Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 907 threats
ImageMagick versions prior to 7.1.2-19 contain a heap buffer over-read in the magnify operation, triggered by an unrecognized magnify:method value. Exploitation can lead to information disclosure from adjacent heap memory or crash the process, resulting in denial of service.
Cisco IOS 12.4 contains cross-site request forgery vulnerabilities in its HTTP-based management interface, allowing remote attackers to trick authenticated administrators into executing arbitrary privileged commands. This flaw is included in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. Successful exploitation could lead to full device reconfiguration or compromise of network infrastructure.
The China-linked threat actor Silver Fox has been attributed a new Rust-based remote access trojan called MODBEACON, which uses gRPC streaming to encrypt and obfuscate its command-and-control traffic. Despite appearing as an opportunistic, low-sophistication campaign relying on SEO poisoning and trojanized installers for distribution, researchers assess the group demonstrates notable organizational and technical maturity.
Security researchers disclosed a chained exploit involving three now-patched vulnerabilities in the OpenClaw personal AI assistant that could be triggered via WhatsApp messages to achieve credential theft, privilege escalation, and arbitrary code execution on the host system. The attack chain leverages the assistant's integration with messaging platforms as an entry point, ultimately compromising the underlying host running the AI agent.
Ledger's Donjon security team demonstrated a physical fault-injection attack using a precisely timed laser pulse against the secure chip in Tangem crypto wallet cards, allowing an attacker to reset the card's password without knowledge of the original credential. Once reset, the attacker gains full control of the wallet and can transfer out any stored funds. The attack requires specialized equipment, physical possession of the card, and cannot be remediated via software patch since it exploits hardware-level fault injection.
A new variant of the RedHook Android malware exploits the Android Wireless Debugging (Wireless ADB) feature to obtain shell-level access on infected devices without requiring a wired connection to a computer. This removes a key barrier that previously limited ADB-based attacks, making device compromise more autonomous and scalable. The technique poses a significant risk to Android users and enterprises relying on mobile devices for authentication and access.
This article is a routine product availability notice stating Anthropic has extended free access to its Claude Fable 5 model for paid subscribers until July 19. It contains no indicators of a security vulnerability, breach, or malicious activity and does not constitute a cyber threat.
This item is a routine product/operations announcement from OpenAI regarding temporary relaxation of usage limits on GPT-5.6 Sol due to surging demand. It does not describe a vulnerability, exploit, or malicious activity and carries no direct security threat.
Crawl4AI, a popular web-crawling library used to feed content into LLM pipelines and RAG systems, contains a critical arbitrary file write vulnerability in its Docker API server's /screenshot and /pdf endpoints. Unauthenticated or low-privilege attackers can supply crafted output_path values to write files anywhere the service account can access, potentially overwriting critical server files and causing denial of service or further compromise.
Zimbra has issued an advisory for a critical stored cross-site scripting vulnerability in its Classic Web Client that can be triggered by specially crafted emails, allowing attackers to execute malicious scripts within a victim's active session. No CVE identifier has been assigned yet, but customers are urged to apply updates immediately.
Suspected China- and India-aligned APT groups conducted a sustained, multi-year cyber espionage campaign (February 2024 to April 2026) against Pakistani law enforcement organizations, including the Balochistan Police. Attackers compromised servers hosting public-facing web applications used to manage sensitive police and citizen data, including criminal records.
The popular jscrambler npm package was compromised, with a malicious 8.14.0 release published on July 11, 2026 that executes a Rust-based infostealer via a preinstall hook during npm install. The attack drops platform-specific native binaries for Windows, macOS, and Linux, meaning any developer or CI/CD system installing this version is automatically compromised. Socket detected the malicious release within six minutes of publication, but organizations that auto-updated or pulled the package before detection remain at risk.
Progress Software has issued an urgent advisory urging ShareFile customers running on-premises Storage Zone Controllers to immediately shut down their servers due to a credible, unspecified external security threat. No CVE or technical details have been publicly disclosed yet, but the severity of the recommendation (full shutdown) suggests a serious, potentially actively exploited vulnerability. Organizations using ShareFile Storage Zone Controllers should treat this as an active incident and act on vendor guidance without delay.
The Australian Cyber Security Centre has warned of an ongoing global campaign in which threat actors are exploiting vulnerabilities in content management systems (CMS) and their plugins to gain unauthorized access to web servers. The campaign appears opportunistic, scanning for and exploiting unpatched or misconfigured CMS installations at scale. Organizations running public-facing CMS platforms are urged to patch immediately and audit for signs of compromise.
Siemens Mendix Studio Pro contains a code injection vulnerability (CVE-2026-48192) in its build pipeline file parsing logic, allowing arbitrary code execution when a user opens a specially crafted malicious project. Exploitation requires user interaction and local access, limiting the attack surface but posing risk to developers and organizations using Mendix for low-code application development.
Hydro-Québec's Le Circuit Electrique EV charging station backend contains three vulnerabilities—an unauthenticated websocket endpoint, lack of authentication attempt throttling, and insufficient session/connection controls—that could allow privilege escalation or denial-of-service attacks. The most severe flaw (CVSS 9.8) permits unauthenticated connections to the charging station's OCPP websocket, enabling attackers to potentially impersonate charging stations or escalate privileges. Hydro-Québec has mitigated most affected stations by disabling OCPP or adding authentication.
PraisonAI, an AI agent framework, contains a critical vulnerability in its AICoder component that allows attackers to abuse LLM tool-calling functionality to write files anywhere on the filesystem and execute arbitrary commands with root privileges. Exploitation can occur via malicious prompt injection through the chat interface, requiring no prior authentication or system access in many deployments. Given the CVSS score of 9.9, this represents a full system compromise vector for any organization running affected PraisonAI versions.
PraisonAI versions prior to 4.6.78 contain an unvalidated dimension parameter in the PGVector and Cassandra knowledge-store create_collection() functions, allowing attackers to inject arbitrary SQL/CQL into the generated DDL statement. Any caller able to influence collection creation—including downstream API consumers or agent orchestration logic—can execute destructive or data-exfiltrating database commands, resulting in a critical 9.8 CVSS-rated vulnerability.
The miniOrange Social Login and Register plugin for WordPress (versions up to 7.7.0) contains a critical authentication bypass allowing unauthenticated attackers to take over any account, including administrators. The flaw stems from unvalidated email input during OAuth profile completion combined with a weak, offline-crackable OTP scheme, enabling full site compromise. Given the 9.8 CVSS score and low attack complexity, mass exploitation against internet-facing WordPress sites is likely once a working exploit circulates.
A critical path traversal vulnerability in JetBrains IntelliJ IDEA allows remote code execution through manipulation of project workspace ID handling. With a CVSS score of 9.6, this flaw could allow attackers to execute arbitrary code on developer workstations, potentially via malicious project files or shared workspace configurations.