Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 1504 threats

coding-agentsautonomous-agentsci-cdself-modifying-softwaresupply-chain-riskunattended-executionASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

This item is a blog quote describing a practice of running a nightly cron job that instructs an AI coding agent to autonomously fetch upstream changes, rebase local modifications, verify functionality, and replace the running software version. This is not itself an attack or exploit report, but it describes a risky operational pattern: unattended, unsupervised agentic code modification and deployment. Severity is medium because the described practice creates a plausible attack surface (supply-chain and prompt-injection risk) even though no actual exploit is documented here.

audio-injectionmultimodal-llmvoice-agentsprompt-injectionacoustic-attackresearchbenchmarkASR-hijackASI01 · Goal HijackingAML.T0051AML.T0054Surface: ModelPropagation: Single Hop

Researchers demonstrate that malicious audio instructions can be covertly embedded alongside legitimate user speech to hijack multimodal LLM agents that process continuous audio input, achieving a 69% attack success rate against Gemini 3 Pro. This is a research paper (with an accompanying defense, CADV) rather than an active exploit in the wild, but it exposes a realistic and largely unaddressed attack surface in voice-driven agent products.

chromebrowser-securitypatch-managementvulnerability-disclosuregoogle

Google released three Chrome updates (versions 149, 150, and 151) fixing a cumulative total of 1,442 security bugs, far exceeding the combined total of the previous 23 releases. This represents a significant spike in disclosed vulnerabilities, largely attributed to internal discovery efforts rather than active exploitation reports.

captive-portal-hijackfake-updateRATsurveillance-malwareMidnight-BlizzardStorm-2945hospitalitynation-statecredential-theftagent-relevant

Microsoft has identified a campaign, tracked as CaptiveCrunch, in which threat actors hijack hotel Wi-Fi captive portals to serve fake browser update prompts. Victims who install the fake update are infected with CornFlake, a remote access trojan capable of capturing webcam images, microphone audio, and keystrokes. The activity is attributed to Storm-2945, assessed as an operational sub-cluster of the Russian state-sponsored group Midnight Blizzard (APT29).

adobecampaign-classicrceauthorization-bypassunauthenticatedcritical-vulnerability

Adobe has issued an emergency patch for a maximum-severity flaw (CVSS 10.0) in Campaign Classic, its enterprise marketing automation platform, caused by incorrect authorization checks. The vulnerability allows arbitrary code execution without any user interaction, making it a high-priority target for exploitation once details or a proof-of-concept become public.

browser-securitychromeextensionsdefensive-featurenew-tab-hijacking

Google is developing a Chrome security feature to block policy-installed extensions from hijacking the New Tab page or overriding the default search engine. This is a defensive enhancement rather than an active exploit, aimed at curbing a common malicious/adware extension technique often used to redirect traffic and harvest ad revenue or credentials.

cryptocurrencyhardware-walletrng-flawkey-managementbitcoin-theftsupply-chain

A flawed random number generator in COLDCARD hardware wallet firmware produced predictable or low-entropy seed phrases, enabling attackers to reconstruct private keys and drain wallets. The flaw is believed responsible for the theft of approximately $88.6 million in Bitcoin from thousands of affected wallets.

not-a-threatai-industry-newsproduct-announcement

This article is a product news item about OpenAI's unreleased 'Astra' model, reported to have solved several long-standing math and theoretical computer science problems internally. It contains no information about a vulnerability, exploit, malware, or attack campaign and does not constitute a cybersecurity threat.

arcadedbauthorization-bypassdatabaserce-adjacenttime-seriesagent-relevant

ArcadeDB versions prior to 26.7.2 contain a critical authorization bypass vulnerability affecting HTTP handlers for time series, batch, Prometheus, and Grafana endpoints. Unauthenticated or under-privileged attackers can access and manipulate arbitrary databases by directly invoking these endpoints with crafted database parameters, bypassing intended access controls. Given the CVSS score of 9.8, this vulnerability poses a severe risk of data theft, tampering, and destruction on any exposed ArcadeDB instance.

arcadedbrceprivilege-escalationdatabasejavascript-injectionagent-relevant

ArcadeDB versions prior to 26.7.2 contain a critical authorization flaw allowing any database user to execute arbitrary JavaScript via the SQL DEFINE FUNCTION statement with LANGUAGE js, bypassing intended admin-only scripting restrictions. This effectively grants remote code execution to any actor with database access, regardless of assigned privilege level.

arcadedbrcesandbox-escapejavascript-injectionprivilege-abusedatabaseagent-relevant

