Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 1522 threats

apache-thriftrpcbuffer-overflowmemory-corruptionagent-relevantsupply-chain-componentcpp

A critical heap-based buffer overflow has been identified in the C++ bindings of Apache Thrift, a widely used cross-language RPC framework, affecting all versions prior to 0.24.0. The vulnerability carries a CVSS score of 9.8, indicating remote exploitability with low attack complexity and potential for full system compromise. Organizations using Thrift-based services must upgrade immediately to mitigate risk of remote code execution or denial of service.

apache-thrifttlscertificate-validationmitmagent-relevantrpcsupply-chain-dependency

Apache Thrift's c_glib bindings before version 0.24.0 fail to properly validate that a TLS certificate's hostname matches the connected host, allowing an attacker positioned on the network path to present a mismatched but otherwise valid certificate and impersonate a trusted server. This affects any application using the c_glib Thrift client library to establish TLS-secured RPC connections, enabling man-in-the-middle attacks against Thrift-based service communication.

CISA-KEVSD-WANcommand-injectionnetwork-infrastructureedge-devicepre-auth-suspected

A critical OS command injection vulnerability (CVE-2026-16812) affects Arista VeloCloud Orchestrator On-Prem, a core SD-WAN management platform. CISA has added this to its Known Exploited Vulnerabilities catalog with an unusually short 3-day remediation window, indicating active exploitation in the wild. Successful exploitation grants attackers privileged access to the orchestrator host, threatening confidentiality, integrity, and availability of the entire managed SD-WAN fabric.

fortinetfortiosnetwork-securitypost-exploitationpersistence-bypasscisa-kevedge-device

CVE-2025-68686 is a vulnerability in Fortinet FortiOS that allows a remote unauthenticated attacker to bypass a previously deployed patch addressing a symbolic link persistency mechanism used in post-exploitation scenarios. Exploitation requires prior compromise of the device at the filesystem level via another vulnerability, making this a persistence and detection-evasion enabler rather than an initial access vector. It has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild.

commentaryai-agentschatgptclaudecode-interpreteragent-modesux-confusionSurface: Human InterfacePropagation: None

This item is a commentary/roundup blog post about the current landscape of agentic AI products (ChatGPT Work/Codex, Claude Cowork/Code) and does not describe an exploit, vulnerability, or attack. It does note a UX point worth flagging for defenders: switching ChatGPT mobile from 'Chat' to 'Work' mode removes the Code Interpreter's normal restriction against internet access, which could have security implications if misunderstood by users, but no actual threat or exploitation is described.

agentic-commercepayment-hijackcredential-exposureprotocol-securitydeterministic-exploitcross-platformAIP-BenchPCATASI08 · Cascading FailuresSurface: ProtocolPropagation: Single Hop

Researchers identify 33 protocol-level vulnerabilities across three leading agentic commerce platforms, achieving a 100% attack success rate independent of the AI model used, with three vulnerabilities chaining into a full payment hijack. This is a research paper (not an active exploit in the wild) demonstrating that agent-to-commerce-service protocols, not model behavior, are the primary structural risk in agentic payment systems.

research-paperindirect-prompt-injectionauthorization-contextbenchmark-gapagentdojowaspcontextual-securitynot-an-exploitASI02 · Tool MisuseSurface: PlannerPropagation: None

This is an academic paper (not an active exploit) arguing that current agent security evaluation is flawed because it judges actions by their content rather than by contextual factors like who authorized them and whether they align with the agent's actual task. The authors propose a four-property contextual framework and note that popular benchmarks (AgentDojo, WASP) structurally cannot distinguish legitimate requests from prompt injection because both often look like the same plausible action. There is no new vulnerability, exploit, or proof-of-concept here—only a conceptual critique and reframing of how defenses and benchmarks should be designed.

SSRFprompt-injectiontool-poisoningdenylist-bypassDNS-rebindingredirect-bypassauto-approveMCP-toolinternal-network-accessASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

Kimi Code's FetchURL tool uses a static hostname/IP denylist to prevent server-side request forgery, but it never resolves DNS or re-checks the target after HTTP redirects, so an attacker can trick the agent into fetching internal resources anyway. Because FetchURL is auto-approved by default, an attacker who controls or injects content into the agent's context (e.g., via prompt injection) can trigger this without any user confirmation. This effectively turns a hardened-looking safety control into a bypassable one, exposing internal network services to the LLM agent's network position.

ransomware-as-a-serviceRaaSaffiliate-modelDevManFunky MantisPRODAFTextortion

DevMan is a ransomware-as-a-service operation running a centralized web portal that lets affiliates build custom payloads, track victim status, and manage payouts. PRODAFT is tracking the broader operator infrastructure under the name Funky Mantis, indicating a structured, business-like criminal enterprise lowering the barrier to entry for ransomware deployment. The centralized tooling suggests active recruitment and scaling of affiliates, increasing the likely volume and diversity of attacks.

