Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 1485 threats

network-infrastructurearubaos-cxrcehpepatch-availableagent-relevant

HPE has released patches for a critical remote code execution vulnerability in ArubaOS-CX, the network operating system powering Aruba switches. Exploitation could allow attackers to gain control over network infrastructure, potentially enabling lateral movement and traffic interception across enterprise environments.

supply-chainterraformcloudflarecredential-theftregistry-compromiseiacagent-relevant

Attackers gained unauthorized access to Coder's Cloudflare-hosted registry infrastructure and inserted rogue registry servers distributing trojanized Terraform modules. These malicious modules contained credential-stealing code, potentially exposing secrets and cloud credentials for any environment that pulled infrastructure definitions from the compromised registry.

data-breachhealthcareregulatory-fineGDPRprivacy

France's data protection authority (CNIL) fined Hôpital privé de la Loire €500,000 for failing to adequately protect the personal data of 727,000 patients and their relatives. The breach exposed sensitive health-related information, highlighting inadequate security controls and non-compliance with GDPR data protection obligations.

ICSOTprivilege-escalationlocal-attackinstaller-vulnerabilityCWE-250OPC-UA

A local privilege escalation vulnerability exists in the OPC UA LocalDiscoveryServer (LDS) installer prior to version 1.04.420, allowing an attacker with local keyboard/display access during installation to hijack a high-privilege console window and execute arbitrary commands. Exploitation requires local access and user interaction, limiting remote attack potential, but could lead to full system compromise on affected industrial control hosts.

ICSSCADAcritical-infrastructureprivilege-escalationdefault-configurationIgnitionCWE-276

Inductive Automation Ignition versions 8.1.53 and earlier ship with a blank 'Create Project Role(s)' setting, allowing any authenticated user capable of executing gateway scripts to create projects without proper authorization. This default misconfiguration affects widely deployed industrial control system software across Critical Manufacturing, Energy, and IT sectors worldwide, with no known public exploitation reported at this time.

ICSOTdenial-of-serviceCIP-protocolRockwell-AutomationEtherNet-IPindustrial-control-systemsCISA-advisory

A high-severity denial-of-service vulnerability (CVE-2025-10478) affects all versions of the Rockwell Automation 1756-ENBT ControlLogix EtherNet/IP bridge module. An attacker can send a crafted CIP packet to crash the module, requiring a manual restart to restore functionality, potentially disrupting industrial communications in critical infrastructure environments.

mozillathunderbirdfirefoxmemory-corruptionbrowser-securityemail-client

A set of internally discovered memory corruption bugs affecting Thunderbird and its ESR branches could potentially be exploited to achieve code execution. Mozilla has patched the issue across Firefox and Thunderbird release and ESR channels, and no public exploitation has been confirmed at this time.

thunderbirdfirefoxmemory-corruptionmozillabrowser-securityemail-client

Internal security research identified multiple memory corruption bugs in Thunderbird 154 that could potentially be exploited by attackers. Mozilla has patched these issues in Thunderbird 155 and Firefox 155, though no public exploitation has been confirmed. The high CVSS score reflects the potential severity if these flaws were weaponized.

browser-vulnerabilityinteger-overflowfirefoxthunderbirdmemory-corruptionrceagent-relevant

A critical integer overflow vulnerability has been identified in the Graphics: ImageLib component of Mozilla Firefox and Thunderbird, carrying a CVSS score of 9.8. The flaw could allow attackers to achieve memory corruption and potentially remote code execution through crafted image content. Mozilla has released patches in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

browser-vulnerabilitysite-isolationfirefoxthunderbirdmozillarce-potentialagent-relevant

A critical site isolation flaw in the DOM Navigation component affects Firefox, Firefox ESR, and Thunderbird, potentially allowing cross-origin data leakage or sandbox bypass. With a CVSS score of 9.8, successful exploitation could let attackers bypass browser security boundaries to access sensitive cross-site data. Mozilla has released patches in Firefox 155, Firefox ESR 153.2, and Thunderbird 155/153.2.

browsermobileandroidfirefoxpatch-available

A vulnerability described only as 'Other issue' has been identified in Firefox Focus for Android, carrying a CVSS score of 9.8, indicating potential for severe impact if exploited. The issue has been resolved in Firefox 155, and the vagueness of the public description suggests Mozilla has withheld technical details pending broader patch adoption.

model-releasebenchmarkllm-announcementno-security-issueSurface: ModelPropagation: None

This item is a news post from Simon Willison summarizing OpenAI's announcement of a new model, GPT-6 Astra, including pricing and benchmark comparisons against Claude Fable and other models. It contains no information about a security vulnerability, exploit, or threat to AI agents, frameworks, or protocols.

codexmcpcommand-injectionpowershellapproval-bypasssandbox-escapegitsupply-chain-repoASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

