Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 918 threats

sql-injectionrceadobecampaign-classiccritical-vulnerabilityunauthenticatedscope-change

A critical SQL Injection vulnerability in Adobe Campaign Classic (CVE-2026-48330) allows an unauthenticated attacker to execute arbitrary SQL commands and achieve remote code execution in the context of the current user, with no user interaction required. With a maximum CVSS score of 10.0 and a scope change, successful exploitation could grant attackers elevated access, full control over the marketing automation platform, and lateral movement into connected infrastructure.

apachetomcatencryption-bypasscisa-kevcluster-securityagent-relevant

Apache Tomcat contains a vulnerability that allows attackers to bypass the EncryptInterceptor, a component intended to encrypt sensitive data transmitted between nodes in a Tomcat cluster. This CVE has been added to CISA's Known Exploited Vulnerabilities catalog with a short remediation window, indicating active exploitation in the wild. Organizations running clustered Tomcat deployments should prioritize patching immediately.

ransomwareVPNSonicWallexploitationdata-leak-siteedge-deviceinitial-accessagent-relevant

The INC Ransomware group has become the dominant threat actor exploiting recently disclosed vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, with a sharp increase in activity since early August 2026. Multiple victims have already been listed on the group's data leak site, indicating active and successful exploitation in the wild.

passkeyscredential-theftWindowsChromeGoogle-Password-Managerlocal-malwareauthentication-bypassagent-relevant

Unit 42 researchers disclosed three attack techniques against Chrome's Google Password Manager cloud authenticator that allow user-level malware on a compromised Windows machine to sign into passkey-protected accounts without any biometric, PIN, or user-visible prompt. The strongest variant, Golden Pass-ta-key, targets the underlying master key, enabling silent, persistent account takeover even after remediation. This undermines the core phishing-resistance promise of passkeys when the endpoint itself is compromised.

npmsupply-chainRATdependency-confusiontyposquattingAlibabasoftware-supply-chainagent-relevant

Researchers identified 18 malicious npm packages, including one named 'lib-mtop' impersonating a private Alibaba package, designed to deliver a cross-platform remote access trojan to developers using Alibaba developer tools. The campaign appears to specifically target Chinese-speaking development environments through a targeted software supply chain attack, likely leveraging dependency confusion or typosquatting techniques.

ClickFixloader-as-a-servicesteganographyCountLoaderDeviceManagerRATRussian-threat-actorsocial-engineeringcross-platformcredential-theftagent-relevant

DOUBLECUP is a newly identified Russian loader-as-a-service that leverages ClickFix-style social engineering to trick victims into executing malicious commands, hiding payload code inside PNG images stored in browser caches. The service delivers CountLoader to both Windows and macOS victims and a new Windows-targeted remote access trojan called DeviceManager, expanding the threat actor's toolkit for initial access and persistent remote control.

passkeyscredential-theftwindowsgoogle-password-managerpost-exploitationaccount-takeoveragent-relevant

Security researchers disclosed three attack techniques, collectively dubbed 'Pass-ta-key,' that allow malware already present on a compromised Windows device to abuse Google Password Manager's synced passkey feature. The attacks enable adversaries to bypass user verification, hijack accounts protected by passkeys, and extract passkey private keys, undermining a core assumption that passkeys are phishing-resistant and device-bound.

APT29Midnight BlizzardhospitalityWi-FiMicrosoft 365credential-theftRussianation-stateagent-relevant

Microsoft has attributed a global campaign against hospitality Wi-Fi networks to the Russian state-sponsored actor Midnight Blizzard (APT29). The group uses custom malware deployed via compromised hotel networks to intercept traffic and steal Microsoft 365 credentials from traveling targets, likely diplomats, government officials, and corporate executives. The campaign highlights the ongoing risk of adversary-in-the-middle attacks on untrusted public networks.

