Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 336 threats
A Russian-speaking threat actor known as 'bandcampro' has been observed repurposing Google's open-source Gemini CLI AI tool as an autonomous hacking agent to conduct offensive operations and manage a small-scale botnet. This represents a real-world case of adversaries weaponizing legitimate agentic AI tooling to automate reconnaissance, exploitation, and malware/botnet management tasks.
CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog: an improper input validation flaw in PTC Windchill and FlexPLM, and an SSRF vulnerability in Cisco Unified Communications Manager. Both are confirmed under active exploitation and pose significant risk, particularly to federal enterprise systems subject to BOD 26-04 remediation timelines.
CISA has added CVE-2026-48558, an authentication bypass vulnerability in SimpleHelp remote access software, to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation. Federal civilian agencies are required under BOD 26-04 to remediate the flaw on a prioritized timeline, and CISA urges all organizations, public and private, to do the same.
CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: a KNX Protocol account lockout flaw (CVE-2023-4346) and an Oracle E-Business Suite improper privilege management vulnerability (CVE-2026-46817). Under BOD 26-04, FCEB agencies must prioritize remediation of these vulnerabilities on publicly exposed assets due to evidence of active in-the-wild exploitation.
CVE-2026-59836 is an improper certificate validation flaw in Fortinet FortiClientEMS affecting versions 7.2, 7.4.0-7.4.1, and 7.4.3-7.4.5, which could allow an attacker to gain access to sensitive information. The vulnerability likely enables man-in-the-middle style attacks due to insufficient validation of TLS/SSL certificates during communications.
Security researchers found that Claude for Chrome, Anthropic's browser-based AI agent, can be manipulated by any other malicious browser extension capable of injecting a script into claude.ai. This allows a rogue extension to trigger Claude's authenticated agent actions, silently reading a victim's Gmail, Google Docs (including comments), and Calendar without direct user consent for that specific action. The flaw is related to but distinct from the previously disclosed 'ClaudeBleed' issue, sharing the same rogue-extension prerequisite but differing in the scope of accessible data.
A threat actor has created nearly 300 fake GitHub repositories impersonating legitimate software and security tools to distribute infostealer malware. Developers and security researchers searching for these tools risk downloading and executing malicious code disguised as trusted projects.
A high-severity local privilege escalation vulnerability (CVE-2026-31431, 'Copy Fail') affects ABB Ability Edgenius edge computing platforms due to a flaw in the Linux kernel's algif_aead cryptographic interface. A locally authenticated user or compromised container workload could exploit incorrect in-place memory operations to gain full root access on affected devices. ABB has released version 3.2.4.1 to remediate the issue.
A flaw in Perl's regex engine (Perl_study_chunk) causes silent match corruption when an alternation pattern contains more than 65535 fixed-string branches, due to a 16-bit field overflow during trie compilation. This can produce false positive or false negative matches with no warning, undermining any security or filtering logic that relies on such patterns.
CVE-2026-57830 is a critical vulnerability in the Helix Ultimate Joomla extension that allows unauthenticated attackers to delete arbitrary files on the underlying server. This could lead to denial of service, configuration file loss, or destruction of critical application data without requiring any authentication.
CVE-2026-15410 is a code injection vulnerability in SonicWall SMA1000 Appliances that allows an authenticated remote attacker with administrator privileges to execute arbitrary OS commands. The flaw has been added to CISA's Known Exploited Vulnerabilities catalog, indicating confirmed active exploitation in the wild. Organizations using SMA1000 for secure remote access are urged to remediate under an accelerated timeline.
CVE-2026-56155 is a known-exploited privilege escalation vulnerability in Microsoft Active Directory Federation Services (ADFS) caused by insufficient granularity of access control. It allows an authorized but low-privileged attacker to elevate privileges locally, potentially leading to compromise of federated identity infrastructure. CISA has added it to the Known Exploited Vulnerabilities catalog with a remediation deadline of July 28, 2026.
A CISA contractor inadvertently published dozens of sensitive internal credentials, including AWS GovCloud keys, in a public GitHub repository where they remained exposed for nearly six months before external notification by a security journalist. The incident highlights systemic weaknesses in secrets management, contractor oversight, and detection capability within a federal cybersecurity agency, raising concerns about the broader public and private sector's exposure to similar risks.
This weekly recap highlights multiple concurrent threats including exploitation of ShareFile vulnerabilities, ransomware campaigns leveraging the 'Citrix Bleed 2' flaw, and a rising trend of attackers using AI coding tools to accelerate exploit development. The report underscores how unpatched, previously disclosed vulnerabilities continue to be actively exploited due to delayed remediation, and how trusted software supply chains are increasingly weaponized against their own users.
CrashStealer is a newly identified macOS information stealer written in native C++ that uses a notarized dropper to bypass Gatekeeper security checks. Unlike typical macOS stealers built with AppleScript or Objective-C wrappers, its native implementation and local password validation suggest a more sophisticated, evasion-focused development approach. The malware is designed to harvest sensitive data from compromised systems, including credentials and stored secrets.
CrashStealer is a newly identified macOS information-stealing malware that disguises itself as Apple's legitimate crash-reporting utility to gain user trust and system access. Once executed, it harvests saved credentials, macOS Keychain data, and cryptocurrency wallet files, exfiltrating them to attacker-controlled infrastructure. Its impersonation of a trusted system tool makes it likely to evade casual user scrutiny and some endpoint defenses.
A threat actor compromised the Jscrambler npm package and published a malicious version containing infostealer malware, which was downloaded nearly 1,500 times before detection. This represents a supply chain attack targeting developers and CI/CD pipelines that depend on the Jscrambler client-side web security tooling.
Russian FSB Center 16 (aka Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, Static Tundra) is conducting a long-running, opportunistic global campaign exploiting poorly configured and vulnerable networking devices, primarily routers, using SNMP abuse and known Cisco CVEs. Targeting spans critical infrastructure sectors including communications, energy, financial services, defense industrial base, government, and healthcare. A joint advisory from CISA, NSA, FBI, and 15 international partner agencies urges organizations to harden router/SNMP configurations and disable legacy protocols.
A vulnerability in gawk's builtin.c (do_sub() routine) allows an integer overflow that corrupts heap metadata and objects, causing crashes on 32-bit builds of gawk version 5.4.0 and earlier. The flaw could potentially be leveraged for further exploitation beyond denial of service depending on heap layout and attacker control over input strings passed to gawk substitution functions.
Cisco IOS 12.4 contains cross-site request forgery vulnerabilities in its HTTP-based management interface, allowing remote attackers to trick authenticated administrators into executing arbitrary privileged commands. This flaw is included in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. Successful exploitation could lead to full device reconfiguration or compromise of network infrastructure.