Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 527 threats
Threat actors are using commodity infostealer malware (Lumma Stealer, Vidar, and similar families) to harvest session tokens, credentials, and API keys from systems accessing AI platforms like Google and Anthropic. These stolen, replayable tokens allow attackers to bypass MFA entirely and gain persistent illicit access to AI accounts and their connected tooling without needing to re-authenticate.
Healthcare company AdaptHealth confirmed that a July cyberattack attributed to the ShinyHunters threat group exposed personal data of 4.1 million individuals. The incident highlights ongoing targeting of healthcare organizations for large-scale data theft and extortion rather than encryption-based ransomware.
Dell SCG 5.0 Appliance and Application versions prior to 5.36.00.16 and 5.36.00.00 respectively contain an improper certificate validation flaw that allows unauthenticated remote attackers to gain unauthorized access. This vulnerability likely enables man-in-the-middle attacks or certificate spoofing, undermining trust boundaries within the affected infrastructure.
CVE-2026-80131 is a path traversal vulnerability in Dell SCG 5.0 Appliance and Application prior to versions 5.36.00.16 and 5.36.00.00 respectively. An unauthenticated remote attacker can exploit this flaw to escape restricted directories and achieve remote code execution on the affected system.
Microsoft released its largest-ever monthly patch batch, addressing approximately 974 security vulnerabilities across Windows and other Microsoft products. The company attributes part of the surge in discovered flaws to AI-assisted vulnerability research, while security experts caution that the scale of the release will strain organizations' ability to test and deploy fixes in a timely manner. Delayed patching windows increase exposure time to any of the disclosed flaws being weaponized.
An attacker exploited a bug in the Elements software underlying the Liquid Network, a Bitcoin sidechain, to steal nearly 4,000 BTC. The following day, 3,400 BTC was returned, leaving approximately 598.5 BTC ($47M reported total held) unaccounted for, with the network still paused and L-BTC redemptions halted.
CrowdStrike has identified a new financially motivated threat actor, dubbed Slim Spider, targeting Brazilian financial institutions since at least March 2026. The group demonstrates deep knowledge of Brazilian financial infrastructure, including instant payment systems, and has been observed stealing crypto custody secrets from a targeted institution.
CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog affecting Adobe Commerce/Magento, Microsoft Windows, and N-able N-central, all confirmed under active exploitation. FCEB agencies must remediate per BOD 26-04, and CISA urges all organizations to prioritize patching given the demonstrated real-world attack activity.
A joint NSA/CISA/FBI advisory describes China-based AI companies (DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, Z.AI) conducting large-scale, systematic extraction of proprietary capabilities from U.S. frontier AI models (Claude, GPT, Gemini, Grok) via automated API abuse, evasion of geographic/usage restrictions, and prompt-based chain-of-thought extraction. This is a genuine, well-documented threat to model IP and competitive advantage rather than a fabricated or exaggerated claim, though it is an economic/espionage concern rather than a direct system-compromise vulnerability.
CVE-2026-85880 is a heap-based buffer overflow in Microsoft Windows Advanced Local Procedure Call (ALPC) that enables local privilege escalation. The vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation in the wild, with a remediation deadline of September 22, 2026.
CVE-2026-81963 is a local privilege escalation vulnerability in the Microsoft Windows Update Stack caused by improper handling of file system links, allowing a local attacker to gain SYSTEM-level privileges. The flaw has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, with a remediation deadline of September 22, 2026.
Researchers demonstrate a black-box adaptive image-based prompt injection attack ('Repeat-After-Me') that reliably hijacks frontier vision-language models into leaking PII or issuing malicious tool calls, even when the user's actual prompt has nothing to do with the injected task. In a real-world OpenClaw Discord agent deployment, the attack allowed an untrusted image to overwrite TOOLS.md, opening a path to remote code execution and secret exfiltration.
An MCP server fails to sanitize filesystem path arguments passed to its tools, allowing an attacker to read, create, overwrite, or delete files outside the intended project directory. This is a classic path traversal vulnerability exposed through an AI agent tool interface, giving attackers a direct route to filesystem compromise via crafted tool calls.
This weekly recap covers multiple active threats including a Chrome 0-day, router hijacking campaigns, and a notable supply chain attack against the Coder platform that resulted in credential theft. Attackers also demonstrated a novel phishing technique using text-rendered QR codes to bypass email image-blocking protections, and abused a network management protocol for malicious purposes.
A threat cluster is targeting executives (directors, VPs, senior staff) at organizations using Microsoft 365 and other SaaS platforms through IT help desk vishing calls, adversary-in-the-middle (AitM) session token theft, and sign-ins routed through residential proxy networks to evade geolocation-based detection. Stolen credentials and session tokens are used for data exfiltration followed by extortion demands. The campaign leverages human trust in IT support workflows rather than software exploits, making it effective against organizations with strong technical controls but weaker identity-verification processes.
PEEP is a post-compromise toolkit that disguises itself as a bookmarks extension for Chrome and Edge, requiring prior administrative or code execution access to deploy. It forges Chromium's Secure Preferences file to bypass Web Store validation and user consent prompts, effectively turning the browser into a persistent backdoor capable of executing host commands.
Online mathematics learning platform Mathspace disclosed a data breach affecting over 1 million students, staff, and parents after attackers compromised its Metabase internal reporting system. The breach exposed personal data likely including names, emails, and academic records tied to a widely used education platform. No technical details on the intrusion vector into Metabase have been disclosed.
BigBear 2.0, a phishing-as-a-service (PhaaS) platform, has been used to compromise 258 organizations and steal over 5,000 Microsoft 365 credentials by bypassing multi-factor authentication via adversary-in-the-middle (AiTM) reverse-proxy techniques. The kit lowers the barrier to entry for large-scale credential phishing campaigns and has demonstrated broad reach across sectors relying on Microsoft 365 for identity and collaboration.
A high-severity vulnerability (CVE-2026-4827) affecting numerous Schneider Electric Easergy, EcoStruxure, PowerLogic, and Saitel protection relays, RTUs, gateways, and SCADA/HMI software stems from insufficient entropy in session token generation. An attacker on the network could exploit weak session-management protections to hijack sessions and perform unauthorized operations on critical electrical grid control and protection devices.
Elastic Security Labs identified four previously unreported programs linked to REVSTEALER, a Windows information stealer, that persist on infected machines after the stealer removes itself. One module disables Windows Update and Microsoft Defender to covertly deploy a cryptocurrency miner, indicating an evolution from pure credential theft toward long-term system abuse.