Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 321 threats

supply-chain-attackopen-sourcenpmmalicious-packagescybercrimeextortionarrestlaw-enforcementagent-relevant

Australian Federal Police arrested two suspects believed to be members of TeamPCP, a cybercrime group linked to what is described as the longest-running spree of software supply chain attacks via malicious open-source packages. The group allegedly compromised thousands of global businesses by distributing trojanized open-source software components. While this report covers the law enforcement action, the underlying threat—malicious open-source packages—remains a systemic risk to any organization consuming public package repositories.

iot-botnetcritical-infrastructuresharepointrcec2-abusescanningexploit-chainwater-utilities

This is a weekly digest from The Hacker News summarizing over 30 distinct security stories, including a 296,000-device IoT botnet, targeting of 100+ water utility systems, and a SharePoint remote code execution exploit chain. The roundup lacks technical depth on any single incident but signals a broad wave of activity spanning critical infrastructure targeting, malicious tooling with delayed payload activation, and abuse of public infrastructure for command-and-control traffic.

papercutprint-managementzero-dayrceenterprise-software

PaperCut has disclosed active zero-day exploitation of a vulnerability affecting all versions of its PaperCut NG and PaperCut MF print management software. Attackers are leveraging the flaw in real-world attacks prior to patch availability or widespread patch adoption, echoing previous high-profile PaperCut exploitation campaigns.

cisakevknown-exploited-vulnerabilitiesownCloudlinux-kerneljfrog-artifactorypatch-managementagent-relevant

CISA has added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: an ownCloud improper authentication flaw, an unspecified Linux Kernel vulnerability, and a JFrog Artifactory path traversal issue. These vulnerabilities pose significant risk to federal and enterprise systems and are subject to expedited remediation under BOD 26-04. Organizations using these technologies should prioritize patching to prevent exploitation.

path-traversaljfrogartifactorycve-2026-66384cisa-kevsupply-chainagent-relevant

JFrog Artifactory is affected by a path traversal vulnerability that allows an authenticated user to write files outside the intended Docker cache directory under specific remote-repository configurations. CISA has added this CVE to its Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, with a remediation deadline of September 10, 2026. Organizations using Artifactory as a package/artifact registry should treat this as a priority patching item.

AitMphishing-as-a-servicesession-hijackingMicrosoft365Docusign-abusecredential-theftagent-relevant

A subscription-based adversary-in-the-middle phishing toolkit called NovaCookies is being used to abuse legitimate Docusign notification emails to lure victims into fraudulent Microsoft 365 login flows. The service acts as a reverse proxy that captures authenticated session cookies, allowing attackers to bypass MFA and hijack active Microsoft 365 sessions for $320/month.

IranIRGCnation-stateespionagebackdoorSSH-tunnelingNimbus ManticoreAPT

Nimbus Manticore, an Iranian state-sponsored APT group affiliated with the IRGC, has expanded its toolset with a new TWOSTROKE-like backdoor and an SSH tunneling utility, according to Group-IB research. The group is characterized as one of the most active Iranian threat actors in 2026, conducting cyber espionage operations using newly discovered infrastructure and malware.

chinastate-sponsoredcritical-infrastructurenetwork-reconnaissancerouter-exploitationbotnetfbi-disruptionQTFY

The U.S. DoJ and FBI disrupted infrastructure operated by China-linked threat actor QTFY, tied to Nanjing Xinjiuwei Network Technology Company, which used two custom hacking platforms—QScan and QTRouter—to target U.S. critical infrastructure and sensitive networks. The takedown highlights ongoing state-sponsored efforts to compromise network edge devices for espionage and data theft purposes.

rowhammergpu-securityprivilege-escalationdenial-of-servicehardware-attacknvidiaagent-relevant

Researchers disclosed GPUThor, a new Rowhammer-class attack that defeats NVIDIA's ECC memory protections, allowing attackers with local access to induce bit flips leading to denial-of-service or root-level privilege escalation. This is particularly concerning for shared GPU infrastructure such as cloud AI training clusters and multi-tenant inference environments.

