Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 335 threats

phishingoauth-abusecredential-theftsocial-engineeringrussiastate-sponsoredaccount-takeoverwhatsappgoogle-oauth

Three suspected Russian cyber espionage clusters (UNC6293, UNC7005, UNC5976) are abusing legitimate Google OAuth flows and WhatsApp device-linking features to hijack accounts of individuals in academia, aerospace/defense, government, and think tanks across Europe and the U.S. These campaigns rely on persistent, adaptive social engineering rather than exploiting software vulnerabilities, making them difficult to detect with traditional malware defenses.

supply-chainrustcrates.iobuild-time-malwaredependency-confusiontyposquattingagent-relevant

A compromised maintainer account was used to publish malicious versions of three popular Rust crates (arrayref, internment, append-only-vec), collectively downloaded over 245 million times. The malicious releases introduced a typosquatted dependency whose build script downloaded and executed a remote payload at compile time, enabling arbitrary code execution on any system that built the affected packages.

supply-chainrustcrates.ioinfostealermalicious-packagebuild-time-executionagent-relevant

Attackers compromised the maintainer account of the widely-used Rust crate 'arrayref' and published a malicious version that executes infostealer malware at compile time on developer systems. Any developer or CI/CD pipeline pulling the poisoned version would trigger malware execution during the build process, risking credential and secret theft.

CISAKEVTrueConfauthentication-bypasscode-injectionactive-exploitationfederal-mandatevideo-conferencing

CISA has added two actively exploited vulnerabilities affecting TrueConf Server to its Known Exploited Vulnerabilities catalog: a missing authentication for critical function flaw (CVE-2026-72529) and a code injection vulnerability (CVE-2026-72530). These vulnerabilities pose significant risk as they can be chained to bypass authentication and execute arbitrary code, with BOD 26-04 requiring FCEB agencies to remediate rapidly.

espionageAPTRATCentral Asiagovernmentnation-state

SilkParasite is a newly identified cyber espionage operation targeting government bodies in Central Asia, first observed in late 2025. The campaign leverages seven distinct RAT families, five of which are previously undocumented, indicating a well-resourced threat actor with custom malware development capabilities.

spectreside-channelcloudflare-workersserverlessjwt-theftspeculative-executionagent-relevant

Researchers demonstrated a remote Spectre-class microarchitectural side-channel attack against Cloudflare Workers that allows a malicious Worker to leak secret data, including JSON Web Tokens, from a co-located victim Worker in production at up to 12 bits per second. This represents a 360x throughput improvement over a 2021 proof-of-concept and confirms that multi-tenant serverless/edge compute platforms remain vulnerable to cross-tenant speculative execution leakage despite existing mitigations.

data-breachcloud-providerjapancustomer-data-exposurethird-party-riskagent-relevant

Sakura Internet, a major Japanese cloud and data center provider, disclosed unauthorized access to its sales management system, exposing contract and membership data for up to 1.36 million accounts. The breach affects a company that provides hosting and cloud infrastructure to numerous business customers, raising downstream exposure concerns.

CISAKEVSSRFMLflowMLOpsagent-relevantvulnerability-managementBOD-26-04

CISA has added CVE-2026-64849, a Server-Side Request Forgery (SSRF) vulnerability in MLflow, to its Known Exploited Vulnerabilities Catalog based on confirmed active exploitation. Federal agencies are required under BOD 26-04 to remediate this vulnerability on a prioritized basis, and CISA urges all organizations to do the same given active in-the-wild attacks.

MLflowSSRFcloud-credential-theftMLOpsagent-relevantFUXASCADAactive-exploitation

Threat actors are actively scanning for and exploiting a critical Server-Side Request Forgery (SSRF) vulnerability in MLflow, an open-source AI/ML lifecycle platform, to steal cloud credentials and secrets from exposed metadata services. A separate but related campaign is targeting FUXA, an open-source SCADA/HMI platform used in industrial automation. Both flaws are being weaponized in the wild according to watchTowr and VulnCheck.

microsoft-copilotLLM-vulnerabilityone-click-exploitdata-exfiltrationprompt-injectionagent-relevantai-security

Varonis Threat Labs disclosed three vulnerabilities, collectively named CoSnitch, in Microsoft Copilot Personal that could allow an attacker to exfiltrate data from a victim's connected apps and Copilot session with a single click on a crafted link. The flaws exploit an undocumented URL parameter surfaced by the assistant itself, enabling silent data leakage without further user interaction.

clopweb-shelldata-theftplmwindchillflexplmextortion

The Clop ransomware gang has deployed a custom Java-based web shell specifically engineered to target PTC Windchill and FlexPLM product lifecycle management servers. The tool is purpose-built to decrypt stored credentials, enumerate file repositories, and exfiltrate sensitive design and engineering data for extortion purposes. This represents an evolution in Clop's tactics toward targeted, application-specific tooling rather than generic ransomware payloads.

