Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 336 threats

npmsupply-chainnodejsRATDEV#POPPERjavascriptmalicious-packageagent-relevant

Two beta releases of npm packages in the @joyfill namespace were compromised to include an import-time JavaScript implant that deploys a remote access trojan linked to the DEV#POPPER campaign. Developers or automated build pipelines that installed the affected beta versions could have unknowingly executed malicious code upon package import, granting attackers remote access to the host.

dns-hijackingsupply-chain-riskdrone-softwareuavtraffic-interceptiondomain-security

CubePilot, an Australian developer of flight controller software for drones, suffered a DNS hijacking attack that allowed threat actors to intercept traffic intended for its domains. The attack caused significant operational disruption and raises concerns about the integrity of software, firmware, or documentation served to CubePilot's customer base during the compromise window.

MikroTikRouterOSbrute-forceauthentication-bypassCWE-307network-deviceICS-advisory

MikroTik RouterOS and Cloud Hosted Router contain a flaw in API authentication handling that fails to enforce rate-limiting or account lockout, allowing attackers to conduct high-volume brute-force login attempts, including bypassing per-connection delays via concurrent sessions. Successful exploitation could grant unauthorized administrative access to the affected router. No public exploitation has been reported and the vulnerability requires adjacent network access, not remote internet-based exploitation.

iotbotnetddosblockchain-c2resilient-infrastructuredecentralized-dnscncertxlab

Dysphoria, an IoT botnet lineage tracked by CNCERT and XLab, has upgraded its command-and-control architecture to use blockchain-based naming services and peer-to-peer relays across infected devices, making it significantly more resilient to takedown efforts. This evolution follows a March 2026 law enforcement disruption of related JackSkid infrastructure, indicating the operators are actively hardening their C2 model against future enforcement action.

botnetddosiot-malwaretraffic-relaylarge-scale-compromise

Dysphoria is a newly identified DDoS botnet that has compromised approximately 200,000 devices globally. The malware is being used both for distributed denial of service attacks and as a traffic relay/proxy network, indicating a dual-purpose criminal infrastructure. Its rapid scale suggests exploitation of weak credentials or unpatched vulnerabilities in widely deployed internet-facing devices.

CISAKEVknown-exploited-vulnerabilityFortinetFortiOSAristaVeloCloudcommand-injectioninformation-disclosurenetwork-infrastructurefederal-agenciespatch-management

CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: a sensitive information exposure flaw in Fortinet FortiOS (CVE-2025-68686) and an OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem (CVE-2026-16812). Both are confirmed to be exploited in the wild and require urgent remediation under BOD 26-04 for federal agencies, with CISA recommending all organizations prioritize patching.

fortinetfortiosnetwork-securitypost-exploitationpersistence-bypasscisa-kevedge-device

CVE-2025-68686 is a vulnerability in Fortinet FortiOS that allows a remote unauthenticated attacker to bypass a previously deployed patch addressing a symbolic link persistency mechanism used in post-exploitation scenarios. Exploitation requires prior compromise of the device at the filesystem level via another vulnerability, making this a persistence and detection-evasion enabler rather than an initial access vector. It has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild.

ransomware-as-a-serviceRaaSaffiliate-modelDevManFunky MantisPRODAFTextortion

DevMan is a ransomware-as-a-service operation running a centralized web portal that lets affiliates build custom payloads, track victim status, and manage payouts. PRODAFT is tracking the broader operator infrastructure under the name Funky Mantis, indicating a structured, business-like criminal enterprise lowering the barrier to entry for ransomware deployment. The centralized tooling suggests active recruitment and scaling of affiliates, increasing the likely volume and diversity of attacks.

phishingcredential-theftreal-time-hijackingsession-hijackinginsurance-sectorfinancial-fraudsocial-engineeringadversary-in-the-middle

CTM360 researchers identified a shift in insurance-sector phishing campaigns from traditional credential harvesting to real-time account hijacking, where stolen credentials and session tokens are used immediately to take over accounts before victims can react. This evolution suggests attackers are increasingly leveraging automated relay infrastructure or adversary-in-the-middle (AiTM) techniques to bypass MFA and act on stolen sessions within seconds of capture.

gitlabrceproof-of-conceptauthenticated-exploitjupyter-notebookheap-leakgitsource-code-managementagent-relevant

A public proof-of-concept exploit now lets any authenticated user with push access to a GitLab project execute arbitrary commands as the 'git' user on unpatched self-managed GitLab 18.11.3 instances. GitLab shipped a fix six weeks before the PoC was released, meaning organizations that have not applied the patch are immediately exposed to remote code execution. Because GitLab often hosts CI/CD pipelines, secrets, and automation scripts used by AI agent and MLOps workflows, this flaw poses a direct risk to agent-integrated development environments.

malvertisingfileless-malwarecryptocurrencybrowser-based-attacksocial-engineeringin-memory-executionagent-relevant

A large-scale malvertising campaign is directing users to fake Solana, Luno, and TradingView websites that use malicious JavaScript to assemble malware directly in browser memory, evading disk-based detection. The campaign targets users seeking cryptocurrency and trading tools, likely aiming to steal credentials, wallet keys, or session tokens.

