Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 918 threats

google-workspaceoauthtoken-theftcloud-securityidentity-securitysaas-securityagent-relevant

This report highlights that attacks against Google Workspace increasingly bypass traditional phishing defenses by exploiting stolen OAuth tokens to gain access to Gmail, Drive, and connected third-party applications. Material Security emphasizes that organizations must defend the entire Workspace attack chain, not just the initial login, since attackers can pivot through connected integrations and persistent tokens. This represents a shift toward identity- and token-centric attack paths rather than credential phishing alone.

botnetmirai-variantlinux-malwarerouter-compromisesocks5-proxyiot-security

Evooo1Bot is a newly identified Mirai-based modular Linux botnet targeting internet-facing gateway devices and routers. Once compromised, infected devices are converted into SOCKS5 traffic relay nodes, likely to support proxy-for-hire services or to anonymize other malicious traffic.

ICSOTenergy-sectorhard-coded-credentialsmissing-authenticationrecoverable-passwordsVNC-exposureCISA-advisory

ANDRITZ HIPASE-250 and 250 SCALA industrial control system products (versions <=7.20) contain four vulnerabilities including recoverable password storage, missing authentication on data/config endpoints, an unauthenticated logging manipulation endpoint, and a hard-coded VNC credential used across engineering workstation deployments. Successful exploitation could allow an attacker to read sensitive process data, access engineering workstations, suppress audit logs, or recover stored credentials. These are primarily energy-sector ICS/OT vulnerabilities with no reported public exploitation to date.

ICSSCADASiemensPLCcryptographic-weaknesshardcoded-keypassword-hashingCWE-321CWE-759industrial-control-systems

Siemens LOGO! Soft Comfort versions prior to V9 contain two vulnerabilities affecting project-file encryption and password protection: a hardcoded AES master key and unsalted SHA-256 password hashes. A local attacker could exploit these flaws to decrypt project files, bypass or remove passwords, and perform efficient offline brute-force attacks, potentially gaining unauthorized access to sensitive PLC project logic and configurations.

ICSmedical-devicehardcoded-credentialsbluetoothCWE-798healthcareIoT

Flow Neuroscience FL-100 (and rebranded Halo Neuroscience FL-100) tDCS devices contain an undocumented hard-coded credential shared across all units, allowing any attacker within Bluetooth range to bypass authentication. Exploitation could let an attacker arbitrarily manipulate brain stimulation parameters and override built-in safety limits, posing direct physical harm risk to patients.

wordpressauthentication-bypassaccount-takeoverplugin-vulnerabilitycryptographic-failureunauthenticated-rce-adjacentcms

The User Session Synchronizer plugin for WordPress (versions up to 1.4.0) contains a critical authentication bypass vulnerability that allows unauthenticated attackers to impersonate any user, including administrators. The flaw stems from unvalidated request parameters and a cryptographic fallback that renders the encryption predictable when an unregistered session key is referenced. Full site takeover is possible with no prior knowledge of secrets, making this an urgent patch priority for any WordPress site running the plugin.

wordpressauthentication-bypassplugin-vulnerabilityprivilege-escalationunauthenticated-rce-adjacentagent-relevant

The 6Storage Rentals WordPress plugin (versions up to 2.27.0) contains a critical authentication bypass vulnerability allowing unauthenticated attackers to log in as any existing WordPress user, including administrators, simply by supplying that user's email address. This flaw stems from an insecure AJAX handler exposed to unauthenticated users that lacks nonce, capability, or ownership checks before establishing a full authenticated session.

wordpressplugin-vulnerabilityarbitrary-file-deletionunauthenticated-rcecontact-form-7web-application-security

The RapiSafe – Secure Multi File Upload plugin for Contact Form 7 (versions up to 1.0.4) contains an unauthenticated arbitrary file deletion vulnerability in its AJAX upload removal handler. Attackers can exploit exposed nonces to delete critical files such as wp-config.php, potentially triggering a reinstallation flow that leads to full remote code execution and site takeover. Given the plugin's popularity and the ease of exploitation (no authentication required), this poses a severe risk to any WordPress site running the affected component.

