Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 918 threats

routercommand-injectionrcefirmwareiotunauthenticatednetwork-infrastructure

A critical command injection vulnerability exists in the alg function of MSI Radix AXE6600 router firmware v781521, allowing remote attackers to execute arbitrary commands with root privileges. With a CVSS score of 9.8, this flaw could enable full device takeover, network pivoting, and traffic interception on affected routers.

routercommand-injectionrceiotfirmwareunauthenticated-rce

A critical unauthenticated command injection vulnerability (CVE-2026-71986) exists in the dmz function of MSI Radix AXE6600 router firmware v781521, allowing remote attackers to execute arbitrary commands and gain root access. With a CVSS score of 9.8, this flaw poses severe risk to any network relying on the affected device for perimeter security or connectivity.

routercommand-injectionrceiotnetwork-infrastructureunauthenticated

A critical command injection vulnerability exists in the accesscontrol function of MSI Radix AXE6600 router firmware v781521, allowing remote attackers to execute arbitrary commands with root privileges. Given the CVSS score of 9.8, exploitation likely requires no authentication and results in full device compromise, enabling attackers to intercept, redirect, or manipulate all network traffic passing through the device.

router-vulnerabilitycommand-injectionrceiotnetwork-infrastructureunauthenticated-exploit

A critical unauthenticated command injection vulnerability exists in the urlfilter function of MSI Radix AXE6600 router firmware v781521, allowing remote attackers to execute arbitrary commands with root privileges. Given the CVSS score of 9.8 and remote exploitability without authentication, this vulnerability poses severe risk to any network using affected devices, potentially enabling full network compromise, traffic interception, or pivot points for further attacks.

routercommand-injectionrcefirmwareiotnetwork-deviceunauthenticated

A critical unauthenticated command injection vulnerability exists in the wps.cgi interface of MSI Radix AXE6600 routers running firmware v781521. Remote attackers can inject malicious commands via the pin2g, pin5g, or pin6g parameters to achieve arbitrary command execution with root privileges. This flaw can allow full device takeover, enabling network-level man-in-the-middle attacks, traffic interception, and pivoting into internal networks.

metabasesql-injectionzero-dayunauthenticated-rcebusiness-intelligenceagent-relevantrag-pipelinecredential-exposure

Metabase has disclosed a maximum-severity (CVSS 10.0) zero-day vulnerability being actively exploited in the wild, allowing unauthenticated remote attackers to inject arbitrary SQL and gain administrative access to Metabase instances. No CVE identifier has been assigned yet, but exploitation has already been observed, making this an urgent patching priority for any organization running Metabase for business intelligence or analytics.

webmailcss-injectionphishingcredential-theftui-redressagent-relevantemail-security

PortSwigger researcher Gareth disclosed a class of CSS-based attacks that allow content embedded in an email to escape its intended message boundary and manipulate the surrounding webmail interface. Affecting Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, hijack trusted UI elements, leak session tokens, take over third-party accounts, and manipulate AI tools that process email content.

critical-infrastructureportstransportationoperational-disruptionIT-OT

The North Carolina Ports Authority confirmed a cyberattack that disrupted IT systems and slowed operations at the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. Details on the attack vector, threat actor, and data impact have not been publicly disclosed as of this report. The incident highlights ongoing risk to critical maritime and logistics infrastructure.

banking-malwareBECclipboard-hijackingcryptocurrency-theftbrowser-manipulationemail-compromisefinancial-fraud

Gen's H1 2026 Threat Report details two distinct financially-motivated attack chains: one leveraging compromised legitimate business email accounts combined with browser manipulation to deliver banking malware, and another using clipboard hijacking malware to silently redirect cryptocurrency payments to attacker-controlled wallets. Both campaigns rely on abusing trust in legitimate channels (real inboxes, clipboard contents) rather than novel exploits, making detection via traditional signature-based tools more difficult.

supply-chainbackdoorvideo-conferencinghacktivismtrojanized-installerrussiaagent-relevant

The Head Mare hacktivist group has compromised unpatched TrueConf video conferencing servers to replace legitimate client installers with trojanized versions containing backdoors. This supply-chain attack allows attackers to distribute malware to any organization or user downloading updates from compromised TrueConf servers, posing significant risk to enterprise communication infrastructure.

d-linkrouterbuffer-overflowrceiotunauthenticatednetwork-perimeter

A critical unauthenticated buffer overflow vulnerability affects D-Link DWR-M961 routers running hardware version C1 with a specific firmware build. Remote attackers can send crafted overly long strings to the test4, ssid2, and username fields of the quicksetup.cgi interface to achieve arbitrary command execution or crash the device. With a CVSS score of 9.8, this flaw poses a severe risk to any exposed device, enabling full device takeover, network pivoting, or denial of service.

