Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 111 threats

data-breachthird-party-risksupply-chainprofessional-servicessupport-ticket-system

Ernst & Young (EY) disclosed a data breach stemming from the compromise of a third-party support ticket system used by its IT staff. The incident highlights ongoing risks associated with vendor and supply-chain access to sensitive internal support infrastructure. Details on the scope of data accessed and the threat actor responsible remain limited based on available reporting.

ICSSCADACISA-advisoryXSSweb-vulnerabilitycritical-manufacturingrockwell-automation

A stored cross-site scripting (XSS) vulnerability affects Rockwell Automation FactoryTalk DataMosaix Private Cloud versions 8.02 and earlier, allowing an authenticated high-privilege attacker to inject persistent malicious scripts via the Workflows configuration. Successful exploitation could lead to account takeover, credential theft, or redirection of other users to malicious sites when they access the affected page. No public exploitation has been reported to date.

yamcsauthentication-bypassbrute-forcemissing-rate-limitingmission-control-softwarecve-2026-44596

Yamcs, an open-source mission control framework, contains a vulnerability in its authentication endpoint that allows unlimited password-guessing attempts due to missing rate limiting and account lockout mechanisms. An unauthenticated remote attacker could exploit this to brute-force credentials for any user account. The issue is patched in versions 5.12.7 and 5.13.0.

account-takeoverresponse-manipulationauthentication-bypassHCLweb-application

CVE-2026-56453 affects HCL DFXAnalytics, allowing a remote attacker to intercept and manipulate HTTP responses to bypass authentication or authorization controls. This can result in unauthorized access to targeted user accounts without requiring credential theft.

roundupransomwarespywareinfostealerbrowser-securitysupply-chainweekly-digest

This is a weekly aggregated security news digest from The Hacker News covering multiple unrelated stories, including spyware disguised as game cheats, ransomware attacks that reach full encryption within 24 hours, and abuse of Chrome sync settings for tracking or session hijacking. The source material lacks technical depth on any single incident, functioning as a curated list of headlines rather than a detailed incident report.

ICSphysical-securityaccess-controlprivilege-escalationauthorization-bypassCISA-advisory

A privilege escalation vulnerability exists in SALTO ProAccess Space access control software versions prior to 6.13, affecting installations using the tenancy/logical partition feature. An authenticated attacker with valid operator credentials can bypass partition boundaries to access spaces outside their assigned tenancy, potentially compromising physical access control across an organization's facilities.

iotbotnetllm-generated-malwareai-assisted-malwarelinuxmirai-variant

TuxBot v3 Evolution is a newly disclosed IoT botnet framework whose codebase shows evidence of being partially generated using an LLM, including a leftover safety disclaimer the developer failed to strip out. The botnet targets vulnerable IoT devices for likely DDoS and further propagation purposes, illustrating growing use of generative AI tools in lowering the barrier to malware development.

investment-fraudlaw-enforcementtakedownsocial-engineeringfinancial-crime

Dutch Police arrested multiple suspects linked to a large-scale international investment fraud scheme that defrauded tens of thousands of victims out of over €100 million. The operation reportedly used deceptive online investment platforms and social engineering tactics to lure victims into fraudulent schemes.

icsotbuilding-automationknxaccount-lockoutphysical-securitycisa-kev

CVE-2023-4346 is a vulnerability in the KNX Protocol's Connection Authorization Option 1 mechanism that allows an attacker to exploit an overly restrictive account lockout to purge all devices lacking additional security options and lock devices via a BCU key. This affects building automation and industrial control deployments using KNX, potentially causing denial of service and loss of device control. CISA has added this CVE to its Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.

BECbusiness-email-compromiseinvestment-fraudmoney-launderinglaw-enforcement-actionfinancial-crime

Spanish National Police dismantled a cybercrime and money-laundering network responsible for approximately €140 million ($160 million) in losses through investment fraud and business email compromise (BEC) schemes. Four suspects were arrested in connection with the operation, which targeted victims through social engineering and fraudulent financial transactions.

