Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 918 threats
A critical, previously unknown SQL injection vulnerability in Metabase, a widely used open-source business intelligence and analytics platform, was exploited in zero-day attacks to breach customer instances and exfiltrate data. Confirmed victims include Framework and Tally, both of which have publicly disclosed the incidents. The flaw allows attackers to bypass authentication and query controls to access sensitive underlying database contents.
Five vulnerabilities in the Controller-Pilot Data Link Communications (CPDLC) protocol over ATN-B1, used for aircraft-air traffic control text communications, allow unauthenticated message injection, denial-of-service, and forced session resets via unauthenticated clear-text radio frequency links. While not creating an unsafe aircraft condition directly, exploitation can degrade operational safety margins by increasing controller/pilot workload, delaying safety-critical instructions, and reducing situational awareness. No public exploitation has been observed, and attack complexity is high, requiring lab-like conditions.
CISA has added CVE-2026-8037, a command injection vulnerability in Progress LoadMaster, to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation in the wild. Federal civilian agencies are required under BOD 26-04 to remediate this vulnerability on a prioritized timeline due to its potential to grant attackers total control of affected assets.
CVE-2026-56793 is an improper authentication vulnerability in Dell OpenManage Server Administrator (OMSA) affecting versions prior to 11.1.0.2. An unauthenticated remote attacker could exploit this flaw to gain unauthorized access to server management interfaces, potentially leading to further compromise of underlying infrastructure.
CVE-2026-62836 is a high-severity vulnerability in Azure SQL Managed Instance caused by improper restriction of communication channels to intended endpoints. An unauthorized attacker could exploit this over the network to elevate privileges without prior authentication, potentially gaining unauthorized access to sensitive data and control over database resources.
Dell Virtual Storage Integrator (VSI) for VMware vSphere Client versions prior to 10.11.1.0 contain a critical sensitive information disclosure vulnerability that allows unauthenticated remote attackers to steal active session credentials. Exploitation enables full impersonation of authenticated users, including administrators, within vSphere environments.
CVE-2026-8037 is an unauthenticated command injection vulnerability in Progress LoadMaster that allows attackers to execute arbitrary commands on the appliance via unsanitized input on multiple management endpoints. CISA has added this to its Known Exploited Vulnerabilities catalog with a short remediation window, indicating active exploitation in the wild. Organizations using LoadMaster for load balancing and application delivery, including in front of internal services, should treat this as an urgent patching priority.
Connor Riley Moucka, a Canadian national linked to the 2024 Snowflake extortion campaign, pleaded guilty to computer fraud and conspiracy charges tied to breaches of over 165 organizations, including the theft of call and text metadata for more than 100 million AT&T customers. The campaign exploited stolen credentials and lack of MFA on customer Snowflake accounts rather than a vulnerability in Snowflake itself, enabling mass data theft and subsequent extortion.
MIT CSAIL researchers demonstrated a new microarchitectural attack called Interrupt Injection that bypasses existing Spectre v2 mitigations on Intel and AMD CPUs by timing a hardware interrupt to re-poison the branch predictor immediately after the kernel sanitizes it. The attack was proven on an AMD Zen 2 system running Linux 6.14 with all default Spectre v2 defenses enabled, allowing an unprivileged local process to leak protected kernel or cross-process data via speculative execution.
Cisco disclosed 12 vulnerabilities affecting Catalyst SD-WAN Software and IOS XE Software, including three critical flaws with CVSS scores of 9.8, discovered during an internal security review. These issues affect SD-WAN devices regardless of configuration and IOS XE devices running in autonomous or controller mode, posing significant risk to enterprise network infrastructure.
A newly disclosed Linux kernel vulnerability dubbed Zapscape (CVE-2026-64561) affects KVM/x86's shadow MMU and can allow an attacker with kernel-level privileges inside a nested L1 guest VM to escape isolation and execute code on the host. This poses significant risk to cloud and virtualization providers that expose nested virtualization to untrusted or semi-trusted tenants.
A wave of cyberattacks against hedge funds, private-equity firms, and other financial organizations has been attributed to UNC6671, an extortion group linked to the BlackFile threat actors. The campaign appears focused on data theft and extortion rather than pure ransomware encryption, targeting high-value financial sector victims. Details on initial access vectors and specific TTPs remain limited in current reporting.
A ClickFix-style social engineering campaign is distributing a Go-based infostealer targeting macOS users, designed to exfiltrate cryptocurrency wallets, browser-saved passwords, Apple Keychain contents, and cached credentials. The attack relies on tricking victims into manually executing malicious commands via fake verification or error prompts, bypassing typical download-based security controls.
This article reports a routine product update from OpenAI, announcing new ChatGPT model versions (GPT-5.6 Sol and GPT-5.6 Luna) being rolled out to Plus, Pro, and Free tier users. There is no vulnerability, exploit, malware, or attack activity described in this content.
ABB Ability Zenon's IIoT services bundle an outdated MongoDB 4.2 instance affected by 13 known MongoDB vulnerabilities, including memory disclosure, authentication/authorization bypass, denial-of-service, log injection, and certificate validation flaws. Successful exploitation could allow attackers to bypass security controls, crash services, execute unauthorized actions, or expose sensitive data on affected industrial control system deployments worldwide.
Johnson Controls TL280 camera devices running firmware versions below 5.63 contain a vulnerability involving use of a broken or risky cryptographic algorithm, tracked as CVE-2026-27871, which stems from hardcoded credentials embedded in the firmware. Successful exploitation could allow an attacker to access sensitive information on the device, though the attack requires high complexity and privileges. Johnson Controls has released firmware 5.63 to remediate the issue and recommends network segmentation and credential rotation as mitigations.
A heap out-of-bounds write vulnerability (CVE-2026-17264) affects Medixant RadiAnt DICOM Viewer versions 2025.2 and earlier, triggered by opening a maliciously crafted DICOM file with malformed JPEG-compressed pixel data. Successful exploitation could crash the application or potentially allow remote code execution, though built-in exploit mitigations (CFG, DEP, ASLR) reduce practical exploitability. No known public exploitation has been reported to date.
CVE-2026-53984 is a critical unauthenticated vulnerability in Ground Station software prior to version 0.6.0, allowing any network peer to destroy or tamper with the entire SQLite database via an exposed Socket.IO event handler. Attackers can wipe operational data or inject fabricated orbital-source URLs to redirect the ground station to attacker-controlled servers, enabling data manipulation and potential downstream compromise.
CVE-2026-66321 is a type confusion vulnerability in Microsoft Edge (Chromium-based) that allows an unauthorized remote attacker to execute arbitrary code, typically via a malicious or compromised web page. Exploitation requires a victim to interact with attacker-controlled content, but successful attacks can lead to full code execution within the browser context.
Poison Claude is an underground service advertising discounted, illegitimate access to Anthropic's Claude models (including Opus 4.8/4.7/4.6 and Sonnet 4.6), likely by reselling stolen or abused API credentials/accounts. The operator sits in the middle of every session, meaning all customer prompts, outputs, and potentially embedded secrets pass through an untrusted third party. This represents a significant confidentiality and data-exfiltration risk for any individual or organization using the service, including those integrating it into automated or agentic workflows.