Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 918 threats
OpenAI disrupted a Cambodia-based scam network operating out of Poipet that used coordinated ChatGPT accounts to generate content for investment fraud, romance scams, illegal gambling promotion, and law enforcement impersonation schemes. The operation leveraged generative AI to scale social engineering content creation and craft convincing fraudulent communications targeting victims across multiple scam categories. OpenAI banned the associated accounts as part of its abuse enforcement efforts.
A large-scale ClickFix campaign spanning over 250 front-end domains uses server-side browser fingerprinting to selectively serve fake software download lures to macOS users while hiding malicious content from crawlers and sandboxes. Microsoft Threat Intelligence has been tracking this infrastructure for weeks, noting the increased sophistication of its evasion techniques targeting Mac users specifically.
Threat actors exploited a SQL injection vulnerability to deploy the khunt post-exploitation toolkit directly within an Oracle database, using it as a foothold to breach the broader corporate network. This attack highlights database servers as an underexploited but high-value initial access vector, especially when they hold elevated privileges or trusted network connectivity.
A Canadian national pleaded guilty to participating in a large-scale data theft and extortion campaign targeting Snowflake cloud storage customers, affecting at least 165 organizations. The attackers used stolen or weak credentials—lacking multi-factor authentication—to access customer Snowflake instances, exfiltrate sensitive data, and extort victims for millions of dollars.
Maksim Silnikau, creator and administrator of the Ransom Cartel ransomware operation, has been sentenced to 16 years in prison for orchestrating attacks against at least 18 companies worldwide. This is a law enforcement outcome rather than an active ongoing threat, though affiliates and derivative variants of the ransomware family may still pose risk to organizations that have not fully remediated prior infections.
CISA has added CVE-2026-63077, a deserialization of untrusted data vulnerability in JetBrains TeamCity, to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation. Under BOD 26-04, FCEB agencies must prioritize remediation of this vulnerability on publicly exposed assets, as it may grant attackers total control of affected systems post-exploitation. All organizations, including those outside federal scope, are strongly encouraged to remediate promptly given the severity of CI/CD compromise.
A critical vulnerability in boringproxy (through 0.10.0) allows low-privileged authenticated users to inject arbitrary SSH public keys into the server's authorized_keys file via a newline injection flaw in the tunnel creation endpoint's domain parameter. Successful exploitation grants attackers persistent SSH shell access to the proxy server and enables theft of cleartext credentials, tunnel private keys, and TLS certificates stored in the local database. Given the CVSS score of 9.9, this represents a full compromise path from limited tunnel-creation privileges to complete host takeover.
Apache NiFi versions 2.0.0 through 2.10.0 contain a broken access control vulnerability in the Asset management REST API tied to Parameter Contexts. An attacker with write access to one Parameter Context can delete Assets belonging to a different Parameter Context they are not authorized for, by manipulating the supplied identifiers. This affects deployments that rely on differentiated authorization across Parameter Contexts as a security boundary.
Apache NiFi versions 1.10.0 through 2.10.0 contain a broken authorization flaw in the Parameter Context update REST API that fails to enforce component-level authorization checks. An authenticated user with only Parameter Context modification rights can alter parameter values affecting components they are not authorized to manage, potentially triggering code execution via scripting-based parameters during automatic validation. Organizations should upgrade to NiFi 2.11.0 immediately, especially those using component-level authorization policies.
A critical unauthenticated remote code execution vulnerability has been identified in JetBrains TeamCity, exploitable via insecure deserialization in the agent polling protocol. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog with an unusually short remediation window, indicating active or imminent exploitation. Organizations running TeamCity build servers should treat this as an urgent patching priority.
Securonix Threat Labs identified an active, multi-wave social engineering campaign dubbed SMOKE#SCREEN that uses fake Adobe and Zoom update prompts, fraudulent document review notices, and system maintenance lures to trick victims into installing ConnectWise ScreenConnect. Once installed, the legitimate RMM tool grants attackers persistent, stealthy remote access to compromised endpoints, bypassing many traditional malware detection controls due to ScreenConnect's legitimate code signing.
The Greatness PhaaS platform has added device code phishing capabilities, allowing attackers to abuse the legitimate OAuth 2.0 Device Authorization Grant flow to bypass MFA and hijack user sessions via stolen tokens. Combined with its existing adversary-in-the-middle (AiTM) credential phishing, this significantly lowers the barrier for attackers to compromise MFA-protected accounts at scale.
The Greatness phishing-as-a-service platform has evolved from basic credential phishing to adversary-in-the-middle (AiTM) and device-code phishing techniques, now spoofing RingCentral notifications to target Microsoft 365 accounts. This expansion enables attackers to bypass MFA protections and steal session tokens, significantly increasing the risk of successful account takeovers across organizations using Microsoft 365.
TP-Link has patched 15 vulnerabilities in the zero-touch provisioning mechanism of its Omada network devices. These flaws can be chained with previously disclosed vulnerabilities to achieve remote code execution, potentially allowing attackers to breach entire networks through compromised network infrastructure.
Acrisure KARR BT and DR-100 anti-theft systems use a shared, hard-coded Bluetooth authentication key across all affected devices, allowing an attacker within Bluetooth range to send unauthorized commands to a vehicle. This could enable unauthorized door unlocking or engine immobilization. Acrisure has released a firmware update (July 20, 2026) to address the flaw, and no public exploitation has been reported.
A vulnerability in multiple Thermo Fisher Applied Biosystems Genetic Analyzer software products allows tampering with .fsa/.hid output files due to missing integrity checks, which could result in falsified DNA test results. The flaw requires local access and no user interaction, affecting eight product lines including several that are end-of-life with no patch available.
A critical unauthenticated remote code execution vulnerability affects MaxSite CMS, allowing attackers to inject arbitrary PHP code into the application's configuration file via the install endpoint. Exploitation results in persistent RCE as the web-server process user, requiring no authentication and enabling full compromise of the affected host.
MaxSite CMS versions 109.5 and earlier contain a critical authentication bypass in the AJAX dispatcher, allowing unauthenticated attackers to reach admin-gated plugin endpoints. Exploitation requires only a crafted X-Requested-With header and a base64-encoded path pointing to any *-ajax.php file, enabling actions like poll manipulation and potentially more severe abuse depending on the targeted plugin.
kotaemon, an open-source RAG (retrieval-augmented generation) UI and document QA toolkit through version 0.12.0, contains a critical unauthenticated insecure deserialization vulnerability in its check_connection endpoint. Attackers can supply crafted YAML/JSON payloads with a manipulated __type__ field to instantiate arbitrary Python classes, ultimately achieving remote code execution via subprocess.check_output injection.
A critical unauthenticated command injection vulnerability affects Puwell IP Camera firmware versions 2.x through 4.x, allowing remote attackers to achieve root-level code execution via a crafted JSON payload sent to the exposed DebugShell service on TCP port 34567. Given the CVSS score of 9.8 and lack of any authentication barrier, this vulnerability is likely to be rapidly weaponized by botnet operators and IoT malware families for mass exploitation.