Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 907 threats

agent-relevantai-abusellm-misuseautomated-exploitationstate-sponsoredcybercrimeagentic-aidata-theft

Anthropic disclosed that state-sponsored actors and financially motivated criminals have weaponized Claude models to automate reconnaissance, exploitation, and data exfiltration across multiple victims between December 2025 and August 2026. Anthropic has categorized these actors as Generative Threat Groups (GTGs), highlighting a shift toward AI-driven, semi-autonomous attack operations rather than solely human-directed intrusions. This represents a broader trend of adversaries operationalizing agentic AI capabilities to scale attacks with reduced manual effort.

ai-model-theftknowledge-distillationintellectual-propertyapi-abusellmanthropicterms-of-service-violationagent-relevant

Anthropic disclosed that it identified and disrupted large-scale illicit knowledge distillation operations targeting its Claude model, attributed to seven China-based AI labs including Alibaba, Moonshot, DeepSeek, Z.ai, and MiniMax. These operations allegedly used systematic, high-volume API querying of Claude to extract outputs used to train competing models, violating Anthropic's usage policies rather than exploiting a technical vulnerability.

gitlabpath-traversalunauthenticated-rcefile-readin-the-wild-exploitationsource-code-managementagent-relevant

GitLab disclosed a maximum-severity (CVSS 10.0) path traversal vulnerability in the repository commits API that allows unauthenticated attackers to read arbitrary files on the GitLab server. Active in-the-wild probing was observed within hours of public disclosure, indicating high urgency for patching. Organizations should treat this as an actively exploited zero-day and prioritize immediate remediation.

phishingsocial-engineeringmicrosoft-365credential-theftshinyhuntersextortionidentity-securityagent-relevant

Threat actors linked to ShinyHunters, Helix, and other extortion groups are conducting social engineering campaigns that abuse passkey and single sign-on registration flows to compromise corporate Microsoft 365 accounts. Stolen credentials and session data are used to exfiltrate sensitive organizational data for extortion purposes.

credential-theftdata-breachinsider-accessgovernmentlaw-enforcementthird-party-accesspii-exposure

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed unauthorized access to its DAVID (Driver and Vehicle Information Database) system after attackers used stolen credentials belonging to a police department employee. The breach highlights ongoing risks around third-party access to sensitive government databases containing driver and vehicle records. This incident is a data confidentiality and access-control failure rather than a malware or exploit-based intrusion.

AI-abuseLLM-misuseagent-relevantcredential-theftmobile-securitythreat-actor-toolingAPTsupply-chain-recon

Anthropic disclosed that multiple threat actors, including financially motivated criminals and state-sponsored groups linked to Russia and China, abused its Claude AI model to automate the extraction of secrets (API keys, credentials, tokens) from approximately 1.8 million Android applications. This represents a significant escalation in adversarial use of AI systems to scale reconnaissance and credential-harvesting operations that would traditionally require substantial manual analyst effort.

healthcareICSmedical-deviceSQL-injectionXXEdata-exfiltrationdenial-of-serviceHL7integration-engine

NextGen Healthcare Mirth Connect versions 4.7.1 and earlier contain three high-severity vulnerabilities including an authenticated SQL injection flaw and two XML External Entity (XXE) injection issues that can lead to credential disclosure, arbitrary file write, data exfiltration, and denial-of-service. These flaws affect a widely deployed healthcare data integration engine used to route and transform clinical messages (HL7, XML) across systems worldwide. No known public exploitation has been reported to CISA at this time, but the vendor has released a patched version (4.7.2) to address all three issues.

CISAKEVGitLabpath-traversalvulnerability-managementactive-exploitationagent-relevant

CISA has added CVE-2026-85706, a path traversal vulnerability in GitLab Community Edition and Enterprise Edition, to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation. Federal agencies are required under BOD 26-04 to remediate this vulnerability on a prioritized timeline, and CISA urges all organizations to do the same given evidence of in-the-wild attacks.

known-exploited-vulnerabilitiesCISAKEVJFrogArtifactoryConnectWiseScreenConnectauthentication-bypassprivilege-escalationsupply-chainremote-access-toolagent-relevant

CISA has added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog affecting JFrog Artifactory and ConnectWise ScreenConnect. These flaws involve improper authentication and authorization controls that could allow attackers to bypass access restrictions and gain unauthorized privileged access. FCEB agencies must remediate under BOD 26-04, and CISA urges all organizations to prioritize patching given confirmed in-the-wild exploitation.

