Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 335 threats

financial-fraudbrazilcrypto-theftthreat-actorinstant-payment-fraudsocial-engineering

CrowdStrike has identified a new financially motivated threat actor, dubbed Slim Spider, targeting Brazilian financial institutions since at least March 2026. The group demonstrates deep knowledge of Brazilian financial infrastructure, including instant payment systems, and has been observed stealing crypto custody secrets from a targeted institution.

kevcisaactively-exploitedadobe-commercemagentowindowsn-ablermmtemplate-injectionprivilege-escalationfederal-mandate

CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog affecting Adobe Commerce/Magento, Microsoft Windows, and N-able N-central, all confirmed under active exploitation. FCEB agencies must remediate per BOD 26-04, and CISA urges all organizations to prioritize patching given the demonstrated real-world attack activity.

windowsprivilege-escalationlocal-exploitcisa-kevalpcheap-overflowagent-relevant

CVE-2026-85880 is a heap-based buffer overflow in Microsoft Windows Advanced Local Procedure Call (ALPC) that enables local privilege escalation. The vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation in the wild, with a remediation deadline of September 22, 2026.

windowsprivilege-escalationlocal-exploitCISA-KEVwindows-update-stacklink-followingagent-relevant

CVE-2026-81963 is a local privilege escalation vulnerability in the Microsoft Windows Update Stack caused by improper handling of file system links, allowing a local attacker to gain SYSTEM-level privileges. The flaw has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, with a remediation deadline of September 22, 2026.

chrome-zero-dayrouter-exploitationsupply-chain-attackcredential-theftqr-code-phishingnetwork-management-protocol-abuseagent-relevant

This weekly recap covers multiple active threats including a Chrome 0-day, router hijacking campaigns, and a notable supply chain attack against the Coder platform that resulted in credential theft. Attackers also demonstrated a novel phishing technique using text-rendered QR codes to bypass email image-blocking protections, and abused a network management protocol for malicious purposes.

vishingsocial-engineeringMicrosoft 365AitMtoken-theftSaaSexecutive-targetingextortionresidential-proxyagent-relevant

A threat cluster is targeting executives (directors, VPs, senior staff) at organizations using Microsoft 365 and other SaaS platforms through IT help desk vishing calls, adversary-in-the-middle (AitM) session token theft, and sign-ins routed through residential proxy networks to evade geolocation-based detection. Stolen credentials and session tokens are used for data exfiltration followed by extortion demands. The campaign leverages human trust in IT support workflows rather than software exploits, making it effective against organizations with strong technical controls but weaker identity-verification processes.

post-exploitationbrowser-hijackingchromiumbackdooragent-relevantcredential-theftpersistence

PEEP is a post-compromise toolkit that disguises itself as a bookmarks extension for Chrome and Edge, requiring prior administrative or code execution access to deploy. It forges Chromium's Secure Preferences file to bypass Web Store validation and user consent prompts, effectively turning the browser into a persistent backdoor capable of executing host commands.

data-breachedtechthird-party-riskbusiness-intelligence-toolPII-exposure

Online mathematics learning platform Mathspace disclosed a data breach affecting over 1 million students, staff, and parents after attackers compromised its Metabase internal reporting system. The breach exposed personal data likely including names, emails, and academic records tied to a widely used education platform. No technical details on the intrusion vector into Metabase have been disclosed.

phishing-as-a-serviceAiTMMFA-bypassMicrosoft 365credential-theftbusiness-email-compromiseagent-relevant

BigBear 2.0, a phishing-as-a-service (PhaaS) platform, has been used to compromise 258 organizations and steal over 5,000 Microsoft 365 credentials by bypassing multi-factor authentication via adversary-in-the-middle (AiTM) reverse-proxy techniques. The kit lowers the barrier to entry for large-scale credential phishing campaigns and has demonstrated broad reach across sectors relying on Microsoft 365 for identity and collaboration.

