Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 918 threats

windowslolbinlolbin-driverkernel-exploitdefenderedr-evasionliving-off-the-landprivilege-escalationagent-relevant

Check Point Research disclosed a technique abusing Microsoft Defender's own legitimately signed boot-time remediation driver (BTR.sys) to perform arbitrary kernel-level file and registry operations on Windows systems, including deletion of security software at boot. Because BTR.sys is Microsoft-signed and no external or malicious driver is introduced, the technique bypasses driver-signature enforcement and many endpoint protections, affecting Windows 7 through Windows 11 25H2.

npmsupply-chainlinuxbackdoormalicious-packageai-c2agent-relevantnodejsdeveloper-tools

Researchers identified 14 trojanized npm packages disguised as calendar and streak-tracking utilities that covertly deploy an AI-powered Linux backdoor called RedC2 4.0. The malware extracts and executes a bundled binary as a detached background process, giving attackers persistent, AI-assisted command-and-control capability on infected hosts.

windows-updatecompatibility-issuergb-softwarenon-securitybug

Microsoft has identified that games crashing or failing to launch after installing the August 2026 Windows updates may be caused by conflicts with RGB lighting peripheral software rather than a security vulnerability. This is a functional compatibility bug affecting gaming systems, not a cybersecurity threat.

awscredential-exposurecloud-securitysecrets-managementapi-keysagent-relevant

Over 9,300 AWS access keys publicly exposed between August 2022 and August 2026 remain active and valid, granting attackers full control over corporate AWS accounts. These leaked credentials likely originate from hardcoded secrets in public repositories, misconfigured applications, or logging errors, posing an ongoing risk of account takeover, data theft, and resource abuse.

malwarephishingcredential-theftmicrosoft-teamsloadersocial-engineering

A new malware loader named SynkLoader is being distributed through Microsoft Teams phishing campaigns, using a fake lock screen overlay to harvest user credentials. The campaign leverages the trust employees place in Teams notifications and internal communication tools to deliver the loader and steal login credentials.

CISAKEVZimbraOS-command-injectionactive-exploitationemail-serverfederal-agenciesagent-relevant

CISA has added CVE-2026-73570, an OS command injection vulnerability in Zimbra Collaboration Suite (ZCS), to its Known Exploited Vulnerabilities Catalog based on confirmed active exploitation. Federal Civilian Executive Branch agencies are required under BOD 26-04 to remediate this vulnerability on an expedited timeline, and CISA urges all organizations to prioritize patching.

kubernetesmulti-clustersubmarinernetwork-hijacktraffic-interceptioncloud-nativeagent-relevant

A critical vulnerability in Submariner, a multi-cluster Kubernetes networking tool, allows a malicious spoke cluster to advertise arbitrary and unvalidated network subnets to peer clusters. This enables the attacker to hijack traffic intended for legitimate destinations, rerouting it through an attacker-controlled tunnel for interception, disruption, or man-in-the-middle attacks across the federated cluster mesh.

IBMAIXPowerVMVIOSfile-overwriteinput-validationremote-attack

A critical vulnerability (CVE-2026-16926) affects IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1, allowing remote attackers to overwrite arbitrary files due to improper input sanitization. With a CVSS score of 9.1, this flaw poses significant risk to enterprise Unix/virtualization environments running on IBM Power hardware.

iotrouterbuffer-overflowrcepublic-exploitnetwork-devicefirmware

A critical stack-based buffer overflow exists in the mycli binary of TRENDnet TEW-755AP wireless access points, triggered by unsanitized input in the SSID parameter. The vulnerability is remotely exploitable and a public exploit is available, making it an immediate risk for exposed devices. CVSS 9.9 reflects the potential for full device compromise without authentication.

kubernetesrbacprivilege-escalationcluster-adminopenshiftoperatoragent-relevant

The search-v2-operator, commonly deployed in Kubernetes/OpenShift environments (e.g., Red Hat Advanced Cluster Management), is provisioned with a ClusterRole granting effectively cluster-admin level permissions. This over-privileged configuration allows the operator or any workload/service account leveraging it to impersonate users, forge RBAC bindings, approve CSRs, and manage ManifestWork objects, enabling full cluster takeover.

