Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 889 threats

Cl0pFIN11ransomwaredata-extortionPLMRCEpre-authPTC-WindchillFlexPLM

Cl0p-affiliated threat actors (FIN11, Graceful Spider, Lace Tempest) are exploiting internet-exposed PTC Windchill and FlexPLM PLM software through a chained vulnerability enabling unauthenticated remote code execution. The campaign appears focused on data theft and extortion rather than traditional file encryption, consistent with Cl0p's established MO of mass exploitation of enterprise file transfer and PLM platforms.

phishingcredential-theftreal-time-hijackingsession-hijackinginsurance-sectorfinancial-fraudsocial-engineeringadversary-in-the-middle

CTM360 researchers identified a shift in insurance-sector phishing campaigns from traditional credential harvesting to real-time account hijacking, where stolen credentials and session tokens are used immediately to take over accounts before victims can react. This evolution suggests attackers are increasingly leveraging automated relay infrastructure or adversary-in-the-middle (AiTM) techniques to bypass MFA and act on stolen sessions within seconds of capture.

outagecloud-reliabilitymicrosoft365azureavailabilityno-malicious-activity

Microsoft confirmed that a bug in its automated network maintenance request system caused a widespread outage affecting Microsoft 365 and Azure services. The bug erroneously removed IP routes from more network devices than intended, disrupting connectivity and service availability. This was a self-inflicted operational failure, not the result of a cyberattack or malicious activity.

outageavailabilityopenaichatgptagent-relevant

OpenAI confirmed a worldwide outage affecting ChatGPT connectivity, disrupting user access to the chatbot service. No evidence suggests this was caused by a malicious attack; it appears to be an availability incident rather than a security breach.

supply-chainpackage-securitygithubpypidependabotdefensive-measureagent-relevantopen-source-security

GitHub and PyPI have rolled out a time-based defense mechanism within Dependabot to reduce the risk and blast radius of supply-chain attacks against open-source packages. This is a defensive/protective development rather than an active threat, aimed at limiting exposure windows for malicious or compromised dependency updates.

ICSOTindustrial-control-systemsCISAplaintext-passwordconfused-deputypass-the-hashweak-encryptioncritical-infrastructure

Panduit IntraVUE versions 3.2.1a14 and earlier contain five vulnerabilities, including a critical confused-deputy proxy flaw (CVSS 10) that allows attackers with IT network access to bypass OT segmentation and manipulate industrial control devices without authentication. Additional flaws expose plaintext credentials via the API, leak host/share filesystem and asset information to unauthenticated users, and use weak encryption enabling pass-the-hash admin credential theft. CISA advises upgrading to version 3.2.1a16 or later; no known public exploitation has been reported to date.

gitlabrceproof-of-conceptauthenticated-exploitjupyter-notebookheap-leakgitsource-code-managementagent-relevant

A public proof-of-concept exploit now lets any authenticated user with push access to a GitLab project execute arbitrary commands as the 'git' user on unpatched self-managed GitLab 18.11.3 instances. GitLab shipped a fix six weeks before the PoC was released, meaning organizations that have not applied the patch are immediately exposed to remote code execution. Because GitLab often hosts CI/CD pipelines, secrets, and automation scripts used by AI agent and MLOps workflows, this flaw poses a direct risk to agent-integrated development environments.

fastjsonjavarceunpatchedspring-bootzero-dayagent-relevantsupply-chain-risk

Attackers are actively exploiting an unpatched critical vulnerability in Fastjson 1.x, Alibaba's widely used JSON serialization library for Java, to achieve unauthenticated remote code execution in Spring Boot applications. Security firms ThreatBook and Imperva have observed live exploitation attempts, and no official patch is currently available, leaving deployed systems exposed. The flaw allows a crafted JSON request to trigger code execution with the privileges of the underlying Java process.

malvertisingwindowsfake-cryptosocial-engineeringevasionbun-runtimetrading-platforms

SourTrade is a malvertising campaign active since late 2024 that impersonates trusted brands like TradingView, Solana, and Luno to lure retail traders and crypto investors. It uniquely constructs its malicious Windows executable client-side, in the victim's browser, using a legitimate Bun JavaScript runtime as its base, avoiding detection by never serving a single complete malicious binary from a static URL.

sextortiondata-breachextortionemail-scamShinyHunterssocial-engineering

Threat actors are leveraging email addresses and personal data leaked by the ShinyHunters extortion group to send mass sextortion emails demanding $2,000 in Bitcoin. The scam uses previously breached data to add false credibility, threatening victims with fake claims of compromising webcam footage or browsing history unless payment is made.

