption. With a CVSS score of 9.8, attackers can remotely disclose sensitive information or crash affected systems without any authentication, posing severe risk to organizations running SAP ERP environments.

kubernetesauthentication-bypassprivilege-escalationmaasmulti-tenancyagent-relevantai-infrastructureapi-security

CVE-2026-14450 is a critical authentication bypass vulnerability in the Model-as-a-Service (MaaS) API layer fronted by Kuadrant's AuthPolicy gateway. Any pod within the affected Kubernetes cluster can forge the X-MaaS-Username and X-MaaS-Group HTTP headers, which are trusted verbatim without first-party verification, enabling full cross-tenant privilege escalation. This allows attackers to mint ServiceAccount tokens in other tenants' namespaces, revoke arbitrary API keys, and exfiltrate model access configuration data.

routercommand-injectiontelnetfirmwarerceiotnetwork-device

A critical command injection vulnerability exists in the TelnetSSH configuration function of MSI Radix AXE6600 router firmware v781521, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This flaw could be leveraged to fully compromise home and small-office network infrastructure, enabling traffic interception, lateral movement, or botnet recruitment.

routercommand-injectionrcesshfirmwarenetwork-deviceunauthenticated

A critical command injection vulnerability exists in the TelnetSSH configuration function of MSI Radix AXE6600 routers running firmware v781521, allowing remote attackers to execute arbitrary commands with root privileges. Given the CVSS score of 9.8, this flaw is likely remotely exploitable without authentication, making affected devices prime targets for botnet recruitment, traffic interception, or use as network pivot points.

model-releasebenchmarkinformationalno-threatlocal-llmSurface: ModelPropagation: None

This is a blog post from Simon Willison announcing Meta's new open-weights model 'Muse Glimmer', tested for agentic tool use, coding assistance, and vision tasks. The content is purely informational and does not describe any vulnerability, exploit, attack technique, or security incident involving AI agents.

gitsupply-chainagent-cliarbitrary-command-executionfsmonitorrepository-poisoningpre-model-executionASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

The `goose review` command in the goose AI agent invokes Git in a way that trusts repository-local configuration, allowing a malicious repository to execute arbitrary commands on the host simply by being reviewed. This happens automatically before any model interaction, prompt, or tool-approval step, bypassing goose's entire trust and permission model. An attacker can exfiltrate secrets, API keys, and modify files with the privileges of the user running goose.

indirect-prompt-injectioncomputer-use-agentsbenchmarkmulti-step-attackweb-navigationgoal-decompositionresearchASI01 · Goal HijackingAML.T0051AML.T0054Surface: PlannerPropagation: Single Hop

This is an academic research paper introducing StepJack, a benchmark that demonstrates how indirect prompt injection attacks against computer-use agents (CUAs) become significantly more effective when the adversarial goal is split across multiple innocuous-looking sub-steps distributed across a chain of web pages. It is not an active exploit, but the findings show meaningfully higher attack success rates against several state-of-the-art CUAs compared to single-step injection, indicating a real and underexplored gap in current agent safety defenses. Severity is rated medium because this is disclosed research with a public benchmark rather than an in-the-wild attack, but the technique is practically reproducible.

CISA-KEVcommand-injectionload-balancernetwork-applianceactive-exploitationedge-device

A critical command injection vulnerability in Progress Kemp LoadMaster, tracked as CVE-2026-8037 (CVSS 9.6), has been added to CISA's Known Exploited Vulnerabilities catalog after 792 reported exploitation attempts in the wild. The flaw allows attackers to achieve arbitrary command execution on affected load balancer appliances, posing severe risk to organizations relying on this infrastructure for traffic management.

RMMexploitation-in-the-wildMSPsupply-chain-riskremote-monitoringhotfixagent-relevant

N-able has released a second hotfix for its N-central Remote Monitoring and Management (RMM) platform after observing threat actors actively exploiting a recently disclosed vulnerability and evolving their attack techniques to persist on managed endpoints. The vendor is expanding protections beyond the initial patch, indicating attackers reaching into managed customer environments through the compromised RMM infrastructure.

prompt-injectionagent-relevantAI-securitydata-exfiltrationAtlassianindirect-prompt-injectionRAGLLM-tool-use

Security researchers demonstrated that Atlassian's Rovo AI assistant can be manipulated via attacker-controlled content (e.g., uploaded files or embedded instructions) to collect Jira and Confluence data accessible to a signed-in user and exfiltrate it to an external server. Two independent research teams found separate exploitation paths; only one has been confirmed remediated by Atlassian.

sharepointgovernmentdata-breachaccount-compromiseon-premises

Switzerland's Federal Office of Information Technology disclosed that attackers exploited vulnerabilities in on-premises Microsoft SharePoint servers to compromise roughly 200 government accounts. The incident highlights ongoing risks tied to unpatched or exposed SharePoint deployments within critical government infrastructure.

routercommand-injectionrcefirmwareiotunauthenticatednetwork-infrastructure

A critical command injection vulnerability exists in the alg function of MSI Radix AXE6600 router firmware v781521, allowing remote attackers to execute arbitrary commands with root privileges. With a CVSS score of 9.8, this flaw could enable full device takeover, network pivoting, and traffic interception on affected routers.

routercommand-injectionrceiotfirmwareunauthenticated-rce

A critical unauthenticated command injection vulnerability (CVE-2026-71986) exists in the dmz function of MSI Radix AXE6600 router firmware v781521, allowing remote attackers to execute arbitrary commands and gain root access. With a CVSS score of 9.8, this flaw poses severe risk to any network relying on the affected device for perimeter security or connectivity.

routercommand-injectionrceiotnetwork-infrastructureunauthenticated

A critical command injection vulnerability exists in the accesscontrol function of MSI Radix AXE6600 router firmware v781521, allowing remote attackers to execute arbitrary commands with root privileges. Given the CVSS score of 9.8, exploitation likely requires no authentication and results in full device compromise, enabling attackers to intercept, redirect, or manipulate all network traffic passing through the device.

router-vulnerabilitycommand-injectionrceiotnetwork-infrastructureunauthenticated-exploit

A critical unauthenticated command injection vulnerability exists in the urlfilter function of MSI Radix AXE6600 router firmware v781521, allowing remote attackers to execute arbitrary commands with root privileges. Given the CVSS score of 9.8 and remote exploitability without authentication, this vulnerability poses severe risk to any network using affected devices, potentially enabling full network compromise, traffic interception, or pivot points for further attacks.