ICSSCADADLL-hijackinglocal-privilege-escalationABBCWE-427critical-infrastructure

ABB disclosed CVE-2025-13162, an uncontrolled search path (DLL hijacking) vulnerability affecting Online Builder (ONB) as included in Control Builder A and 800xA for Advant Master. A local attacker with prior system access could place a malicious DLL in an unrestricted application directory to achieve arbitrary code execution on the affected node.

cyberattacktaxi-industryjapaninfrastructure-shutdownincident-response

Nihon Kotsu, Japan's largest taxi operator, suffered a cyberattack that forced the company to shut down parts of its IT infrastructure. Details on the attack vector, threat actor, and data impact have not been disclosed. The incident highlights ongoing targeting of transportation and logistics companies by threat actors.

CISAKEVCiscoCSRFvulnerability-managementfederal-agenciesnetwork-infrastructure

CISA added CVE-2008-4128, a Cross-Site Request Forgery vulnerability in Cisco IOS, to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. Federal Civilian Executive Branch agencies must remediate this per BOD 26-04, and CISA recommends all organizations prioritize patching this vulnerability on publicly exposed assets.

hardware-attackfault-injectioncryptocurrencyside-channelphysical-accesswallet-security

Ledger's Donjon security team demonstrated a physical fault-injection attack using a precisely timed laser pulse against the secure chip in Tangem crypto wallet cards, allowing an attacker to reset the card's password without knowledge of the original credential. Once reset, the attacker gains full control of the wallet and can transfer out any stored funds. The attack requires specialized equipment, physical possession of the card, and cannot be remediated via software patch since it exploits hardware-level fault injection.

ICSSiemensMendixcode-injectionbuild-pipelinelow-codelocal-attackCWE-94

Siemens Mendix Studio Pro contains a code injection vulnerability (CVE-2026-48192) in its build pipeline file parsing logic, allowing arbitrary code execution when a user opens a specially crafted malicious project. Exploitation requires user interaction and local access, limiting the attack surface but posing risk to developers and organizations using Mendix for low-code application development.

data-breachtelecomlaw-enforcementinvestigationnetherlands

Dutch police report strong indications that Dutch hackers were behind a February breach at telecommunications provider Odido. Details on the attack vector, data exfiltrated, and threat actor identity remain limited at this stage of the investigation.

ryukransomwarelegal-actioncybercrimelaw-enforcement

An Armenian national has pleaded guilty in U.S. federal court to participating in Ryuk ransomware attacks against American companies, facing up to 15 years in prison. This is a legal/law enforcement development rather than a new active threat campaign, though it underscores the continued prosecution of Ryuk-affiliated actors.

moveitfile-transferinjectiondata-exposuremanaged-file-transfer

A vulnerability in Progress MOVEit Transfer's Custom Reports module allows improper neutralization of special elements in data query logic, potentially enabling unauthorized data access or manipulation. This affects versions before 2025.0.7 and 2025.1.0 through 2025.1.3, and is reminiscent of prior MOVEit vulnerabilities that were exploited at scale for mass data theft.

npmsupply-chainpackage-managerinstall-scripts2faagent-relevantdependency-securitynodejs

GitHub has released npm version 12, which disables automatic execution of package install scripts by default and deprecates granular access tokens (GATs) that could be used to bypass two-factor authentication. This is a defensive supply-chain security improvement aimed at reducing the risk of malicious packages executing arbitrary code during installation, a common vector in npm supply-chain attacks.

githubreconnaissanceoauth-abuseaccount-compromisesupply-chain-reconapi-abuseagent-relevant

Datadog Security Labs identified multiple overlapping campaigns systematically enumerating corporate GitHub organizations, repositories, and user accounts via the GitHub API. Operators use dormant 'ghost' accounts and compromised OAuth tokens or personal access tokens to blend in with legitimate traffic while conducting reconnaissance, likely as a precursor to supply-chain or targeted intrusion operations.