CVE-2026-17186IBMDb2command-injectionIBM-iremote-code-execution

A critical vulnerability in IBM Db2 Mirror for i allows a remote, likely unauthenticated attacker to execute arbitrary CL (Control Language) commands due to improper input sanitization. With a CVSS score of 9.9, successful exploitation could lead to full compromise of the affected IBM i system.

ibmdb2rcepath-traversalibm-icritical-infrastructure

A critical vulnerability in IBM Db2 Mirror for i (versions 7.4, 7.5, 7.6) allows remote attackers to execute arbitrary code by exploiting external control of file name or path. With a CVSS score of 9.8, this flaw poses severe risk to organizations running IBM i systems for high-availability database replication.

adtechprivacytrackingtransparency-toolnon-malicious

DecryptAds is a new free service that scrapes and correlates adtech and mobile SDK data to help users identify which companies are tracking them via websites and apps. This is a privacy/transparency tool rather than a malicious threat, though it highlights the scale of existing ad-tracking infrastructure. No exploit, malware, or attack vector is involved.

SAPCommerce CloudRCEunauthenticatedinput-validationauthorization-bypasspatch-now

SAP has patched a maximum-severity (CVSS 10.0) vulnerability in Commerce Cloud's Data Hub Adapter that allows unauthenticated attackers to execute arbitrary code due to insufficient authorization checks and input validation. Given the flaw requires no authentication and results in full code execution, organizations running affected SAP Commerce Cloud deployments should prioritize immediate patching.

supply-chainpypilitellmcredential-theftpythonagent-relevantcloud-securitysecrets-exposure

Two malicious versions of the popular LiteLLM package were published to PyPI in March and remained live for roughly 40 minutes, long enough to be pulled by automated build pipelines and developers. The packages contained credential-harvesting code that exfiltrated cloud keys, SSH keys, Kubernetes tokens, and database passwords, with CloudSEK estimating exposure impacting over 2,100 organizations based on a dataset of ~434,000 captured files.

vmwarevcenterrcedirectory-traversalvirtualizationpersistent-accessagent-relevant

Threat actors are actively exploiting a critical directory-traversal vulnerability (CVE-2026-59310, CVSS 9.8) in Broadcom VMware vCenter to achieve remote code execution and establish persistent access. The flaw affects any attacker with network access to the vCenter management interface, making unpatched instances high-value targets for post-exploitation activity including lateral movement and infrastructure takeover.

macOSauthentication-bypasscryptominingmoneroexploit-code-publicagent-relevant

Hackers are actively exploiting a macOS Screen Sharing authentication bypass vulnerability following the release of public exploit code, according to the Netherlands' NCSC. Attackers use the flaw to gain unauthorized remote access to macOS systems and deploy Monero (XMR) cryptocurrency miners. Organizations running exposed macOS Screen Sharing services are at immediate risk of unauthorized access and resource hijacking.

banking-fraudthird-party-riskservice-provider-compromiselaw-enforcementfinancial-crime

Law enforcement in Brazil and Europe arrested seven individuals connected to a fraud scheme that exploited a vulnerability at a third-party service provider to withdraw approximately €30 million from Commerzbank customer accounts. The case highlights the ongoing risk that vulnerabilities in banking service providers and payment intermediaries pose to end customers.

AI-safetywatermarkingcontent-provenancenot-a-threatinformational

This is a news report on Anthropic's plans to implement watermarking for AI-generated text produced by Claude, aimed at improving content provenance and detection of AI-generated material. This is a defensive/product feature announcement rather than a security threat, vulnerability, or attack campaign.

ICSOTvulnerabilityOS-command-injectionSiemensvideo-management-systemphysical-securityCVE-2026-3014privileged-user-exploit

Siemens Siveillance Video Management Servers (based on Milestone XProtect) contain a critical OS command injection vulnerability in the Management Server API that allows users with edit permissions to execute arbitrary code in the context of the Management Server service. Siemens has released patched versions for the affected V2023 R3, V2024 R1, and V2025 product lines and urges immediate updates.

icsotbuilding-automationxsscwe-79johnson-controlsmetasyscisa-advisory

A high-severity persistent cross-site scripting vulnerability affects Johnson Controls Metasys building automation systems (versions 12–15), allowing a low-privilege user to inject a malicious payload via a crafted URL that executes in other users' sessions, including administrators. This could lead to session hijacking and unauthorized access within critical infrastructure environments such as commercial facilities, manufacturing, energy, and government sites. No public exploitation has been reported to CISA at this time, but patches or vendor guidance are available for supported versions.

ICSOTCVE-2026-64887CVE-2026-34492hard-coded-keypath-traversalarbitrary-file-readcritical-infrastructurejohnson-controlsCISA

Johnson Controls Airwall versions 4.0.4 and earlier contain two vulnerabilities: a hard-coded cryptographic key used identically across all deployments, and an arbitrary file read flaw via path traversal. Combined, these could allow an attacker with local access or code/binary access to decrypt sensitive configuration data or read arbitrary files including credential stores and private keys. No public exploitation has been reported, and both flaws require local access or high attack complexity, limiting immediate risk.