ArcadeDB before version 26.7.2 contains a critical flaw in its ScriptTriggerExecutor that improperly whitelists java.lang.* packages, allowing an authenticated user with UPDATE_SCHEMA permission to craft a malicious JavaScript trigger. This trigger can invoke Java.type to access Runtime.getRuntime().exec() or ProcessBuilder, resulting in arbitrary OS command execution when the trigger fires.

authentication-bypassaccount-takeoverscimidentity-managementbetter-authssosupply-chainagent-relevant

A critical authorization bypass in the @better-auth/scim plugin allows an authenticated user to mint a SCIM token that collides with an existing SSO/SAML/OIDC/OAuth provider namespace, granting full read/write/delete access over unrelated user accounts and sessions. This enables account takeover, unauthorized profile/email rewriting, and mass deprovisioning across the identity system. Given the 9.9 CVSS score and low attack complexity, this is highly exploitable in any deployment using SCIM provisioning alongside social/SSO logins.

gitpythonpythonrcecommand-injectionsupply-chaindependency-vulnerabilityagent-relevant

GitPython 3.1.50's protection against dangerous clone options (--upload-pack/-u) can be bypassed by passing the joined short-option form -u<value>, which the default unsafe-option gate fails to detect. Applications that pass attacker-influenced values into Repo.clone_from() with allow_unsafe_options=False are still vulnerable to arbitrary command execution during the clone operation. The issue is fixed in GitPython 3.1.51.

MCPArcadeDBinformation-disclosureprivilege-escalationcluster-tokenimpersonationtool-misuseASI02 · Tool MisuseSurface: Tool LayerPropagation: Single Hop

ArcadeDB's MCP server exposes a get_server_settings tool that leaks the cluster authentication token in cleartext. Any client with MCP access can use this token to forge headers and impersonate the root user, gaining full control of the database server.

newsletternon-securitypromotional-contentSurface: Human InterfacePropagation: None

This is a promotional post from Simon Willison announcing his monthly sponsors-only newsletter, listing topics like model releases (GPT-5.6, Claude Opus 5) and a mention of renewed interest in MCP. It contains no actual vulnerability details, exploit information, or threat data about AI agents, frameworks, or protocols.

supply-chainadtechcryptocurrencyclipboard-hijackingjavascriptmalvertisingweb-skimming

Attackers compromised a JavaScript file served by advertising technology provider Adform, injecting code that rewrites cryptocurrency wallet addresses copied by site visitors, redirecting funds to attacker-controlled wallets. The malicious script was distributed across multiple customer sites that embedded Adform's ad-serving code, exposing visitors who copied Bitcoin or other crypto addresses on July 27, 2026. Adform detected and remediated the incident, notified affected clients, and reported it to authorities.

cryptocurrencyhardware-walletweak-rngfirmware-vulnerabilitybitcoin-theftsupply-chain

A March 2021 firmware integration error in Coinkite's Coldcard hardware wallet caused seed generation to rely on a deterministic software pseudorandom number generator (PRNG) instead of proper entropy sources, producing predictable private keys. Attackers exploited this weakness to systematically drain 1,196 Bitcoin addresses, stealing 1,082.65 BTC (~$70.2 million) in just 41 minutes on July 30. Galaxy Research identified the pattern and linked the mass sweep directly to the firmware defect, exposing years of latent risk for affected wallet holders.

agent-relevantai-agent-abuseautonomous-attackdeepseekllm-misuseserver-exploitationchina-nexus

A Chinese-speaking threat actor is leveraging the DeepSeek AI model combined with the open-source Hermes Agent framework to autonomously scan, target, and exploit internet-exposed vulnerable servers with minimal human oversight. This represents a notable escalation in offensive AI usage, where an agentic LLM pipeline performs reconnaissance, exploitation, and possibly post-exploitation actions with limited operator intervention. The campaign highlights growing risk from adversaries weaponizing legitimate agent frameworks originally built for benign automation.

non-securityvendor-announcementinformationalopenaipricing

This item is a routine business/product announcement from OpenAI regarding API pricing changes for its GPT-5.6 model variants ('Luna' and 'Terra'), not a security incident. No vulnerability, exploit, malware, or attack technique is described.

railsrubyactive-storagercefile-readweb-frameworkagent-relevant

A critical vulnerability in Ruby on Rails' Active Storage framework allows unauthenticated attackers to read arbitrary files from an affected application, with a potential escalation path to remote code execution. Rails maintainers have released patches, and organizations running unpatched Active Storage implementations should prioritize updates given the severity and ease of exploitation typically associated with such flaws.