Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 1485 threats
CareCam Pro IP Cameras (ANJIA AJL33PC0801 firmware) contain a hard-coded credential used for bootloader authentication, allowing an attacker with physical access to gain privileged bootloader access and fully compromise the device. The vendor has not responded to CISA's coordination attempts, and no patch is currently available. Exploitation requires physical access and is not remotely exploitable.
Knowns versions prior to 0.30.0 expose an unauthenticated management API on all network interfaces by default, with no password set on fresh installs. Attackers can leverage the exposed /api/tunnel/start endpoint to publicly republish the internal management API, gaining full administrative access without credentials. This flaw is trivially exploitable via internet-wide scanning and poses a critical risk to any deployment that has not been manually hardened.
A critical OS command injection vulnerability exists in the Linksys RE7000 2.0.15 firmware, affecting the PingTest handler in /cgi-bin/json.cgi. The flaw allows unauthenticated remote attackers to execute arbitrary commands via crafted pingTestIp, pingTestPktSize, or pingTestTimes parameters. Public exploit code is available, significantly increasing the likelihood of mass exploitation against exposed devices.
A critical command injection vulnerability affects multiple Advantech WISE-6610 industrial cellular gateway models running firmware 1.2.1_20251110, exploitable remotely via the Node-RED Library's nodered_lib_apply function. Public exploit code is available, significantly increasing the likelihood of active exploitation against exposed industrial and IoT gateway deployments. Advantech has released a patched firmware version (1.2.4_20260821) to address the flaw.
A critical remote OS command injection vulnerability has been identified in Tenda CP3 (firmware 27.5.57.101), affecting the CAutoAddWifi::ThreadProc function within the Kylin component. The flaw allows an unauthenticated remote attacker to execute arbitrary OS commands on the device, with a maximum CVSS score of 10.0. This vulnerability poses a severe risk to networks relying on affected Tenda devices for connectivity or camera/IoT functions.
A critical remote OS command injection vulnerability has been identified in the Tenda CP3 (firmware 27.5.57.101) within the Network Configuration Management component. The flaw resides in the sub_2F77E8 function of Apis/system.c and can be exploited remotely without requiring physical access, potentially granting attackers full device compromise.
CVE-2026-85880 is a heap-based buffer overflow in Microsoft Windows Advanced Local Procedure Call (ALPC) that enables local privilege escalation. The vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation in the wild, with a remediation deadline of September 22, 2026.
N-able N-central, a widely used remote monitoring and management (RMM) platform, contains a static code injection vulnerability enabling pre-authentication remote code execution. This flaw is listed in CISA's Known Exploited Vulnerabilities catalog with an aggressive remediation deadline, indicating active exploitation in the wild. Because N-central is deployed by MSPs to manage large fleets of downstream client endpoints, successful exploitation could grant attackers a foothold across many organizations simultaneously.
CVE-2026-81963 is a local privilege escalation vulnerability in the Microsoft Windows Update Stack caused by improper handling of file system links, allowing a local attacker to gain SYSTEM-level privileges. The flaw has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, with a remediation deadline of September 22, 2026.
A critical server-side template injection vulnerability affecting Adobe Commerce and Magento Open Source has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. The flaw allows attackers to inject malicious template elements that are improperly neutralized, resulting in arbitrary code execution on affected servers. Organizations running Adobe Commerce or Magento storefronts must patch by the CISA-mandated due date of September 11, 2026.
This item is a quoted excerpt from OpenAI's Chief Scientist discussing the broad strategic argument for developing powerful AI to defend against risks posed by other AI systems, alongside a caution against reckless development. It contains no technical details about specific vulnerabilities, exploits, or agent security incidents, and does not describe an actionable threat.
This is an academic research paper (not an active exploit) that reframes indirect prompt injection as a search problem, showing that an attacker agent with more compute and structured strategy management becomes significantly better at finding and exploiting injection vulnerabilities in victim agents. The core finding is that attack success scales with attacker search budget and adaptive strategy, meaning current security evaluations that treat 'attack success' as fixed likely underestimate real-world risk against tool-using agents.
Researchers demonstrate a black-box adaptive image-based prompt injection attack ('Repeat-After-Me') that reliably hijacks frontier vision-language models into leaking PII or issuing malicious tool calls, even when the user's actual prompt has nothing to do with the injected task. In a real-world OpenClaw Discord agent deployment, the attack allowed an untrusted image to overwrite TOOLS.md, opening a path to remote code execution and secret exfiltration.
An MCP server fails to sanitize filesystem path arguments passed to its tools, allowing an attacker to read, create, overwrite, or delete files outside the intended project directory. This is a classic path traversal vulnerability exposed through an AI agent tool interface, giving attackers a direct route to filesystem compromise via crafted tool calls.
This weekly recap covers multiple active threats including a Chrome 0-day, router hijacking campaigns, and a notable supply chain attack against the Coder platform that resulted in credential theft. Attackers also demonstrated a novel phishing technique using text-rendered QR codes to bypass email image-blocking protections, and abused a network management protocol for malicious purposes.
A threat cluster is targeting executives (directors, VPs, senior staff) at organizations using Microsoft 365 and other SaaS platforms through IT help desk vishing calls, adversary-in-the-middle (AitM) session token theft, and sign-ins routed through residential proxy networks to evade geolocation-based detection. Stolen credentials and session tokens are used for data exfiltration followed by extortion demands. The campaign leverages human trust in IT support workflows rather than software exploits, making it effective against organizations with strong technical controls but weaker identity-verification processes.
PEEP is a post-compromise toolkit that disguises itself as a bookmarks extension for Chrome and Edge, requiring prior administrative or code execution access to deploy. It forges Chromium's Secure Preferences file to bypass Web Store validation and user consent prompts, effectively turning the browser into a persistent backdoor capable of executing host commands.
Online mathematics learning platform Mathspace disclosed a data breach affecting over 1 million students, staff, and parents after attackers compromised its Metabase internal reporting system. The breach exposed personal data likely including names, emails, and academic records tied to a widely used education platform. No technical details on the intrusion vector into Metabase have been disclosed.
BigBear 2.0, a phishing-as-a-service (PhaaS) platform, has been used to compromise 258 organizations and steal over 5,000 Microsoft 365 credentials by bypassing multi-factor authentication via adversary-in-the-middle (AiTM) reverse-proxy techniques. The kit lowers the barrier to entry for large-scale credential phishing campaigns and has demonstrated broad reach across sectors relying on Microsoft 365 for identity and collaboration.
A zero-day vulnerability named 'StyleSmuggler' affecting all versions of Magento and Adobe Commerce is being actively exploited in the wild to deploy a Linux backdoor on compromised servers. The flaw appears to allow attackers to smuggle malicious code through style/template processing, granting persistent unauthorized access to e-commerce infrastructure.