ICSSCADAsession-hijackinginsufficient-entropycritical-infrastructureenergy-sectorSchneider-ElectricCWE-331

A high-severity vulnerability (CVE-2026-4827) affecting numerous Schneider Electric Easergy, EcoStruxure, PowerLogic, and Saitel protection relays, RTUs, gateways, and SCADA/HMI software stems from insufficient entropy in session token generation. An attacker on the network could exploit weak session-management protections to hijack sessions and perform unauthorized operations on critical electrical grid control and protection devices.

infostealercryptominingwindowsdefense-evasionpersistencedefender-bypassagent-relevant

Elastic Security Labs identified four previously unreported programs linked to REVSTEALER, a Windows information stealer, that persist on infected machines after the stealer removes itself. One module disables Windows Update and Microsoft Defender to covertly deploy a cryptocurrency miner, indicating an evolution from pure credential theft toward long-term system abuse.

mikrotiksshrouter-compromiseinternet-exposednetwork-infrastructureunauthenticated-accesscert-polskaiot

Attackers are actively hijacking internet-exposed MikroTik routers by abusing their SSH remote-access service to gain full administrative control without authentication. CERT Polska issued a warning on September 5, 2026, with confirmed exploitation activity dating back to at least September 2. No victim count or specific technical root cause has been publicly disclosed yet.

zero-dayprivilege-escalationwindowsedr-bypasscrowdstrikeagent-relevant

A publicly released zero-day exploit dubbed 'FalconFlank' targets CrowdStrike Falcon sensor on fully patched Windows systems, allowing local attackers to escalate privileges to SYSTEM level. The exploit was disclosed by a researcher using the handle 'Nightmare Eclipse' without prior coordinated disclosure to CrowdStrike, increasing risk of rapid weaponization by threat actors.

ICSSCADARockwell Automationlocal-privilege-escalationinsecure-permissionscritical-infrastructureCWE-306

Rockwell Automation ControlFLASH versions V15.07 and earlier contain a local privilege escalation vulnerability caused by the installer granting the 'Everyone' group write permissions on the product installation directory. A local attacker with limited privileges could exploit this to plant malicious code or binaries that execute at the logged-in user's permission level, enabling arbitrary command or code execution.

jetbrainsteamcitycadenceci-cdcredential-theftawssupply-chainagent-relevant

Unidentified threat actors exploited a recently disclosed critical vulnerability in JetBrains TeamCity to breach JetBrains' own environment, compromising its Cadence CI/CD service. JetBrains has urged all Cadence users to immediately revoke and rotate credentials and secrets used in their Cadence executions, indicating potential exposure of customer AWS credentials and other secrets.

clickfixsocial-engineeringblockchain-malwareweb3compromised-websitesbnb-smart-chaincredential-theftagent-relevant

A large-scale campaign has compromised over 5,400 small-business websites to serve fake CAPTCHA/verification pages that trick users into executing malicious commands (ClickFix technique). The payload delivery infrastructure is hosted in smart contracts on the BNB Smart Chain, making takedown difficult since blockchain data cannot be removed by hosting providers or registrars.

ICSOTcritical-infrastructurerockwell-automationcross-site-scriptingdenial-of-servicecisa-advisory

Rockwell Automation ArmorStart LT firmware versions ≤v2.001 contain two vulnerabilities: a stored cross-site scripting flaw and a denial-of-service issue triggered by a crafted HTTP PUT request to the embedded web server. Exploitation could allow an attacker to inject malicious scripts executed by other users or crash the device's web server, disrupting availability. No public exploitation has been reported, and Rockwell has released firmware v2.002 to remediate both issues.

linuxbackdoorhaproxyweb-traffic-interceptionsupply-chainpost-exploitationsouth-korea

A previously undocumented Linux backdoor named 'Ted' has been discovered compiled directly into trojanized HAProxy load balancer builds at two South Korean organizations. The implant intercepts and manipulates web traffic, serving altered content to selected visitors, indicating a targeted, capability-focused intrusion rather than opportunistic malware distribution.

postgresqlprivilege-escalationrcedatabase-securitylogical-decodingagent-relevant

A 12-year-old flaw in PostgreSQL's logical decoding feature allows a database role with REPLICATION privileges to escalate to arbitrary code execution as the OS user running the database server. PostgreSQL has released patched versions across all supported major releases to address CVE-2026-6471.

data-breachidentity-verificationpii-exposuredriver-licensethird-party-risklitigation

IDScan, an identity verification company, allegedly suffered a data breach in which threat actors claim to have obtained and offered for sale over 153 million driver's license records. The company now faces multiple lawsuits related to the incident. Details on the initial attack vector remain undisclosed publicly.