Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 335 threats
Nimbus Manticore, an Iranian state-sponsored APT group affiliated with the IRGC, has expanded its toolset with a new TWOSTROKE-like backdoor and an SSH tunneling utility, according to Group-IB research. The group is characterized as one of the most active Iranian threat actors in 2026, conducting cyber espionage operations using newly discovered infrastructure and malware.
The U.S. DoJ and FBI disrupted infrastructure operated by China-linked threat actor QTFY, tied to Nanjing Xinjiuwei Network Technology Company, which used two custom hacking platforms—QScan and QTRouter—to target U.S. critical infrastructure and sensitive networks. The takedown highlights ongoing state-sponsored efforts to compromise network edge devices for espionage and data theft purposes.
Researchers disclosed GPUThor, a new Rowhammer-class attack that defeats NVIDIA's ECC memory protections, allowing attackers with local access to induce bit flips leading to denial-of-service or root-level privilege escalation. This is particularly concerning for shared GPU infrastructure such as cloud AI training clusters and multi-tenant inference environments.
PayRange API, used to manage internet-connected vending and payment devices, contains a missing authorization vulnerability that exposes verbose device management data to unauthenticated or authenticated attackers. Exploitation could allow information disclosure, denial of service, or manipulation of device-displayed content across the PayRange network. PayRange has not engaged with CISA to remediate the issue, leaving affected deployments exposed.
CISA added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation, spanning Red Hat Libuser/ABRT, Microsoft SQL Server, Ajax.NET Professional, Linux Kernel, and Citrix NetScaler ADC/Gateway. BOD 26-04 mandates FCEB agencies prioritize rapid remediation of these on internet-facing assets, particularly those allowing full post-exploitation control. All organizations, including those hosting AI infrastructure, are encouraged to remediate promptly given confirmed in-the-wild exploitation.
CVE-2026-8452 is an improper memory buffer restriction vulnerability in Citrix NetScaler ADC and NetScaler Gateway that can result in denial of service. CISA has added this CVE to its Known Exploited Vulnerabilities catalog with a short remediation window, indicating active exploitation in the wild. Organizations using NetScaler appliances as gateways or load balancers should prioritize patching due to the aggressive due date.
CVE-2022-0995 is an out-of-bounds write vulnerability in the Linux Kernel's watch_queue event notification subsystem that allows a local attacker to escalate privileges or crash the system. It is listed in CISA's Known Exploited Vulnerabilities catalog, indicating confirmed active exploitation in the wild. Organizations running affected Linux kernel versions must remediate promptly per CISA's mandated due date.
CVE-2015-5287 is a local privilege escalation vulnerability in Red Hat's Automatic Bug Reporting Tool (ABRT), exploitable via a symlink attack on a predictably named file. The flaw allows local users with certain permissions to escalate privileges on affected Linux systems. This vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation in the wild despite its age.
CISA added CVE-2026-60004, a code injection vulnerability in Gitea, to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation. Federal agencies are required under BOD 26-04 to remediate this vulnerability on a prioritized basis, and CISA urges all organizations to do the same given the risk of total asset compromise.
Rently Smart Home versions 20.1.0 and earlier contain a vulnerability that insufficiently protects credentials, allowing an attacker to retrieve PINs, including the Master PIN, and override standard user permissions. Rently has released a patch as of late June 2026, and no known public exploitation has been reported.
Attackers are actively exploiting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, allowing forgery of SAML responses to gain unauthorized administrator access. Sites running vulnerable versions of the plugin are at immediate risk of full site takeover.
An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers allows remote, unauthenticated attackers to create arbitrary port-forwarding rules, bypassing NAT protections and exposing internal network devices directly to the internet. The flaw affects devices deployed by multiple U.S. broadband providers, putting a large base of residential and small-office networks at risk of direct exposure of internal systems such as NAS devices, cameras, and smart home hubs.
CISA has added CVE-2026-21962, an improper access control vulnerability affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities (KEV) catalog based on confirmed active exploitation. Federal civilian agencies are required under BOD 26-04 to remediate this vulnerability on a priority basis, and CISA urges all organizations to do the same given the active exploitation in the wild.
CISA has added two actively exploited vulnerabilities in TrueConf Server, a self-hosted video conferencing and communications platform, to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch immediately. The flaws are being leveraged in the wild, indicating attackers have working exploits and are actively targeting exposed instances.
ToxicPanda, an Android banking trojan, has expanded its capabilities to target 349 applications and now supports 167 remote commands. The malware abuses Android VPN permissions to block access to Google Play, likely to prevent security updates or app removal, while enabling device takeover and financial fraud.
Check Point Research disclosed a technique abusing Microsoft Defender's own legitimately signed boot-time remediation driver (BTR.sys) to perform arbitrary kernel-level file and registry operations on Windows systems, including deletion of security software at boot. Because BTR.sys is Microsoft-signed and no external or malicious driver is introduced, the technique bypasses driver-signature enforcement and many endpoint protections, affecting Windows 7 through Windows 11 25H2.
Researchers identified 14 trojanized npm packages disguised as calendar and streak-tracking utilities that covertly deploy an AI-powered Linux backdoor called RedC2 4.0. The malware extracts and executes a bundled binary as a detached background process, giving attackers persistent, AI-assisted command-and-control capability on infected hosts.
Over 9,300 AWS access keys publicly exposed between August 2022 and August 2026 remain active and valid, granting attackers full control over corporate AWS accounts. These leaked credentials likely originate from hardcoded secrets in public repositories, misconfigured applications, or logging errors, posing an ongoing risk of account takeover, data theft, and resource abuse.
CISA has added CVE-2026-73570, an OS command injection vulnerability in Zimbra Collaboration Suite (ZCS), to its Known Exploited Vulnerabilities Catalog based on confirmed active exploitation. Federal Civilian Executive Branch agencies are required under BOD 26-04 to remediate this vulnerability on an expedited timeline, and CISA urges all organizations to prioritize patching.
This roundup covers multiple distinct security issues, including a remote code execution flaw in the Gogs self-hosted Git service, a workflow-to-RCE chain in the n8n automation platform, abuse of signed drivers for defense evasion, and use of AI models (GLM-5.3) to assist in exploit research. Collectively these lower the barrier for attackers by chaining trusted functionality and legitimate software behaviors into compromise paths.