Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 918 threats
A critical unauthenticated code injection vulnerability in GitLab (CVE-2026-19478, CVSS 9.4) is being actively exploited in the wild within days of public disclosure. The flaw allows attackers to modify or delete publicly accessible GitLab projects and rewrite repository data without authentication, posing severe risk to source code integrity and CI/CD pipeline trust.
CISA has added two actively exploited vulnerabilities in TrueConf Server, a self-hosted video conferencing and communications platform, to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch immediately. The flaws are being leveraged in the wild, indicating attackers have working exploits and are actively targeting exposed instances.
This item is a routine Microsoft product announcement describing the rollout of a Classic Outlook visual theme for Outlook on the web and New Outlook for Windows users. It contains no security vulnerability, exploit, malware, or threat actor activity. No action is required from a cybersecurity threat-response perspective.
ToxicPanda, an Android banking trojan, has expanded its capabilities to target 349 applications and now supports 167 remote commands. The malware abuses Android VPN permissions to block access to Google Play, likely to prevent security updates or app removal, while enabling device takeover and financial fraud.
A critical prototype pollution vulnerability exists in exceljs-hardened versions prior to 5.0.0, where the deepMerge helper fails to sanitize dangerous keys (__proto__, constructor, prototype) when merging cell note objects. Attackers can craft malicious spreadsheet or JSON input to pollute Object.prototype, potentially leading to remote code execution, denial of service, or security bypass in downstream application logic.
justhtml versions up to 1.11.0 fail to escape angle brackets when converting parsed HTML to Markdown via to_markdown(), allowing untrusted HTML content (including entity-decoded text and content from RCDATA/RAWTEXT elements like <title>, <textarea>, <noscript>) to be emitted as raw, executable HTML in Markdown output. This creates a sanitizer bypass that can lead to stored or reflected cross-site scripting when the resulting Markdown is later rendered as HTML. The vulnerability is fixed in version 1.12.0.
justhtml versions before 1.16.0 contain multiple sanitization bypass flaws that can allow malicious script/style content to survive HTML sanitization, potentially enabling cross-site scripting. The issues mainly affect advanced usage patterns such as reused/mutated policy objects, programmatic DOM input, and custom SVG/MathML-preserving policies rather than the default sanitize=True parsing path.
A critical stack-based buffer overflow vulnerability affects the Web Management interface of Comfast CF-N1-S wireless routers version 2.6.0.1, exploitable remotely via the NTP timezone configuration endpoint. The exploit code is publicly available, significantly increasing the likelihood of active exploitation, and successful attacks could allow full device compromise.
Cisco has released patches addressing nine vulnerabilities across its Crosswork platforms and Secure Workload software, five of which carry the maximum CVSS score of 10.0. These flaws affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning regardless of device configuration, posing significant risk to network orchestration infrastructure.
This item is promotional/informational content from The Hacker News discussing how Wazuh, an open-source security platform, integrates AI to improve SOC (Security Operations Center) workflows. It does not describe an active threat, vulnerability, exploit, or attack campaign.
TikTok has agreed to pay $400 million to settle a 2024 U.S. Department of Justice lawsuit alleging violations of child privacy laws, specifically related to prior consent decree obligations. This is a regulatory and legal enforcement action rather than a cybersecurity incident, involving no exploited vulnerability, malware, or technical compromise.
This is an informational/promotional article from Anonyome Labs discussing the benefits of using separate digital personas (distinct emails, phone numbers, payment methods) to reduce data broker correlation and limit exposure from breaches and identity theft. It does not describe an active threat, vulnerability, or attack campaign.
This report is an educational/advisory piece from ThreatLocker discussing how weak access controls on Windows named pipes can expose privileged services to untrusted or malicious processes. It highlights best practices such as endpoint verification, command authorization, input validation, and least-privilege scoping to mitigate abuse of interprocess communication channels.
Attackers compromised a legitimate Android device-update application distributed with car head units, using it to deliver malware that enrolls devices into a proxy botnet and conducts ad fraud. This supply-chain compromise leverages a trusted update mechanism to gain persistent access to a large, distributed fleet of embedded automotive devices.
The WS Form LITE WordPress plugin (versions up to 1.10.80) contains a PHP Object Injection vulnerability caused by insecure deserialization of untrusted form submission meta values. While no exploitable POP (Property-Oriented Programming) chain exists within the plugin itself, the presence of a vulnerable POP chain in any other installed plugin or theme could enable unauthenticated attackers to achieve file deletion, data exfiltration, or remote code execution.
A critical stack-based buffer overflow vulnerability exists in TRENDnet TEW-821DAP routers (firmware 2.2.01b05) within the NTP Timezone Configuration Handler's uci_safe_get function. The flaw is remotely exploitable without authentication via manipulated CGI parameters, and a public exploit is already available, making immediate exploitation likely.
The Mailgun for WordPress plugin (versions up to 2.2.0) contains an unauthenticated SSRF vulnerability caused by insufficient input validation in the add_list() function. Attackers can leverage this flaw to make authenticated requests to any Mailgun API endpoint using the site's stored API key, enabling creation of email-forwarding rules that intercept password reset emails and result in full administrator account takeover.
A critical vulnerability (CVE-2026-17145) affects IBM AIX versions 7.2 and 7.3, as well as IBM PowerVM VIOS 4.1, allowing a remote, unauthenticated attacker to execute arbitrary code due to improper privilege management. With a CVSS score of 9.8, this flaw poses severe risk to enterprises running IBM Power systems, potentially enabling full system compromise. Organizations using these platforms for critical workloads, including hosted virtualized environments, should prioritize patching.
A critical vulnerability in Lighthouse (Submariner's multi-cluster service discovery component) allows an attacker who has compromised a spoke cluster to inject malicious EndpointSlices and ServiceImports into arbitrary namespaces on peer clusters, including sensitive system namespaces. This can lead to traffic hijacking, privilege escalation, and broader compromise of federated Kubernetes/OpenShift environments.
Kaspersky discovered a malware family targeting Android-based vehicle head unit firmware developed by DoFun, which propagates via built-in firmware updaters. The malware deploys a multi-stage downloader used to conduct ad fraud and enlist infected devices into a proxy botnet.