D-Linkrouterbuffer-overflowRCEIoTnetwork-applianceCVE-2026-71957

A critical buffer overflow vulnerability exists in D-Link DWR-M961 routers (hardware version C1, firmware 1.1.2_C1_202602110044) in the app.cgi web management interface. A remote, unauthenticated attacker can trigger the flaw by submitting an overly long string to the netAcc.addlist[].name field, enabling arbitrary command execution or causing a denial of service. Given the CVSS score of 9.8, this vulnerability poses a severe risk to any network relying on the affected device for connectivity or perimeter security.

d-linkcommand-injectionrouteriotrceunauthenticatednetwork-infrastructure

A critical unauthenticated command injection vulnerability affects D-Link DWR-M961 routers (hardware version C1, firmware 1.1.2_C1_202602110044). Remote attackers can execute arbitrary commands with root privileges via the netDig.ping.dst parameter in the app.cgi interface, enabling full device takeover. With a CVSS score of 9.8, this vulnerability poses severe risk to any network relying on affected devices for connectivity.

iotroutercommand-injectionrced-linkunauthenticatednetwork-device

A critical unauthenticated command injection vulnerability affects D-Link DWR-M961 routers running firmware prior to 1.1.5_C1_202607071108. Attackers can exploit the fota_url parameter in the LTE FOTA upgrade interface to execute arbitrary commands with root privileges, potentially leading to full device compromise. Given the CVSS score of 9.8 and remote exploitability, this poses a severe risk to any network relying on this device for connectivity.

wordpressplugin-vulnerabilityprivilege-escalationauthentication-bypassai-pluginagent-relevantunauthenticated-rce-equivalent

The AI Copilot – Content Generator WordPress plugin (versions up to 1.5.6) contains an authorization bypass vulnerability allowing unauthenticated attackers to create administrator accounts and fully take over affected sites. The flaw stems from a nonce value being exposed in publicly accessible JavaScript, rendering the plugin's authorization check ineffective on any page rendering the [aiwu-form] shortcode or public chatbot.

vishingsocial-engineeringsaasdata-extortioncredential-thefthelp-desk-impersonationagent-relevant

UNC6671 is a data extortion group conducting voice phishing attacks against financial services, private equity, and professional services firms. The group impersonates IT help desk staff and contacts employees via personal phones to coerce urgent 'security migration' actions that grant attackers access to SaaS environments and enterprise data.

clickfixmacosinfostealercrypto-theftsocial-engineeringcredential-theftagent-relevant

A ClickFix-style social engineering campaign is delivering a Go-based macOS infostealer capable of draining cryptocurrency wallets, harvesting browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The infection chain uses a shell script that profiles the victim's CPU architecture before fetching an architecture-specific malware payload, indicating deliberate targeting and evasion.

npmtyposquattingsupply-chainRATinfostealermalwarecross-platformagent-relevant

Nearly 800 malicious npm packages were identified delivering a cross-platform Remote Access Trojan and infostealer payload to Windows, macOS, and Linux systems. The packages use AI-generated or randomly typo-squatted names to trick developers into installing them via automated or manual dependency resolution.

social-engineeringdata-breachcorporate-espionageemployee-targetingcredential-theft

Levi Strauss & Co. disclosed that attackers used social engineering tactics against three employees to gain unauthorized access to corporate data stored on their machines. The incident resulted in the theft of corporate information, though full scope of the compromised data has not been publicly detailed. This represents a targeted human-layer attack rather than a technical exploit of infrastructure.

data-breachhealthcarepii-exposurethird-party-risk

Unlimited Technology Systems, a healthcare software company, disclosed a data breach affecting more than 3.8 million individuals stemming from an incident that occurred in October 2025. Details on the specific attack vector, threat actor, and exact data types exposed remain limited in public reporting.