ICSOTIEC-60870-5-104denial-of-serviceout-of-bounds-readCISA-advisorycritical-infrastructureprotocol-library

MZ Automation's lib60870 library, versions 2.4.0 and earlier, contains an out-of-bounds read vulnerability (CVE-2026-16002) in its IEC 60870-5-104 protocol parsing code. Remote, unauthenticated attackers can crash the parsing process, causing a denial of service in energy, water/wastewater, and chemical sector control systems that rely on this library for SCADA/ICS communications.

BlueNoroffNorth-KoreaAPTClickFixcrypto-theftsocial-engineeringtyposquattingwallet-draineragent-relevant

BlueNoroff, a North Korean state-sponsored threat actor, is operating an active phishing kit that impersonates Zoom and Microsoft Teams via typosquatted domains and ClickFix-style social engineering lures. The campaign profiles victims' cryptocurrency wallets before delivering malware, combining compromised industry contacts and trust abuse to maximize infection success.

DNS hijackingcredential theftMicrosoft 365phishinghospitalitytravel-securitycaptive-portal-abuseagent-relevant

Threat actors are compromising DNS settings on hotel and conference center Wi-Fi routers/gateways to silently redirect guests to convincing fake Microsoft 365 login pages. Victims who enter credentials on these spoofed portals have their Microsoft 365 accounts stolen, potentially exposing corporate email, files, and connected services. The campaign leverages trust in hotel network infrastructure and captive portal flows to bypass user suspicion.

icsotiec61850buffer-overflowrcedenial-of-servicecritical-infrastructureenergy-sector

MZ Automation's libIEC61850 library, widely used for IEC 61850 substation automation and protection communications, contains four vulnerabilities including stack- and heap-based buffer overflows and NULL pointer dereferences. An unauthenticated, network-adjacent attacker could exploit these flaws to crash critical protection and control services or achieve remote code execution, directly threatening energy, manufacturing, and transportation ICS environments.

dnscache-poisoningunbounddns-resolverso_reuseportnetwork-securityagent-relevant

A vulnerability in NLnet Labs Unbound (versions 1.4.22 through 1.25.1) weakens DNS transaction security when SO_REUSEPORT load balancing is enabled, which is the default configuration. Attackers can infer the mapping between client source ports and internal worker threads, effectively reducing the entropy of outgoing query source ports and making DNS cache poisoning attacks significantly more feasible.

data-breachpii-exposureenergy-sectoraustraliacustomer-data-leak

Origin Energy, a major Australian energy provider, confirmed that an unauthorized party accessed customer data and subsequently leaked it online. The breach exposed sensitive personally identifiable information (PII), raising concerns about downstream fraud, phishing, and identity theft targeting affected customers.

ICSOTpath-traversalrockwell-automationthinmanagerindustrial-control-systemsCWE-22

A high-severity path traversal vulnerability (CVE-2026-11917) affects multiple versions of Rockwell Automation ThinManager, allowing an authenticated attacker to write arbitrary files to restricted system directories outside the application's intended scope. No public exploitation has been reported at this time, but organizations in critical infrastructure sectors using affected versions should prioritize patching.

ICSHMIvulnerabilityprivilege-escalationplaintext-passwordCWE-784CWE-732CWE-256CWE-286critical-manufacturingCISA-advisory

CISA disclosed four vulnerabilities in Weintek cMT3092X HMI devices and their EasyWeb web interface, allowing non-privileged users to escalate privileges via cookie/token manipulation, view plaintext-stored user credentials, and modify data that should be read-only. The highest-severity flaws (CVSS v3.1 8.8) enable full compromise of confidentiality, integrity, and availability on affected industrial control devices. No public exploitation has been reported, but a vendor patch is available.

browser-extensionadobe-acrobatwhatsapp-webcross-origindata-exposurechrome-extensionprivacy

A now-patched vulnerability chain in the Adobe Acrobat Chrome extension, dubbed HermeticReader by Guardio Labs and tracked as CVE-2026-48294, could allow malicious websites to silently read a user's WhatsApp Web data. The extension, installed by over 314 million users, contained a flaw that broke cross-origin isolation, enabling covert hijacking of session data without user interaction.