Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 336 threats

data-breachextortionhigher-educationfile-storagecredential-theft

Mount Royal University in Calgary confirmed that attackers breached its network and exfiltrated data from file storage systems before deleting it, with threat actors publicly claiming responsibility for the attack. The incident reflects an ongoing trend of threat actors targeting higher-education institutions for data theft and extortion rather than traditional ransomware encryption.

microsoft-defenderzero-daypatch-tuesdaywindowsendpoint-security

Microsoft disclosed and patched a zero-day vulnerability in Microsoft Defender, dubbed 'RoguePlanet', following the June 2026 Patch Tuesday cycle. The vulnerability was actively exploited or publicly known prior to patch release, prompting an out-of-band advisory. Organizations relying on Defender for endpoint protection should prioritize patching to prevent detection evasion or compromise of protected hosts.

ICSOTenergy-sectorinsecure-transmissioncredential-theftsession-hijackingHitachi-EnergyPROMOD-V

Hitachi Energy PROMOD V versions 1.0.10 and prior rely on insecure HTTP communication instead of HTTPS due to a lack of TLS support in the third-party Digipede grid server component. This flaw could allow an attacker with network access to intercept or manipulate data in transit, potentially leading to credential theft, session hijacking, or unauthorized access to industrial engineering workstations.

device-code-phishingmicrosoft-365oauth-abusecredential-theftbusiness-email-compromisesocial-engineeringagent-relevant

A phishing campaign dubbed DEBULL abuses Microsoft's legitimate device-code authentication flow to hijack Microsoft 365 accounts, using collaboration-themed lures rather than fake login pages. Because the attack leverages the real Microsoft login experience and obtains valid OAuth tokens, it bypasses many traditional phishing detections and can persist beyond password resets. The campaign was active between late June and early July 2026, as reported by ZeroBEC.

agent-relevantchatbot-securityprivilege-escalationcloud-misconfigurationgoogle-cloudconversational-aidata-exposure

Varonis researchers discovered a critical flaw in Google Dialogflow CX that allowed an attacker with edit access to one Code Block-enabled conversational agent to hijack other Code Block-enabled agents within the same Google Cloud project. Exploitation could expose live conversation data, steal user-shared information, and enable injection of attacker-controlled bot responses, including deceptive prompts to re-enter passwords. Google has since remediated the issue, but the flaw highlights significant multi-tenancy isolation risks in managed conversational AI platforms.

androidbanking-trojanmaastelegrammobile-malwarecredential-theftotp-interceptionoblivion-variant

RedWing is a newly identified Android malware-as-a-service operation, rented out via Telegram for roughly $300/month, that allows low-skill attackers to take full control of victim devices, steal banking credentials, and intercept one-time passcodes (OTPs). Discovered by Zimperium's zLabs, it is believed to be a new variant of the Oblivion malware family, lowering the barrier of entry for widespread mobile banking fraud.

backdoorrouterfirmwareiotauthentication-bypassnetwork-infrastructure

A hidden authentication backdoor has been discovered in multiple versions of Tenda router firmware, allowing attackers to gain unauthorized administrative access to the device's web management panel. This could enable full device takeover, traffic interception, and use of the router as a pivot point into internal networks.

china-nexusORB-networkrouter-compromiseedge-device-exploitationbotnetstate-sponsored

Chinese state-linked threat actor UAT-7810 is deploying new malware dubbed LONGLEASH to expand an Operational Relay Box (ORB) network, primarily by compromising unpatched internet-facing Ruckus routers. The ORB network is used to anonymize and relay malicious traffic, complicating attribution and enabling downstream intrusion campaigns.

data-breachsource-code-theftthird-party-riskIT-servicesextortion

Accenture confirmed a security breach after a threat actor claimed to have stolen approximately 35 GB of source code and other internal data, subsequently offering it for sale on underground forums. As a major IT services and consulting provider, exposure of Accenture's internal source code and data poses downstream risk to its extensive client base across multiple industries.

ICSCISA-advisorymemory-corruptionlocal-attack-vectorEDA-softwareelectronics-design-automationuse-after-freebuffer-overflow

Labcenter Proteus 9 (build 9.1_SP4_Build_42914), an electronic design automation tool used across critical infrastructure sectors, contains three high-severity memory corruption vulnerabilities including an out-of-bounds write, a stack-based buffer overflow, and a use-after-free. Successful exploitation requires local access and user interaction (e.g., opening a crafted file) but could lead to arbitrary code execution or information disclosure. No known public exploitation has been reported, and the vendor has released version 9.2 SPO to address the issues.