Cl0pFIN11ransomwaredata-extortionPLMRCEpre-authPTC-WindchillFlexPLM

Cl0p-affiliated threat actors (FIN11, Graceful Spider, Lace Tempest) are exploiting internet-exposed PTC Windchill and FlexPLM PLM software through a chained vulnerability enabling unauthenticated remote code execution. The campaign appears focused on data theft and extortion rather than traditional file encryption, consistent with Cl0p's established MO of mass exploitation of enterprise file transfer and PLM platforms.

phishingcredential-theftreal-time-hijackingsession-hijackinginsurance-sectorfinancial-fraudsocial-engineeringadversary-in-the-middle

CTM360 researchers identified a shift in insurance-sector phishing campaigns from traditional credential harvesting to real-time account hijacking, where stolen credentials and session tokens are used immediately to take over accounts before victims can react. This evolution suggests attackers are increasingly leveraging automated relay infrastructure or adversary-in-the-middle (AiTM) techniques to bypass MFA and act on stolen sessions within seconds of capture.

outagecloud-reliabilitymicrosoft365azureavailabilityno-malicious-activity

Microsoft confirmed that a bug in its automated network maintenance request system caused a widespread outage affecting Microsoft 365 and Azure services. The bug erroneously removed IP routes from more network devices than intended, disrupting connectivity and service availability. This was a self-inflicted operational failure, not the result of a cyberattack or malicious activity.

outageavailabilityopenaichatgptagent-relevant

OpenAI confirmed a worldwide outage affecting ChatGPT connectivity, disrupting user access to the chatbot service. No evidence suggests this was caused by a malicious attack; it appears to be an availability incident rather than a security breach.

supply-chainpackage-securitygithubpypidependabotdefensive-measureagent-relevantopen-source-security

GitHub and PyPI have rolled out a time-based defense mechanism within Dependabot to reduce the risk and blast radius of supply-chain attacks against open-source packages. This is a defensive/protective development rather than an active threat, aimed at limiting exposure windows for malicious or compromised dependency updates.

ICSOTindustrial-control-systemsCISAplaintext-passwordconfused-deputypass-the-hashweak-encryptioncritical-infrastructure

Panduit IntraVUE versions 3.2.1a14 and earlier contain five vulnerabilities, including a critical confused-deputy proxy flaw (CVSS 10) that allows attackers with IT network access to bypass OT segmentation and manipulate industrial control devices without authentication. Additional flaws expose plaintext credentials via the API, leak host/share filesystem and asset information to unauthenticated users, and use weak encryption enabling pass-the-hash admin credential theft. CISA advises upgrading to version 3.2.1a16 or later; no known public exploitation has been reported to date.

MCPauthorization-bypasslocal-attacknanocoaiNanoClawtool-approvalASI06 · Memory PoisoningSurface: ProtocolPropagation: Single Hop

A vulnerability in NanoClaw's MCP Server Approval component allows a local attacker to bypass authorization checks in the createChatSdkBridge.setup function, potentially approving or manipulating MCP server connections without proper consent. The flaw requires local access and has a public exploit available, but the vendor has not yet responded to the disclosure. Severity is moderate due to the local attack vector constraint, though the improper authorization could undermine trust in MCP server approval workflows.

gitlabrceproof-of-conceptauthenticated-exploitjupyter-notebookheap-leakgitsource-code-managementagent-relevant

A public proof-of-concept exploit now lets any authenticated user with push access to a GitLab project execute arbitrary commands as the 'git' user on unpatched self-managed GitLab 18.11.3 instances. GitLab shipped a fix six weeks before the PoC was released, meaning organizations that have not applied the patch are immediately exposed to remote code execution. Because GitLab often hosts CI/CD pipelines, secrets, and automation scripts used by AI agent and MLOps workflows, this flaw poses a direct risk to agent-integrated development environments.

fastjsonjavarceunpatchedspring-bootzero-dayagent-relevantsupply-chain-risk

Attackers are actively exploiting an unpatched critical vulnerability in Fastjson 1.x, Alibaba's widely used JSON serialization library for Java, to achieve unauthenticated remote code execution in Spring Boot applications. Security firms ThreatBook and Imperva have observed live exploitation attempts, and no official patch is currently available, leaving deployed systems exposed. The flaw allows a crafted JSON request to trigger code execution with the privileges of the underlying Java process.

malvertisingwindowsfake-cryptosocial-engineeringevasionbun-runtimetrading-platforms

SourTrade is a malvertising campaign active since late 2024 that impersonates trusted brands like TradingView, Solana, and Luno to lure retail traders and crypto investors. It uniquely constructs its malicious Windows executable client-side, in the victim's browser, using a legitimate Bun JavaScript runtime as its base, avoiding detection by never serving a single complete malicious binary from a static URL.

sextortiondata-breachextortionemail-scamShinyHunterssocial-engineering

Threat actors are leveraging email addresses and personal data leaked by the ShinyHunters extortion group to send mass sextortion emails demanding $2,000 in Bitcoin. The scam uses previously breached data to add false credibility, threatening victims with fake claims of compromising webcam footage or browsing history unless payment is made.