Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 874 threats
Researchers have catalogued 39 distinct methods that undermine passkey-based authentication without breaking FIDO2 cryptography itself, instead targeting weak points like enrollment, recovery flows, synced credential stores, and user-facing prompts. These attacks exploit implementation and process gaps across platforms rather than cryptographic flaws, meaning organizations relying on passkeys as a phishing-proof control may still be exposed to account takeover.
A large-scale campaign has compromised over 5,400 small-business websites to serve fake CAPTCHA/verification pages that trick users into executing malicious commands (ClickFix technique). The payload delivery infrastructure is hosted in smart contracts on the BNB Smart Chain, making takedown difficult since blockchain data cannot be removed by hosting providers or registrars.
Rockwell Automation ArmorStart LT firmware versions ≤v2.001 contain two vulnerabilities: a stored cross-site scripting flaw and a denial-of-service issue triggered by a crafted HTTP PUT request to the embedded web server. Exploitation could allow an attacker to inject malicious scripts executed by other users or crash the device's web server, disrupting availability. No public exploitation has been reported, and Rockwell has released firmware v2.002 to remediate both issues.
CISA and the G7 Cyber Security Working Group have jointly issued a call to action urging governments and organizations to begin transitioning to post-quantum cryptography (PQC) in order to protect sensitive data, authentication systems, and critical infrastructure from future quantum computing threats. This is a strategic/policy advisory rather than an active exploit, emphasizing awareness, national strategy development, R&D, public-private partnerships, and procurement integration.
IXON VPN Client versions before 1.4.7 contain a critical CRLF injection vulnerability that allows an unauthenticated local attacker to inject configuration directives consumed by a privileged subprocess, resulting in remote code execution as root or SYSTEM. The flaw persists silently across restarts with no visible behavioral change, making detection difficult. IXON has released a patched client and blocks connections from vulnerable versions at the cloud/API level as a compensating control.
zerox 1.1.20, a document-to-markdown/OCR conversion library commonly integrated into AI ingestion and RAG pipelines, contains a critical OS command injection vulnerability in its file download and temporary file handling logic. An attacker can craft a malicious document URL whose derived file extension contains shell command substitution syntax, resulting in arbitrary command execution on the host before any document processing occurs.
xiaobei versions through 5.5.2 contain a critical vulnerability where webhook endpoints lack authentication or signature validation, allowing unauthenticated attackers to inject arbitrary messages directly into the agent pipeline. Combined with unvalidated media URL fetching, this enables server-side request forgery (SSRF) attacks against internal services, potentially exposing internal network infrastructure to external attackers.
excel-mcp-server version 0.1.8, a Model Context Protocol (MCP) server used to give AI agents Excel file manipulation capabilities, fails to restrict file access to a designated directory when running in stdio mode without EXCEL_FILES_PATH configured. This allows an attacker-controlled or malicious tool call to read or write arbitrary files accessible to the server process, enabling data exfiltration, config tampering, or code/config injection on the host.
The Divi Ajax Filter plugin for WordPress (versions up to 5.1.2) contains an unauthenticated Local File Inclusion vulnerability via the 'custom_loop_template' parameter, allowing attackers to include and execute arbitrary PHP files on the server. With a CVSS score of 9.8, this flaw can lead to full remote code execution, data exposure, and access control bypass on affected WordPress installations.
MOOS-IvP, an autonomous marine vehicle behavior and control framework, contains a critical buffer overflow vulnerability in its IvP function parsing logic (CVE-2026-85438). Attackers who can supply crafted BHV_IPF payloads can trigger out-of-bounds writes leading to memory corruption and potential remote code execution. This affects autonomous vehicle control software rather than typical enterprise AI agent stacks, though similar parsing patterns are common in agent tool pipelines.
A previously undocumented Linux backdoor named 'Ted' has been discovered compiled directly into trojanized HAProxy load balancer builds at two South Korean organizations. The implant intercepts and manipulates web traffic, serving altered content to selected visitors, indicating a targeted, capability-focused intrusion rather than opportunistic malware distribution.
A 12-year-old flaw in PostgreSQL's logical decoding feature allows a database role with REPLICATION privileges to escalate to arbitrary code execution as the OS user running the database server. PostgreSQL has released patched versions across all supported major releases to address CVE-2026-6471.
Microsoft identified a high-volume phishing campaign that embeds invisible Unicode tag characters within financial lure words (e.g., 'funding') to evade traditional email security filters. The technique splits keywords at the character level so pattern-matching and keyword-based detection engines fail to flag the malicious content, while the text still renders normally to human recipients.
Microsoft has acknowledged a known technical issue causing delays or outright failures when some users attempt to open the Microsoft Teams desktop client on Windows systems. This is a service reliability/availability problem rather than a security incident, with Microsoft actively working on a resolution.
A critical authentication bypass vulnerability in Citrix NetScaler (CVE-2026-19490) is being actively exploited in the wild, as reported by vulnerability intelligence firm Previdian. The flaw allows attackers to bypass authentication controls on NetScaler ADC/Gateway appliances, potentially granting unauthorized access to internal networks and sensitive resources.
IDScan, an identity verification company, allegedly suffered a data breach in which threat actors claim to have obtained and offered for sale over 153 million driver's license records. The company now faces multiple lawsuits related to the incident. Details on the initial attack vector remain undisclosed publicly.
A critical stack-based buffer overflow vulnerability affects Pyramid Solutions NetStaX EtherNet/IP Stack products prior to v5.6.1, used across industrial control system (ICS) devices. Exploitation via oversized Class 3 explicit-message requests could cause memory corruption, device crashes, or remote code execution without any CIP error notification, posing significant risk to critical manufacturing, energy, water, and chemical sectors.
Tycon Systems TPDIN-Monitor-WEB3 firmware versions 2.2.9 and earlier contain three vulnerabilities—hard-coded credentials, CSRF, and missing authorization—that could allow an attacker to intercept sensitive data, perform state-changing operations, or extract system credentials, configurations, and flash contents. These devices are deployed worldwide in Critical Manufacturing and Energy sectors, and successful exploitation could enable man-in-the-middle attacks, factory resets, credential wipes, or full information disclosure. Tycon Systems has released firmware v2.4.2 to remediate all three issues.
CISA has added CVE-2026-85046, a type confusion vulnerability in Google Chromium's V8 JavaScript engine, to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. Federal agencies are required under BOD 26-04 to remediate this vulnerability on a prioritized timeline, and all organizations are encouraged to patch given confirmed in-the-wild exploitation.
A critical authorization flaw in MOOS essential-moos pShare (through 10.0.1) allows any publisher on the bus to send crafted PSHARE_CMD messages that reconfigure network routes and listeners at runtime. This enables attackers to redirect or duplicate sensitive inter-process communication traffic to attacker-controlled destinations without authentication, posing severe risks to robotics and autonomous system deployments that rely on MOOS for message passing.