iotrouterbuffer-overflowrcepublic-exploitnvramcgi

A critical stack-based buffer overflow vulnerability exists in TRENDnet TEW-823DRU routers (firmware 1.1.02b01) due to unsafe use of strcpy on the wan_l2tp_password parameter in /cgi-bin/wan.cgi. The flaw is remotely exploitable without complex prerequisites, and public exploit code is already available, making it an immediate risk for internet-exposed or compromised-network devices.

zimbracommand-injectionunauthenticated-rcesmtpemail-servercisa-kevagent-relevant

CVE-2026-73570 is an unauthenticated OS command injection vulnerability in Synacor Zimbra Collaboration Suite that can be triggered via specially crafted SMTP requests, leading to arbitrary command execution as the Zimbra user. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog with an unusually short remediation window, indicating active exploitation in the wild. Organizations running ZCS mail servers should treat this as an imminent compromise risk.

rcen8ngogsworkflow-automationai-assisted-exploitationsigned-driver-abuseliving-off-the-landagent-relevantself-hosted-tools

This roundup covers multiple distinct security issues, including a remote code execution flaw in the Gogs self-hosted Git service, a workflow-to-RCE chain in the n8n automation platform, abuse of signed drivers for defense evasion, and use of AI models (GLM-5.3) to assist in exploit research. Collectively these lower the barrier for attackers by chaining trusted functionality and legitimate software behaviors into compromise paths.

phishingoauth-abusecredential-theftsocial-engineeringrussiastate-sponsoredaccount-takeoverwhatsappgoogle-oauth

Three suspected Russian cyber espionage clusters (UNC6293, UNC7005, UNC5976) are abusing legitimate Google OAuth flows and WhatsApp device-linking features to hijack accounts of individuals in academia, aerospace/defense, government, and think tanks across Europe and the U.S. These campaigns rely on persistent, adaptive social engineering rather than exploiting software vulnerabilities, making them difficult to detect with traditional malware defenses.

supply-chainrustcrates.iobuild-time-malwaredependency-confusiontyposquattingagent-relevant

A compromised maintainer account was used to publish malicious versions of three popular Rust crates (arrayref, internment, append-only-vec), collectively downloaded over 245 million times. The malicious releases introduced a typosquatted dependency whose build script downloaded and executed a remote payload at compile time, enabling arbitrary code execution on any system that built the affected packages.

phishingai-generated-contentmspemail-securityidentity-securitysocial-engineering

This is a vendor advisory (Kaseya via BleepingComputer) describing how AI is making phishing emails more personalized and convincing, allowing them to bypass traditional email filters. It recommends MSPs adopt layered monitoring across identity, email, and endpoint activity to catch attacks that reach user inboxes.

wordpresselementorrcefile-uploadweb-plugincms-securityagent-relevant

A critical vulnerability in the Elementor Pro WordPress plugin allows unauthenticated or low-privileged attackers to upload executable files, leading to full remote code execution on the underlying server. Given Elementor Pro's massive install base, this flaw poses a significant risk of mass exploitation against WordPress-hosted sites and infrastructure.

supply-chainrustcrates.ioinfostealermalicious-packagebuild-time-executionagent-relevant

Attackers compromised the maintainer account of the widely-used Rust crate 'arrayref' and published a malicious version that executes infostealer malware at compile time on developer systems. Any developer or CI/CD pipeline pulling the poisoned version would trigger malware execution during the build process, risking credential and secret theft.

ICSOTbuilding-automationcredential-exposureCWE-316local-privilegeJohnson-Controls

Johnson Controls Simplex Incident Manager versions up to V2.01 store user credentials, including passwords and authentication tokens, in cleartext within system memory. A local low-privileged attacker could extract these credentials using memory-dumping techniques, potentially gaining unauthorized access to the application and connected building automation systems. Johnson Controls has released patched version v2.01.01 to remediate the issue.

CISAKEVTrueConfauthentication-bypasscode-injectionactive-exploitationfederal-mandatevideo-conferencing

CISA has added two actively exploited vulnerabilities affecting TrueConf Server to its Known Exploited Vulnerabilities catalog: a missing authentication for critical function flaw (CVE-2026-72529) and a code injection vulnerability (CVE-2026-72530). These vulnerabilities pose significant risk as they can be chained to bypass authentication and execute arbitrary code, with BOD 26-04 requiring FCEB agencies to remediate rapidly.