malvertisingfileless-malwarecryptocurrencybrowser-based-attacksocial-engineeringin-memory-executionagent-relevant

A large-scale malvertising campaign is directing users to fake Solana, Luno, and TradingView websites that use malicious JavaScript to assemble malware directly in browser memory, evading disk-based detection. The campaign targets users seeking cryptocurrency and trading tools, likely aiming to steal credentials, wallet keys, or session tokens.

clickfixcryptominingxmrigsocial-engineeringsteamgamingfake-fixclipboard-hijack

Threat actors are posting fake troubleshooting guides on Steam discussion forums that use the ClickFix social engineering technique to trick gamers into executing malicious commands via the Windows Run dialog. These commands ultimately deploy XMRig cryptominers on victim machines, hijacking system resources for cryptocurrency mining.

ICSSCADAphysical-securitySSRFdeserializationremote-code-executioncritical-infrastructureCISA-advisory

Johnson Controls C-CURE 9000 and victor application server products contain three vulnerabilities, including a critical SSRF flaw (CVSS 9.6) in victor Web and a .NET deserialization-related SSRF issue enabling unauthenticated remote code execution on the application server. Successful exploitation could allow attackers with adjacent network access to compromise physical access control and video security systems, including connected client workstations used by security personnel.

ICSOTIEC-60870-5-104denial-of-serviceout-of-bounds-readCISA-advisorycritical-infrastructureprotocol-library

MZ Automation's lib60870 library, versions 2.4.0 and earlier, contains an out-of-bounds read vulnerability (CVE-2026-16002) in its IEC 60870-5-104 protocol parsing code. Remote, unauthenticated attackers can crash the parsing process, causing a denial of service in energy, water/wastewater, and chemical sector control systems that rely on this library for SCADA/ICS communications.

agent-relevantai-agentschatgptworkspace-agentsphishingprivilege-escalationopenaillm-security

Security researchers at Zenity Labs disclosed a critical vulnerability, dubbed AgentForger, in OpenAI's ChatGPT Workspace Agents that could allow an attacker to use a single phishing link to covertly create, authorize, and deploy a rogue autonomous AI agent inside a victim organization. OpenAI patched the issue as of June 8, but the flaw highlights significant risks in agent authorization and deployment workflows within enterprise AI platforms.

active-directoryadcsprivilege-escalationkerberosdcsyncdomain-controllercredential-theftagent-relevant

Security researchers H0j3n and Aniq Fakhrul disclosed Certighost, an exploit chain allowing low-privileged Active Directory users to request a certificate impersonating a Domain Controller. The resulting Kerberos credential inherits directory replication rights, enabling attackers to perform DCSync and extract the krbtgt secret, effectively achieving full domain compromise.

BlueNoroffNorth-KoreaAPTClickFixcrypto-theftsocial-engineeringtyposquattingwallet-draineragent-relevant

BlueNoroff, a North Korean state-sponsored threat actor, is operating an active phishing kit that impersonates Zoom and Microsoft Teams via typosquatted domains and ClickFix-style social engineering lures. The campaign profiles victims' cryptocurrency wallets before delivering malware, combining compromised industry contacts and trust abuse to maximize infection success.

DNS hijackingcredential theftMicrosoft 365phishinghospitalitytravel-securitycaptive-portal-abuseagent-relevant

Threat actors are compromising DNS settings on hotel and conference center Wi-Fi routers/gateways to silently redirect guests to convincing fake Microsoft 365 login pages. Victims who enter credentials on these spoofed portals have their Microsoft 365 accounts stolen, potentially exposing corporate email, files, and connected services. The campaign leverages trust in hotel network infrastructure and captive portal flows to bypass user suspicion.

data-breachlogisticspii-exposurecorporate-network-intrusion

OnTrac, a parcel delivery company, disclosed that attackers breached its corporate network and potentially accessed customer personal information. Details on the intrusion vector, threat actor, and full scope of compromised data remain limited based on available reporting.

icsotiec61850buffer-overflowrcedenial-of-servicecritical-infrastructureenergy-sector

MZ Automation's libIEC61850 library, widely used for IEC 61850 substation automation and protection communications, contains four vulnerabilities including stack- and heap-based buffer overflows and NULL pointer dereferences. An unauthenticated, network-adjacent attacker could exploit these flaws to crash critical protection and control services or achieve remote code execution, directly threatening energy, manufacturing, and transportation ICS environments.