CISAKEVauthentication-bypassN-ableN-centralRMMvulnerability-managementfederal-directive

CISA has added CVE-2026-18577, an authentication bypass vulnerability in N-able N-central, to its Known Exploited Vulnerabilities Catalog based on confirmed active exploitation. Federal civilian agencies are required under BOD 26-04 to remediate this vulnerability on a prioritized timeline, and CISA urges all organizations to apply the same urgency.

command-injectionrouteriotnetwork-devicercepublic-exploitgl-inet

A critical command injection vulnerability affects GL-iNet GL-MT3000 routers up to firmware version 4.4.5, residing in the server.set_peer function of the wg-server.so native plugin exposed via /cgi-bin/glc. The flaw allows unauthenticated or low-privilege remote attackers to inject arbitrary OS commands through the public_key parameter, and a public exploit is already available, significantly increasing the risk of active exploitation.

command-injectioniotrouterrcepublic-exploitnetwork-appliance

A critical command injection vulnerability affects the s2s.enable_echo_server function within the s2s.so native plugin on GL-iNet GL-MT3000 routers up to version 4.4.5. The flaw allows unauthenticated remote attackers to inject arbitrary OS commands via the 'port' argument, and a public exploit is already available. Given the CVSS score of 9.8 and remote exploitability, affected devices are at immediate risk of full compromise.

authentication-bypasscrmprivilege-escalationunauthenticated-rce-pathweb-applicationpre-authagent-relevant

Krayin CRM 2.2.4 contains a critical missing authentication vulnerability that allows unauthenticated attackers to overwrite the primary administrator account by exploiting a flaw in the installer middleware bypass logic. Successful exploitation grants full administrative access to all CRM data, including customer records, credentials, and any integrated API keys or tokens.

rceeval-injectionsql-injectionhealthcareopenemrweb-applicationprivilege-escalation

A critical remote code execution vulnerability exists in OpenEMR through 8.2.0, allowing authenticated administrators to inject PHP payloads into the categories database table via SQL manipulation. The payload is later executed through an unsanitized eval() call in the CategoryTree component, which can be triggered by unauthenticated or low-privilege pages, resulting in full command execution as the web server user.

command-injectionrouteriotrceopenvpnunauthenticatedpublic-exploit

A critical command injection vulnerability exists in the ovpn-client.so plugin of GL.iNet GL-MT3000 routers (up to firmware 4.4.5), reachable via the /cgi-bin/glc endpoint. An attacker can remotely inject OS commands through the Hostname parameter of the get_recommend_config function, potentially achieving full device compromise. The exploit has been publicly disclosed, increasing the likelihood of active exploitation.

authentication-bypassrmmpatch-bypasscisa-kevaccount-takeovern-central

CVE-2026-18577 is an authentication bypass in N-able N-central, a widely deployed remote monitoring and management (RMM) platform, resulting from an incomplete fix for the prior vulnerability CVE-2026-18556. CISA has added this flaw to its Known Exploited Vulnerabilities catalog with an unusually short remediation window, indicating active or imminent exploitation. Successful exploitation allows attackers to bypass authentication entirely and take over accounts within N-central.

chromebrowser-securitypatch-managementvulnerability-disclosuregoogle

Google released three Chrome updates (versions 149, 150, and 151) fixing a cumulative total of 1,442 security bugs, far exceeding the combined total of the previous 23 releases. This represents a significant spike in disclosed vulnerabilities, largely attributed to internal discovery efforts rather than active exploitation reports.

captive-portal-hijackfake-updateRATsurveillance-malwareMidnight-BlizzardStorm-2945hospitalitynation-statecredential-theftagent-relevant

Microsoft has identified a campaign, tracked as CaptiveCrunch, in which threat actors hijack hotel Wi-Fi captive portals to serve fake browser update prompts. Victims who install the fake update are infected with CornFlake, a remote access trojan capable of capturing webcam images, microphone audio, and keystrokes. The activity is attributed to Storm-2945, assessed as an operational sub-cluster of the Russian state-sponsored group Midnight Blizzard (APT29).

adobecampaign-classicrceauthorization-bypassunauthenticatedcritical-vulnerability

Adobe has issued an emergency patch for a maximum-severity flaw (CVSS 10.0) in Campaign Classic, its enterprise marketing automation platform, caused by incorrect authorization checks. The vulnerability allows arbitrary code execution without any user interaction, making it a high-priority target for exploitation once details or a proof-of-concept become public.

browser-securitychromeextensionsdefensive-featurenew-tab-hijacking

Google is developing a Chrome security feature to block policy-installed extensions from hijacking the New Tab page or overriding the default search engine. This is a defensive enhancement rather than an active exploit, aimed at curbing a common malicious/adware extension technique often used to redirect traffic and harvest ad revenue or credentials.

cryptocurrencyhardware-walletrng-flawkey-managementbitcoin-theftsupply-chain

A flawed random number generator in COLDCARD hardware wallet firmware produced predictable or low-entropy seed phrases, enabling attackers to reconstruct private keys and drain wallets. The flaw is believed responsible for the theft of approximately $88.6 million in Bitcoin from thousands of affected wallets.