CISAMalcolmnetwork-traffic-analysisRCEpath-traversalauthorization-bypassdenial-of-servicefile-uploadRBAC-bypasszip-bombagent-relevant

Multiple vulnerabilities have been disclosed in CISA's Malcolm network traffic analysis tool suite, including an unauthenticated-adjacent arbitrary PHP code execution flaw (CVE-2026-55676, CVSS 8.8), two nginx/Lua RBAC bypasses via URI normalization mismatches (CVE-2026-63177, CVE-2026-19670), a path traversal in archive extraction (CVE-2026-63134), and two resource-exhaustion/DoS flaws involving malicious archives and decompression bombs (CVE-2026-63133, CVE-2026-19671). Versions prior to 26.06.1/26.07.0/26.08.0 depending on the specific CVE are affected, with vendor patches available and no known public exploitation reported at this time.

ICSindustrial-control-systemssiemensbuffer-overflowlocal-code-executionengineering-softwareCWE-121

Siemens Simcenter Femap and Simcenter Nastran versions prior to V2606 contain a stack-based buffer overflow vulnerability triggered when an application binary parses a malicious string as a file argument. Successful exploitation could allow an attacker to achieve remote code execution in the context of the current process, though exploitation requires user interaction (tricking a user into running the binary with a crafted argument).

github-actionsworkflow-injectionci-cdsupply-chaincredential-theftsnowflakeagent-relevant

Researchers at Wiz disclosed a GitHub Actions workflow injection vulnerability in Snowflake's public snowflake-connector-net repository, where a maliciously crafted GitHub issue could trigger command injection in a workflow that contained internal Jira credentials. Successful exploitation could allow an attacker to exfiltrate secrets and potentially compromise the CI/CD pipeline of a widely used Snowflake connector library.

credential-theftcloud-securitydata-breachazureidentity-compromiseagent-relevant

A threat actor claims to be selling 3.6 million employee records allegedly exfiltrated from Microsoft Azure environments belonging to multiple Fortune 500 companies. The intrusion reportedly stemmed from compromised credentials rather than a platform vulnerability, highlighting ongoing risks around identity and access management in cloud tenants. The claim remains unverified but poses significant exposure risk if confirmed.

ICSCISA-advisorySiemensfile-parsingmemory-corruptionout-of-bounds-readout-of-bounds-writeuse-after-freecritical-manufacturinglocal-code-execution

Siemens Solid Edge SE2025 and SE2026 contain seven high-severity memory corruption vulnerabilities (CVSS 7.8) triggered when parsing specially crafted PAR, PSM, or DFT files, which could allow an attacker to crash the application or achieve arbitrary code execution in the context of the current process. Exploitation requires a user to open a malicious file, making this a local-vector, user-interaction-required threat rather than a remotely exploitable one. Siemens has released patched versions (SE2025 V225.0.15+ and SE2026 V226.0.7+) and organizations should update promptly.

microsoft-defenderpatch-bypassprivilege-escalationwindowsSYSTEM-accesszero-dayproof-of-conceptagent-relevant

A researcher known as Chaotic Eclipse released a public proof-of-concept called ShieldBreak that bypasses Microsoft's patch for CVE-2026-50656 (RoguePlanet), a Windows Defender vulnerability. The PoC reportedly grants SYSTEM-level access, meaning organizations that applied the original patch may still be exposed to full local privilege escalation.

ICSOTenergy-sectorhard-coded-credentialsmissing-authenticationrecoverable-passwordsVNC-exposureCISA-advisory

ANDRITZ HIPASE-250 and 250 SCALA industrial control system products (versions <=7.20) contain four vulnerabilities including recoverable password storage, missing authentication on data/config endpoints, an unauthenticated logging manipulation endpoint, and a hard-coded VNC credential used across engineering workstation deployments. Successful exploitation could allow an attacker to read sensitive process data, access engineering workstations, suppress audit logs, or recover stored credentials. These are primarily energy-sector ICS/OT vulnerabilities with no reported public exploitation to date.

ICSmedical-devicehardcoded-credentialsbluetoothCWE-798healthcareIoT

Flow Neuroscience FL-100 (and rebranded Halo Neuroscience FL-100) tDCS devices contain an undocumented hard-coded credential shared across all units, allowing any attacker within Bluetooth range to bypass authentication. Exploitation could let an attacker arbitrarily manipulate brain stimulation parameters and override built-in safety limits, posing direct physical harm risk to patients.

macOSauthentication-bypasscryptominingmoneroexploit-code-publicagent-relevant

Hackers are actively exploiting a macOS Screen Sharing authentication bypass vulnerability following the release of public exploit code, according to the Netherlands' NCSC. Attackers use the flaw to gain unauthorized remote access to macOS systems and deploy Monero (XMR) cryptocurrency miners. Organizations running exposed macOS Screen Sharing services are at immediate risk of unauthorized access and resource hijacking.