Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 1541 threats
A newly disclosed Linux kernel vulnerability dubbed 'Bad Epoll' (CVE-2026-46242) allows an unprivileged local user to escalate privileges to root, affecting Linux desktops, servers, and Android devices. A patch has already been released, but unpatched systems remain fully exploitable by any local user or process with code execution.
This article reports user dissatisfaction with the relaunch of 'Claude Fable,' a model reported to underperform relative to its original release. This is a product quality/performance issue, not a security vulnerability, breach, or malicious campaign.
This item is a product/business announcement, not a cybersecurity threat. Anthropic is temporarily removing a Claude model variant from its usage-based subscription plans starting July 7, with plans to reinstate access later.
This item is a product/business update reporting that Flipper Devices will continue developing Flipper Zero firmware with a smaller internal team and increased reliance on community contributions. It is not a disclosed vulnerability, exploit, or active threat campaign, but a governance and development-model change for a widely used pentesting/hardware hacking tool.
StoneFly Storage Concentrator (SC) and its Virtual Machine variant contain five critical/medium vulnerabilities including hardcoded credentials, two unauthenticated OS command injection flaws leading to root-level remote code execution, an unauthenticated SQL injection exposing session tokens and password hashes, and a reflected XSS. Combined, these flaws allow attackers to fully compromise storage infrastructure without authentication, potentially affecting Defense Industrial Base, Energy, Financial Services, Healthcare, and IT sector organizations worldwide.
A medium-severity XML External Entity (XXE) vulnerability affects Schneider Electric EcoStruxure IT Data Center Expert versions 9.1.1 and prior, allowing an authenticated attacker to disclose server-side file contents via crafted XML payloads to SOAP service endpoints. Schneider Electric has released version 9.1.2 to remediate the issue, and no known public exploitation has been reported.
A critical SQL injection vulnerability has been identified in Destekz, a product from Raera (Ankara Web Design and Digital Advertising Agency), with a CVSS score of 9.8. The vendor has confirmed the product is no longer supported, meaning no patch will be released, leaving all deployments permanently vulnerable to exploitation.
CVE-2026-14544 is an incomplete fix for the previously patched CVE-2026-8631, leaving an integer overflow in HPLIP's hpcups print-processing path exploitable via specially crafted print jobs. A remote attacker able to submit print data can trigger memory corruption leading to privilege escalation or arbitrary code execution on the host. With a CVSS score of 9.8, this represents a critical, low-complexity threat to any Linux system with HPLIP installed.
The Printcart Web to Print Product Designer plugin for WooCommerce (versions up to 2.5.2) contains a critical vulnerability allowing unauthenticated attackers to delete arbitrary files on the server. Combined with a bypassable nonce mechanism, this flaw could enable deletion of critical files such as wp-config.php, potentially leading to remote code execution and full site compromise.
This is a PortSwigger web security research post describing a CSS injection technique that exfiltrates attribute data via chained conditional CSS in inline style attributes, without needing selectors or stylesheet imports. It is a general web application security finding about browsers and CSS, with no relationship to AI agents, LLMs, agent frameworks, or agent-to-agent protocols such as MCP or A2A.
This item is a vendor blog post from Unit 42 discussing general risks of integrating third-party 'skills' or plugins into enterprise AI agents, and advocating for integrity verification practices. It does not describe a specific vulnerability, exploit, or active threat, so it is classified as low severity informational content rather than a genuine incident.
This item is a promotional blog post from Unit 42 about their SOC, MDR, and XSIAM services, framed around the statistic that attackers can move from initial access to exfiltration in 72 minutes. It does not describe any specific threat, vulnerability, or technique involving AI agents, agent frameworks, or agent protocols, so no genuine security issue can be extracted from it.
This Unit 42 research describes a cloud storage misconfiguration risk where attackers exploit globally unique bucket namespaces across cloud service providers to hijack references to deleted or unclaimed buckets, redirecting data intended for legitimate storage to attacker-controlled buckets. This is a traditional cloud infrastructure security issue and does not involve AI agents, agent frameworks, agent protocols (MCP/A2A), or inter-agent communication in any way. Severity is rated low strictly for relevance to AI agent security; the underlying cloud risk itself may carry higher severity in a pure cloud-security context, but that is out of scope here.
Unit 42 identified malicious 'skills' distributed through OpenClaw's ClawHub marketplace that evade automated security scanning to deploy infostealer malware and carry out agentic financial fraud. This represents a supply chain threat where trusted third-party agent extensions become a vector for compromising the host system and any credentials or financial capabilities the agent has access to.
This item is a promotional/informational OWASP blog post announcing that its Agentic AI Threats and Mitigations taxonomy is being adopted by third-party tools (PENSAR, SPLX.AI Agentic Radar, AI&ME) and previewing an upcoming OWASP Top 10 for Agentic AI. It does not describe any vulnerability, exploit, or active threat, so no security risk is present in this data itself.
This item is a press release announcing that OWASP's GenAI Security Project published a Top 10 risks and mitigations list for agentic AI security. It is not a threat report, vulnerability disclosure, or incident; it describes a community guidance document rather than an active exploit or attack.
This item is an announcement from OWASP GenAI Security Project introducing their new Top 10 list for Agentic AI Applications, a community-driven security framework rather than a specific vulnerability or attack. It describes a taxonomy/guidance resource, not an active threat, exploit, or incident.
This item is a promotional announcement from OWASP GenAI Security Project about a new educational Capture-The-Flag environment called FinBot, designed to teach agentic AI security risks in a simulated financial services setting. It does not describe an actual vulnerability, exploit, or active threat, but rather a training tool for defenders and builders. No genuine security incident is present in this data.
This item is an OWASP Gen AI Security Project blog post discussing memory and context poisoning as a conceptual risk category (ASI06) for agentic AI systems, not a report of a specific active exploit or vulnerability. It explains why persistent agent memory can become an attack surface if untrusted input is carried forward and later trusted, but contains no technical exploit details, affected products, or indicators of compromise. Severity is set to low because this is educational/awareness content rather than a disclosed incident or vulnerability.
This is a conceptual/cultural commentary piece, not a disclosure of a specific vulnerability or exploit. It argues that organizations are gradually normalizing warning signs and over-reliance on LLM outputs in agentic systems, drawing an analogy to the Challenger disaster's 'normalization of deviance.' There is no concrete technical threat, proof-of-concept, or attack mechanism described.