OpenAI Codex CLI and Desktop failed to correctly parse PowerShell's stop-parsing token (--%), causing malicious commands to be misclassified as safe and auto-approved. An attacker who gets a user to open a poisoned repository can trick Codex into running an unapproved file-writing Git command that rewrites Codex's own configuration, ultimately allowing it to launch an attacker-controlled MCP server and execute code with the user's privileges.

wordpress-pluginmcpbroken-access-controlprivilege-escalationllms.txtai-seoASI08 · Cascading FailuresSurface: Tool LayerPropagation: Single Hop

A WordPress plugin that exposes an MCP interface and llms.txt generation for AI agents contains a broken access control flaw allowing low-privileged Subscriber-level users to perform actions reserved for higher-privilege roles. This could let an attacker with minimal site access escalate privileges or manipulate AI-agent-facing configuration and content. No evidence of active exploitation is provided in the raw data, but the CVSS score indicates meaningful impact if exploited.

threat-intelligencelatin-americadata-exfiltrationopsecattacker-tradecraftSurface: Human InterfacePropagation: None

This report from Unit 42 describes conventional threat actors using AI tools as part of their tooling to exfiltrate data from Latin American organizations, and highlights operational security mistakes that allowed defenders to disrupt them. The raw data provided is only a brief press-release style teaser with no technical detail on agent-specific vulnerabilities, prompt injection, tool poisoning, or inter-agent exploitation, so no genuine agentic-AI security threat can be substantiated from this content alone.

researchdefensive-proposalMCPA2Askill-privacyprompt-injection-surfaceconfidential-computingmulti-agent-coordinationASI05 · Unsafe Code ExecutionSurface: Inter Agent CommsPropagation: None

This is an academic research paper proposing a new protocol-layer defense (Skill-as-API) rather than a report of an active exploit. It identifies a legitimate design weakness in current agent coordination protocols like MCP and A2A: they expose full skill descriptions, schemas, and potentially system prompts to all peers, and offer no mechanism to hide skill existence or narrow the prompt-injection surface structurally. Severity is low because this is a proactive mitigation proposal, not evidence of exploitation in the wild.

researchMCPA2Alabel-manipulationdata-egressconfidentiality-labelingmulti-model-studycross-protocolcontrolled-experimentASI02 · Tool MisuseSurface: Inter Agent CommsPropagation: Single Hop

This is a controlled academic study (not an active exploit) showing that when an agent pulls data via MCP and then relays it to another agent via A2A, simply attaching a 'PUBLIC - OK TO SHARE' label to a record can increase the odds that sensitive substantive field values are copied verbatim into outbound messages, compared to unlabeled data. The effect is strongly model-dependent (pronounced in one Claude model, weaker or floor-limited in GPT-5.6 tiers) and the paper is explicit that this is an association in one configuration, not a proven general or causal effect. Severity is modest because it is a research finding highlighting a labeling/trust-heuristic weakness rather than a demonstrated in-the-wild attack.

audit-loggingforensicsdefensive-researchon-chain-anchoringtamper-evidencelong-horizon-agentsnot-an-exploitASI09 · Human Trust ExploitationSurface: Tool LayerPropagation: None

This is a defensive research paper describing a system for tamper-evident logging and forensic auditing of AI agent actions, not an active exploit or vulnerability. It proposes hash-chained, Merkle-batched, on-chain-anchored audit trails to help detect and investigate incidents like cascading tool-use failures or prompt injection spread after the fact. Severity is low because the content describes a mitigation/monitoring tool rather than a threat vector.

skill-selectionsemantic-manipulationtool-poisoningprompt-injection-evasionguardrail-bypassplugin-ecosystemresearchASI05 · Unsafe Code ExecutionAML.T0051AML.T0054Surface: PlannerPropagation: Single Hop

Researchers demonstrate a novel attack (ISM) that manipulates which skill/tool an LLM agent selects by crafting benign-looking skill metadata and prompts whose semantic relationship is engineered to bias the selector, without any explicit steering instructions. This bypasses human review and existing prompt-injection defenses far more effectively than explicit instruction-based attacks, raising the target-selection rate from ~15% baseline to ~63-73%.

researchprovenancememory-poisoningdefensive-mechanismformal-verificationautobiographical-memoryprompt-injection-mitigationASI05 · Unsafe Code ExecutionAML.T0051AML.T0048Surface: MemoryPropagation: None

This is a defensive research paper, not an active exploit or vulnerability disclosure. It formally describes how persistent AI agents can be poisoned when untrusted inputs (including prompt injections or unverified model inferences) get stored and later recalled as if they were verified agent history or user commitments, and proposes a typed provenance/guardrail system to prevent this. The core contribution is a mitigation architecture, evaluated against a small hand-authored conformance suite, not a report of a real-world attack.