Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 16 of 336 threats
A newly disclosed Linux kernel vulnerability dubbed 'Bad Epoll' (CVE-2026-46242) allows an unprivileged local user to escalate privileges to root, affecting Linux desktops, servers, and Android devices. A patch has already been released, but unpatched systems remain fully exploitable by any local user or process with code execution.
The Gentlemen is a rapidly growing ransomware-as-a-service (RaaS) operation that has become the second most active ransomware gang by victim count, driven by an aggressive affiliate recruitment strategy offering 90% of ransom proceeds. Investigative reporting by Krebs on Security examines OSINT clues pointing to the real-world identity of the group's administrator, highlighting the operational and personal risks facing RaaS operators as attribution efforts intensify.
Two members of the Scattered Spider cybercrime group pleaded guilty on the first day of their UK trial for a August 2024 cyberattack that crippled Transport for London (TfL). This marks a significant law enforcement outcome against a group known for sophisticated social engineering, SIM-swapping, and help-desk impersonation attacks targeting large enterprises and critical infrastructure.
Security firm runZero disclosed seven unpatched vulnerabilities in FatFs, a widely embedded filesystem library used to read and write FAT/exFAT formats on USB drives and SD cards. Because FatFs is bundled into firmware across security cameras, drones, industrial controllers, and hardware crypto wallets, these flaws could enable attackers with physical or logical access to removable media to trigger memory corruption or logic errors in a huge range of downstream devices.
North Korean threat actors tied to the Contagious Interview campaign have published 108 malicious packages and browser extensions across npm, Packagist, Go, and the Chrome Web Store in an operation dubbed PolinRider. The campaign leverages compromised maintainer accounts to distribute malware through widely trusted software registries, posing an ongoing supply-chain risk as new packages continue to surface.
A U.S. government entity paid approximately $1 million in extortion payments to a group calling itself Kairos to prevent the leak of stolen data. Analysis of a leaked negotiation chat and blockchain payment trail suggests Kairos may operate purely as a data-theft extortion outfit without deploying ransomware encryption, distinguishing it from traditional ransomware gangs. This case highlights the growing prevalence of extortion-only threat actors targeting public sector organizations.
ARToken is a newly identified phishing-as-a-service (PhaaS) platform operating as an affiliate of the EvilTokens phishing ecosystem, offering attackers a turnkey toolkit to compromise Microsoft 365 accounts. The platform enables adversary-in-the-middle (AiTM) style credential and session token theft at scale, lowering the barrier to entry for large-scale enterprise account compromise.
Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M versions 1.000A through 1.014Q contain four vulnerabilities in its bundled 7-Zip component, including a heap-based buffer overflow, NULL pointer dereference, link following, and path traversal issue. Successful exploitation requires local access and user interaction to decompress a specially crafted archive, and could lead to denial-of-service, data tampering, or arbitrary code execution. No public exploitation has been observed, and the vulnerabilities are not remotely exploitable.
The FBI, working with industry partners, seized hundreds of domains linked to NetNut, a residential proxy service operated by publicly-traded Israeli firm Alarum Technologies. The takedown follows security research connecting NetNut to the Popa botnet, a network of at least two million devices compromised without meaningful user consent. This represents a significant disruption to a large-scale proxyware/botnet infrastructure used to monetize unwitting victims' internet connections.
Schneider Electric EasyLogic T150 and Saitel DP RTU devices contain two vulnerabilities that could allow unauthorized access to sensitive credentials and password hashes. CVE-2026-9650 allows an unauthenticated attacker with physical access to extract credentials from firmware or system files, while CVE-2026-9651 allows a privileged local attacker to read improperly protected system files containing password hashes. No public exploitation has been reported to CISA at this time.
CISA added CVE-2026-45659, a deserialization of untrusted data vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog due to confirmed active exploitation. Federal civilian agencies are required under BOD 26-04 to remediate this vulnerability on an expedited basis given its potential for full system compromise on publicly exposed assets. All organizations, not just federal agencies, are strongly encouraged to prioritize patching.
The Popa botnet is a large-scale Android-based malware network that has compromised millions of consumer TV boxes over the past four years, using them as unwitting relays for internet traffic. Security researchers have linked this infrastructure to NetNut, a residential proxy service operated by publicly-traded Israeli company Alarum Technologies Ltd (NASDAQ: ALAR), raising concerns about corporate involvement in facilitating malicious traffic relay networks.
Two high-severity vulnerabilities affect ST Engineering iDirect iQ-Series satellite terminals (Evolution iQ, 3315-Series, 9-Series) running firmware <=4.5.2.1. Successful exploitation could allow an unauthenticated attacker to retrieve sensitive device credentials or force device reboots via CSRF, potentially causing terminal impersonation or denial-of-service on satellite links. No known public exploitation has been reported to CISA at this time.
Coordinated campaign publishing typosquatted Python packages to steal environment variables, SSH keys, and cloud credentials from developer workstations and CI/CD pipelines.
English-speaking group using SIM-swapping and MFA fatigue attacks to compromise enterprise identity providers via IT help desk impersonation calls.
Chinese state-sponsored group maintaining persistent access in US energy, water, and telecom networks using living-off-the-land techniques that blend with normal admin activity.