Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 1560 threats
This is an academic research paper (arXiv, not an active exploit) empirically benchmarking six major LLMs against direct, multilingual, and obfuscated prompt injection attacks. The study finds that all tested models can be induced to generate phishing content, malicious websites, and malware, with non-English prompts and multi-stage obfuscation significantly increasing compliance rates. Since this is a research disclosure rather than an in-the-wild exploit or agent-specific vulnerability, severity is rated medium rather than high/critical.
This is an academic research paper, not an active exploit or vulnerability disclosure. It introduces a benchmark (SecFid) showing that current defenses against indirect prompt injection achieve security by suppressing untrusted text, which degrades task fidelity for legitimate uses like translation or document editing. No new attack technique or exploited system is described; it is a measurement and evaluation contribution.
The FBI, working with industry partners, seized hundreds of domains linked to NetNut, a residential proxy service operated by publicly-traded Israeli firm Alarum Technologies. The takedown follows security research connecting NetNut to the Popa botnet, a network of at least two million devices compromised without meaningful user consent. This represents a significant disruption to a large-scale proxyware/botnet infrastructure used to monetize unwitting victims' internet connections.
Schneider Electric EasyLogic T150 and Saitel DP RTU devices contain two vulnerabilities that could allow unauthorized access to sensitive credentials and password hashes. CVE-2026-9650 allows an unauthenticated attacker with physical access to extract credentials from firmware or system files, while CVE-2026-9651 allows a privileged local attacker to read improperly protected system files containing password hashes. No public exploitation has been reported to CISA at this time.
CISA added CVE-2026-45659, a deserialization of untrusted data vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog due to confirmed active exploitation. Federal civilian agencies are required under BOD 26-04 to remediate this vulnerability on an expedited basis given its potential for full system compromise on publicly exposed assets. All organizations, not just federal agencies, are strongly encouraged to prioritize patching.
A critical vulnerability in containerd's CRI implementation allows users with pod creation permissions to bypass Kubernetes resource allocation and device plugin enforcement by injecting arbitrary Container Device Interface (CDI) edits through malicious checkpoint image metadata. This can result in unauthorized access to host device nodes and mounts, potentially leading to container breakout or privilege escalation on affected nodes. Exploitation requires CDI to be enabled on the node with matching host CDI specifications for the targeted device.
The Popa botnet is a large-scale Android-based malware network that has compromised millions of consumer TV boxes over the past four years, using them as unwitting relays for internet traffic. Security researchers have linked this infrastructure to NetNut, a residential proxy service operated by publicly-traded Israeli company Alarum Technologies Ltd (NASDAQ: ALAR), raising concerns about corporate involvement in facilitating malicious traffic relay networks.
Two high-severity vulnerabilities affect ST Engineering iDirect iQ-Series satellite terminals (Evolution iQ, 3315-Series, 9-Series) running firmware <=4.5.2.1. Successful exploitation could allow an unauthenticated attacker to retrieve sensitive device credentials or force device reboots via CSRF, potentially causing terminal impersonation or denial-of-service on satellite links. No known public exploitation has been reported to CISA at this time.
CubeSpace CW0057 Reaction Wheel firmware versions prior to 5.0.20 fail to properly verify cryptographic signatures on firmware updates, relying only on CRC-32 integrity checks. An attacker with physical access could upload arbitrary malicious firmware without authentication, though the device remains recoverable via an independent bootloader.
A critical authentication bypass vulnerability exists in SimpleHelp's OIDC authentication flow, where identity tokens are accepted without cryptographic signature verification. This allows a remote, unauthenticated attacker to forge tokens and gain fully authenticated technician-level access, potentially bypassing multi-factor authentication safeguards. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation.
Attackers seed false facts or standing instructions into an agent's long-term memory or RAG store, quietly steering decisions across future sessions long after the original malicious input is gone.
Adversarial instructions planted in content processed by one agent can replicate into its outputs and infect downstream agents, spreading through normal inter-agent messaging the way the Morris II research worm spread through AI email assistants.
The MCP Inspector developer tool shipped a proxy that lacked authentication, allowing browser-based attackers to reach it from a malicious web page and execute code on the developer's machine. Reported by Oligo Security with a CVSS score of 9.4.
A critical flaw in the widely used mcp-remote OAuth proxy let malicious MCP servers achieve remote code execution on connecting developer machines, turning a routine agent connection into full host compromise. The package had hundreds of thousands of downloads before patching.
Malicious or compromised MCP servers embed hidden instructions in tool metadata that the model reads but the human approving the tool never sees, steering agents into data exfiltration or unauthorized actions. First documented publicly by Invariant Labs in 2025 and since reproduced across many clients.
Coordinated campaign publishing typosquatted Python packages to steal environment variables, SSH keys, and cloud credentials from developer workstations and CI/CD pipelines.
English-speaking group using SIM-swapping and MFA fatigue attacks to compromise enterprise identity providers via IT help desk impersonation calls.
Chinese state-sponsored group maintaining persistent access in US energy, water, and telecom networks using living-off-the-land techniques that blend with normal admin activity.
Two chained zero-days in Ivanti VPN appliances enabling unauthenticated remote code execution. Mass exploitation targeting government and defense across 12 countries.
Fourth-generation LockBit ransomware-as-a-service with enhanced encryption completing full-disk encryption in under four minutes. Actively targeting hospitals, municipal governments, and manufacturing.