Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 1541 threats
Apache Doris versions prior to 3.1.0 expose Frontend (FE) HTTP REST administrative APIs without proper authentication enforcement, allowing unauthenticated network attackers to perform privileged administrative operations. This can lead to cluster instability, unauthorized configuration changes, or denial of service against the analytics cluster.
A flaw in Perl's regex engine (Perl_study_chunk) causes silent match corruption when an alternation pattern contains more than 65535 fixed-string branches, due to a 16-bit field overflow during trie compilation. This can produce false positive or false negative matches with no warning, undermining any security or filtering logic that relies on such patterns.
CVE-2026-57830 is a critical vulnerability in the Helix Ultimate Joomla extension that allows unauthenticated attackers to delete arbitrary files on the underlying server. This could lead to denial of service, configuration file loss, or destruction of critical application data without requiring any authentication.
CVE-2026-15410 is a code injection vulnerability in SonicWall SMA1000 Appliances that allows an authenticated remote attacker with administrator privileges to execute arbitrary OS commands. The flaw has been added to CISA's Known Exploited Vulnerabilities catalog, indicating confirmed active exploitation in the wild. Organizations using SMA1000 for secure remote access are urged to remediate under an accelerated timeline.
CVE-2026-56164 is a missing authentication for critical function vulnerability in Microsoft SharePoint Server that allows an unauthorized, remote attacker to elevate privileges over the network. CISA has added this CVE to its Known Exploited Vulnerabilities (KEV) catalog with an aggressive three-day remediation deadline, indicating active exploitation in the wild. Organizations running on-premises SharePoint Server deployments should treat this as an urgent patching priority.
CVE-2026-56155 is a known-exploited privilege escalation vulnerability in Microsoft Active Directory Federation Services (ADFS) caused by insufficient granularity of access control. It allows an authorized but low-privileged attacker to elevate privileges locally, potentially leading to compromise of federated identity infrastructure. CISA has added it to the Known Exploited Vulnerabilities catalog with a remediation deadline of July 28, 2026.
This is a Simon Willison blog post describing a fun, benign feature of OpenAI's Codex Desktop app: an animated desktop 'pet' (a pelican on a bicycle) created using gpt-image-2 and open-source skill scripts. There is no security vulnerability, exploit, or malicious activity described in this content.
The mastergo-magic-mcp MCP server (versions up to 0.2.0) contains a server-side request forgery vulnerability in its getComponentLink tool, caused by insufficient validation of the url argument passed to a z.string schema check. A remote attacker can supply a crafted URL to make the MCP server issue requests to arbitrary internal or external endpoints. A public exploit exists and the vendor has not yet responded to the disclosure.
The AWS HealthLake MCP Server fails to validate that pagination URLs returned via the next_token parameter point back to the legitimate HealthLake endpoint, enabling an authenticated user to redirect the server's outbound requests to an attacker-controlled endpoint. This can leak AWS temporary security credentials used by the MCP server, giving an attacker a foothold to access AWS resources tied to those credentials. Fixed in version 0.0.14.
This is a quoted essay excerpt from Armin Ronacher discussing how shared understanding in software projects is built through human friction, and how AI coding agents affect that process. It contains no technical details about vulnerabilities, exploits, or attacks against AI agents, and is purely a philosophical/editorial commentary piece.
Researchers demonstrate that malicious text placed in the physical environment (e.g., signs, labels) can be captured by camera-equipped smart glasses and hijack the behavior of Vision-Language Models, causing them to ignore true visual context and produce harmful, biased, or false outputs. This is a research paper describing a demonstrated but not actively exploited class of attack, with success rates up to 96% in simulation and 60% in real-world tests across 12 VLM models.
This is an academic benchmark paper (NetInjectBench), not an active exploit, demonstrating that LLM agents used for network operations can be manipulated via indirect prompt injection embedded in tickets, alerts, logs, and ChatOps messages to trigger unsafe tool actions. The researchers show naive agents execute unsafe actions 82.5% of the time under attack, but a metadata-aware execution-time policy gate can reduce this to near-zero while preserving usefulness. The severity is rated medium because this is defensive research quantifying and mitigating a known risk class rather than a disclosed vulnerability in a specific deployed product.
Researchers demonstrate that an adversary can poison an open dataset with misleading metadata and upload it to a public repository, causing autonomous AI research agents (built on Claude, GPT, Gemini) to unknowingly retrieve and use the poisoned data, producing fraudulent scientific conclusions in nearly half of tested runs. No prompt injection, agent compromise, or fabricated papers are needed — only manipulation of the open data ecosystem — and current agents rarely detect the poisoning (6% detection rate), though provenance auditing fully mitigates it in testing.
This is an academic research paper, not an active exploit or attack. The authors built MCPZoo, a large dataset of runnable MCP servers, and found that existing MCP security scanners are unreliable: they flag ~97% of servers as risky, but fewer than half of sampled alerts are true positives, and different scanners disagree substantially with each other.
A CISA contractor inadvertently published dozens of sensitive internal credentials, including AWS GovCloud keys, in a public GitHub repository where they remained exposed for nearly six months before external notification by a security journalist. The incident highlights systemic weaknesses in secrets management, contractor oversight, and detection capability within a federal cybersecurity agency, raising concerns about the broader public and private sector's exposure to similar risks.
This weekly recap highlights multiple concurrent threats including exploitation of ShareFile vulnerabilities, ransomware campaigns leveraging the 'Citrix Bleed 2' flaw, and a rising trend of attackers using AI coding tools to accelerate exploit development. The report underscores how unpatched, previously disclosed vulnerabilities continue to be actively exploited due to delayed remediation, and how trusted software supply chains are increasingly weaponized against their own users.
CrashStealer is a newly identified macOS information stealer written in native C++ that uses a notarized dropper to bypass Gatekeeper security checks. Unlike typical macOS stealers built with AppleScript or Objective-C wrappers, its native implementation and local password validation suggest a more sophisticated, evasion-focused development approach. The malware is designed to harvest sensitive data from compromised systems, including credentials and stored secrets.
CrashStealer is a newly identified macOS information-stealing malware that disguises itself as Apple's legitimate crash-reporting utility to gain user trust and system access. Once executed, it harvests saved credentials, macOS Keychain data, and cryptocurrency wallet files, exfiltrating them to attacker-controlled infrastructure. Its impersonation of a trusted system tool makes it likely to evade casual user scrutiny and some endpoint defenses.
A threat actor compromised the Jscrambler npm package and published a malicious version containing infostealer malware, which was downloaded nearly 1,500 times before detection. This represents a supply chain attack targeting developers and CI/CD pipelines that depend on the Jscrambler client-side web security tooling.
Nihon Kotsu, Japan's largest taxi operator, suffered a cyberattack that forced the company to shut down parts of its IT infrastructure. Details on the attack vector, threat actor, and data impact have not been disclosed. The incident highlights ongoing targeting of transportation and logistics companies by threat actors.