os-command-injectiondellscgunauthenticatednetwork-applianceinput-validation

Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application versions prior to 5.36.00.16 and 5.36.00.00 respectively contain an OS command injection vulnerability that can be exploited remotely without authentication. Successful exploitation could lead to script injection, potentially enabling unauthorized command execution on the affected appliance.

command-injectiondellunauthenticatednetwork-appliancescript-injection

Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application contain a command injection vulnerability that could allow an unauthenticated remote attacker to inject malicious scripts. The flaw carries a moderate CVSS score of 5.3, indicating limited but real risk to affected deployments.

mobile-securityandroidsamsungheap-overflowrceimage-parsingcve-2026-21096

A critical heap-based buffer overflow exists in the JPEG decoder within libimagecodec.quram.so, a native image codec library used in Samsung devices prior to the September 2026 SMR release. Remote attackers can exploit this flaw via a maliciously crafted JPEG image to achieve arbitrary code execution, potentially without user interaction depending on the delivery vector (e.g., MMS, messaging apps, or web content auto-rendering images). This affects a widely deployed component across the Samsung Android ecosystem.

cve-2026-21095androidsamsungrceimage-parsingheap-overflowmobile-security

A critical heap-based buffer overflow exists in the DNG image decoder within libimagecodec.quram.so, a native image codec library used on Samsung mobile devices. Remote attackers can trigger the flaw by delivering a malicious DNG/image file, potentially achieving arbitrary code execution without user interaction depending on the delivery vector (e.g., MMS, messaging apps, or web content). The vulnerability carries a maximum-severity CVSS score of 9.8 and was patched in the September 2026 Samsung Mobile Security Release.

chromebrowser-vulnerabilityextensionsprivilege-escalationsandbox-bypass

CVE-2026-87544 is an incorrect authorization vulnerability in Google Chrome's Extensions component that allows a remote attacker to bypass system access restrictions and reach a privileged page via a crafted HTML page. Google classifies the Chromium security severity as Low, though the NVD CVSS score of 9.8 appears inconsistent with the vendor's own assessment. Affects Chrome versions prior to 153.0.8010.36.

gitlabpath-traversalunauthenticatedcisa-kevarbitrary-file-readagent-relevantci-cdsource-code-exposure

CVE-2026-85706 is an unauthenticated path traversal vulnerability in GitLab Community Edition and Enterprise Edition that allows attackers to read arbitrary files on affected servers via the repository commits API. This flaw has been added to CISA's Known Exploited Vulnerabilities catalog with an aggressive remediation deadline of September 14, 2026, indicating confirmed active exploitation in the wild.

authentication-bypassartifactorysoftware-supply-chaincisa-kevagent-relevanttoken-exposureci-cd

JFrog Artifactory contains an improper authentication flaw that can return an internal anonymous-user access token to unauthenticated callers even when anonymous access has been explicitly disabled. This could allow attackers to access sensitive repository resources without valid credentials, undermining the intended access control model of the artifact repository. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.

authorization-bypassprivilege-escalationcve-2026-42016jfrogartifactorysupply-chain-riskcisa-kevagent-relevant

CVE-2026-42016 is an actively exploited incorrect authorization vulnerability in JFrog Artifactory, added to CISA's Known Exploited Vulnerabilities catalog with a remediation deadline of September 25, 2026. The flaw arises from token validation logic checking only signature and issuer rather than scope, enabling attackers with a valid but improperly-scoped token to escalate privileges within the artifact repository.

remote-access-toolprivilege-escalationunauthorized-file-transferRMMCISA-KEVagent-relevant

ConnectWise ScreenConnect contains a privilege management and authorization flaw that allows an attacker to perform unauthorized file transfer and code execution during active remote sessions without host confirmation. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, and requires urgent patching given its short remediation window (due date only three days after addition).

androidmobile-fraudgoogle-playsocial-engineeringfake-appsscam

Threat actors are exploiting Google Play's Early Access program, intended for pre-release beta feedback, to distribute thousands of deceptive Android apps promising fake money, rewards, casino winnings, and premium content. This abuse allows fraudulent apps to bypass some standard vetting scrutiny while still appearing on the legitimate Play Store, increasing user trust and installation rates.

roundupandroidphishingbrowser-extensionssupply-chainscam-shopsvulnerability-digest

This is a weekly aggregated security news digest covering approximately 200 Android vulnerabilities, browser-based phishing techniques using malicious extensions, and a network of roughly 119,000 fraudulent online storefronts. The report is a compilation of disparate stories rather than a single coordinated campaign, spanning exposed systems, aging unpatched bugs, malicious browser extensions, and risky software packages.