ICSIoTmissing-authorizationCWE-862payment-systemsunauthenticated-accessinformation-disclosure

PayRange API, used to manage internet-connected vending and payment devices, contains a missing authorization vulnerability that exposes verbose device management data to unauthenticated or authenticated attackers. Exploitation could allow information disclosure, denial of service, or manipulation of device-displayed content across the PayRange network. PayRange has not engaged with CISA to remediate the issue, leaving affected deployments exposed.

kevcisavulnerability-managementpatch-prioritylegacy-softwarenetwork-applianceagent-relevant

CISA added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation, spanning Red Hat Libuser/ABRT, Microsoft SQL Server, Ajax.NET Professional, Linux Kernel, and Citrix NetScaler ADC/Gateway. BOD 26-04 mandates FCEB agencies prioritize rapid remediation of these on internet-facing assets, particularly those allowing full post-exploitation control. All organizations, including those hosting AI infrastructure, are encouraged to remediate promptly given confirmed in-the-wild exploitation.

citrixnetscalerdenial-of-servicecisa-kevedge-devicenetwork-applianceactive-exploitation

CVE-2026-8452 is an improper memory buffer restriction vulnerability in Citrix NetScaler ADC and NetScaler Gateway that can result in denial of service. CISA has added this CVE to its Known Exploited Vulnerabilities catalog with a short remediation window, indicating active exploitation in the wild. Organizations using NetScaler appliances as gateways or load balancers should prioritize patching due to the aggressive due date.

linux-kernelprivilege-escalationlocal-exploitcisa-kevwatch_queueagent-relevant

CVE-2022-0995 is an out-of-bounds write vulnerability in the Linux Kernel's watch_queue event notification subsystem that allows a local attacker to escalate privileges or crash the system. It is listed in CISA's Known Exploited Vulnerabilities catalog, indicating confirmed active exploitation in the wild. Organizations running affected Linux kernel versions must remediate promptly per CISA's mandated due date.

privilege-escalationsymlink-attacklinuxred-hatCISA-KEVeol-software

CVE-2015-5287 is a local privilege escalation vulnerability in Red Hat's Automatic Bug Reporting Tool (ABRT), exploitable via a symlink attack on a predictably named file. The flaw allows local users with certain permissions to escalate privileges on affected Linux systems. This vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation in the wild despite its age.

CISAKEVGiteacode-injectionactive-exploitationagent-relevantself-hosted-gitRCE

CISA added CVE-2026-60004, a code injection vulnerability in Gitea, to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation. Federal agencies are required under BOD 26-04 to remediate this vulnerability on a prioritized basis, and CISA urges all organizations to do the same given the risk of total asset compromise.

ICSIoTsmart-homecredential-exposureCWE-522vulnerability-disclosure

Rently Smart Home versions 20.1.0 and earlier contain a vulnerability that insufficiently protects credentials, allowing an attacker to retrieve PINs, including the Master PIN, and override standard user permissions. Rently has released a patch as of late June 2026, and no known public exploitation has been reported.

wordpressauthentication-bypasssamlplugin-vulnerabilityprivilege-escalationweb-security

Attackers are actively exploiting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, allowing forgery of SAML responses to gain unauthorized administrator access. Sites running vulnerable versions of the plugin are at immediate risk of full site takeover.

NAT bypassrouter vulnerabilityunpatchedresidential gatewayport forwardingbroadband ISPIoT exposurenetwork security

An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers allows remote, unauthenticated attackers to create arbitrary port-forwarding rules, bypassing NAT protections and exposing internal network devices directly to the internet. The flaw affects devices deployed by multiple U.S. broadband providers, putting a large base of residential and small-office networks at risk of direct exposure of internal systems such as NAS devices, cameras, and smart home hubs.

oracleweblogichttp-serverknown-exploited-vulnerabilityCISAaccess-controlagent-relevant

CISA has added CVE-2026-21962, an improper access control vulnerability affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities (KEV) catalog based on confirmed active exploitation. Federal civilian agencies are required under BOD 26-04 to remediate this vulnerability on a priority basis, and CISA urges all organizations to do the same given the active exploitation in the wild.

CISAKEVTrueConfself-hosted-communicationsfederal-mandateactive-exploitationRCE

CISA has added two actively exploited vulnerabilities in TrueConf Server, a self-hosted video conferencing and communications platform, to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch immediately. The flaws are being leveraged in the wild, indicating attackers have working exploits and are actively targeting exposed instances.