Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 120 threats
This is a vendor advisory (Kaseya via BleepingComputer) describing how AI is making phishing emails more personalized and convincing, allowing them to bypass traditional email filters. It recommends MSPs adopt layered monitoring across identity, email, and endpoint activity to catch attacks that reach user inboxes.
Johnson Controls Simplex Incident Manager versions up to V2.01 store user credentials, including passwords and authentication tokens, in cleartext within system memory. A local low-privileged attacker could extract these credentials using memory-dumping techniques, potentially gaining unauthorized access to the application and connected building automation systems. Johnson Controls has released patched version v2.01.01 to remediate the issue.
OpenAI temporarily paused reinforcement learning (RL) training of its newest frontier models for two weeks to strengthen internal defenses and expand monitoring, citing growing risks as model capability increases. The move appears preventive, referencing a prior 'Hugging Face-like incident' as a cautionary precedent rather than disclosing an active breach or exploit.
A suspected ransomware affiliate is impersonating a legitimate data recovery firm called 'Ransom Busters,' contacting victims prior to public disclosure of breaches and offering fraudulent decryption keys and data deletion services for payment. This represents a secondary extortion layer that exploits victim desperation and confusion during active incident response, potentially resulting in double payment with no guarantee of data recovery or deletion.
A threat actor group calling itself 'Ransom Busters' is contacting organizations previously victimized by ransomware attacks, falsely claiming to have hacked the original ransomware operators' infrastructure and offering to delete stolen data for a fee of $20,000 to $60,000. This appears to be a secondary extortion scam preying on already-compromised victims rather than a legitimate data recovery or threat actor takedown service.
This is a vendor research report (Picus Security's Blue Report 2026) rather than an active threat, highlighting that security controls often block well-known attack signatures but fail to detect variant or behavioral approaches achieving the same malicious objective. The report underscores the need for continuous behavioral and adversarial testing rather than relying solely on signature- or IOC-based defenses.
GitHub experienced a widespread outage affecting its website, API, Actions, Pull Requests, and other core services. This is a service availability incident rather than a malicious attack, but it disrupts development workflows, CI/CD pipelines, and any automated systems dependent on GitHub's infrastructure.
Pokémon Center notified customers in the UK and Germany of a data breach involving their personal and order information, caused by a compromise at third-party logistics provider CEVA Logistics. The breach resulted in exposure of customer data and led to the cancellation of some pending orders, highlighting risks inherent in outsourced fulfillment operations.
Threema, a secure messaging service, suffered multiple large-scale DDoS attacks that caused severe disruptions to user communications. The attacks appear focused on service availability rather than data compromise, with no evidence of encryption bypass or user data exposure reported.
Cryptocurrency hardware wallet vendor SafePal disclosed a data breach affecting approximately 39,798 customers after an application flaw was exploited to exfiltrate customer order information. A threat actor is now advertising the stolen data for sale on underground forums, raising risk of targeted phishing and social engineering against affected customers.
This report highlights that attacks against Google Workspace increasingly bypass traditional phishing defenses by exploiting stolen OAuth tokens to gain access to Gmail, Drive, and connected third-party applications. Material Security emphasizes that organizations must defend the entire Workspace attack chain, not just the initial login, since attackers can pivot through connected integrations and persistent tokens. This represents a shift toward identity- and token-centric attack paths rather than credential phishing alone.
Evooo1Bot is a newly identified Mirai-based modular Linux botnet targeting internet-facing gateway devices and routers. Once compromised, infected devices are converted into SOCKS5 traffic relay nodes, likely to support proxy-for-hire services or to anonymize other malicious traffic.
Siemens LOGO! Soft Comfort versions prior to V9 contain two vulnerabilities affecting project-file encryption and password protection: a hardcoded AES master key and unsalted SHA-256 password hashes. A local attacker could exploit these flaws to decrypt project files, bypass or remove passwords, and perform efficient offline brute-force attacks, potentially gaining unauthorized access to sensitive PLC project logic and configurations.
Law enforcement in Brazil and Europe arrested seven individuals connected to a fraud scheme that exploited a vulnerability at a third-party service provider to withdraw approximately €30 million from Commerzbank customer accounts. The case highlights the ongoing risk that vulnerabilities in banking service providers and payment intermediaries pose to end customers.
Johnson Controls Airwall versions 4.0.4 and earlier contain two vulnerabilities: a hard-coded cryptographic key used identically across all deployments, and an arbitrary file read flaw via path traversal. Combined, these could allow an attacker with local access or code/binary access to decrypt sensitive configuration data or read arbitrary files including credential stores and private keys. No public exploitation has been reported, and both flaws require local access or high attack complexity, limiting immediate risk.
Picus Labs' Blue Report 2026 analyzed over 338 million attack simulations across production environments in H1 2026, finding that while perimeter/edge defenses have improved significantly, internal detection and containment capabilities have deteriorated. Attackers are increasingly succeeding not through loud, high-signature attacks but through low-noise techniques that evade internal detection once initial defenses are bypassed.
A denial-of-service vulnerability (CVE-2026-59693) affects Siemens Desigo DXR and PXC building automation controllers. An attacker with adjacent network access can send a malformed BACnet packet to cause the device to stop responding, requiring a manual reset or reboot to restore functionality. Siemens has released firmware updates to remediate the issue.
A coordinated campaign involving 737 free VPN and proxy Chrome extensions, published across at least 40 developer accounts, has been found intercepting browser traffic and routing it through attacker-controlled proxy infrastructure. The campaign primarily targets Russian-speaking users attempting to bypass service blocks, with 274 extensions identified as impersonating 66 legitimate brands, and has amassed over 75,000 installs.
Kimwolf v7, an evolution of the AISURU Android/IoT botnet, was discovered by Palo Alto Networks Unit 42 in February 2026 with enhanced HTTP/2-based DDoS capabilities designed to blend malicious traffic with legitimate browsing patterns. The improvements increase operational resilience and evasion, making detection and mitigation more difficult for defenders relying on traditional traffic-signature analysis.
Gen's H1 2026 Threat Report details two distinct financially-motivated attack chains: one leveraging compromised legitimate business email accounts combined with browser manipulation to deliver banking malware, and another using clipboard hijacking malware to silently redirect cryptocurrency payments to attacker-controlled wallets. Both campaigns rely on abusing trust in legitimate channels (real inboxes, clipboard contents) rather than novel exploits, making detection via traditional signature-based tools more difficult.