ICSSCADAenergy-sectorbuffer-overflownginxCISA-advisorydenial-of-servicecritical-infrastructure

Hitachi Energy e-mesh EMS versions 4.1.6, 4.4.2, and 4.7.0 contain a heap-based buffer overflow vulnerability in the bundled NGINX ngx_http_rewrite_module (CVE-2026-42945), affecting NGINX v1.30.0 and below. Successful exploitation could crash the NGINX worker process (denial of service) and, under certain conditions where ASLR is disabled or bypassed, allow arbitrary code execution on the affected energy management system.

botnetddosiotarrestlaw-enforcementthreat-actor

Canadian authorities arrested a 23-year-old Ottawa man alleged to be 'Dort,' the operator of Kimwolf, a fast-spreading IoT botnet responsible for large-scale DDoS attacks over the past six months. The suspect also allegedly conducted doxing and swatting campaigns against a journalist and a security researcher, and now faces criminal charges in both the U.S. and Canada. While the operator's arrest may disrupt operations, the underlying botnet infrastructure and malware may persist or be repurposed by other actors.

AI-abusesocial-engineeringaccount-takeoverchatbot-exploitationagent-relevantprompt-injectionidentity-theft

Attackers discovered and shared a method on Telegram to manipulate Meta's AI-powered support assistant into resetting passwords for high-profile Instagram accounts without proper identity verification. This led to the compromise and defacement of accounts belonging to the Obama White House and a senior U.S. Space Force official with pro-Iranian propaganda. The incident highlights how conversational AI agents deployed for customer support can be socially engineered into bypassing security controls.

irannation-statec2-frameworkmoisisraelgovernmentit-sectorcheck-point-research

A threat cluster linked to Iran's Ministry of Intelligence and Security (MOIS) has been observed using a previously undocumented modular command-and-control framework called Cavern (Cav3rn) to target Israeli IT providers and government organizations. Check Point Research attributes the activity to a state-sponsored espionage campaign aimed at establishing persistent access within high-value networks. The framework's modular design suggests ongoing development and long-term operational use by the threat actor.

vishingteams-abusesocial-engineeringinitial-accessratremote-access-trojanhelp-desk-impersonationagent-relevant

Threat actors are impersonating corporate IT support staff over Microsoft Teams voice calls to socially engineer employees into installing the EtherRAT remote access trojan. Once installed, the malware grants attackers initial access to corporate networks, potentially enabling lateral movement, credential theft, and further compromise. This campaign leverages trust in internal communication tools rather than exploiting a software vulnerability.

icsotxz-utilsliblzmarace-conditiondenial-of-servicecritical-manufacturingbr-industrial-automation

A high-severity race condition vulnerability (CVE-2025-31115) in the XZ Utils liblzma multithreaded decoder affects multiple B&R Industrial Automation GmbH HMI/panel products, potentially causing crashes or memory corruption. The flaw stems from improper handling of invalid input in the lzma_stream_decoder_mt function, and has been patched in XZ Utils 5.8.1 with corresponding firmware updates from B&R.

credential-leakcloud-securitygovernmentgithub-exposureinsider-riskawsagent-relevant

A contractor for CISA intentionally published AWS GovCloud access keys and a large set of other agency secrets to a public GitHub account, prompting congressional inquiries into the incident. CISA is currently working to contain the exposure and rotate or invalidate the leaked credentials, but the scope and duration of exposure remain unclear.

bulletproof-hostingrussiadisinformationlaw-enforcement-actioninfrastructure-seizurenation-stateEU-sanctions

Dutch authorities arrested two co-owners of hosting companies that had taken over the technical infrastructure of Stark Industries Solutions, an ISP sanctioned by the EU for enabling Russian cyberattacks, influence operations, and disinformation campaigns. The operation resulted in the seizure of roughly 800 servers used as bulletproof hosting infrastructure supporting state-linked malicious cyber activity across the EU.

npmsupply-chainnorth-koreatyposquattingdeveloper-targetingcredential-theftagent-relevant

North Korea-linked threat actors published malicious npm packages ('rollup-packages-polyfill-core' and 'rollup-runtime-polyfill-core') that impersonate the legitimate 'rollup-plugin-polyfill-node' project, replicating its metadata to deceive developers. These packages are designed to enable remote access and exfiltrate developer secrets, continuing a pattern of North Korean supply-chain attacks against the JavaScript/npm ecosystem.

malwareransomwarephishingmodular-frameworkcredential-theftlateral-movementCrownXagent-relevant

Researchers have identified Avalon, a previously undocumented modular malware framework distributed via a multi-stage phishing chain designed to evade traditional security controls. The framework integrates credential harvesting, lateral movement, remote access, backup/recovery disruption, and ransomware deployment (CrownX) into a single unified toolkit, making it a versatile end-to-end intrusion and extortion platform.