Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 120 threats
Nihon Kotsu, Japan's largest taxi operator, suffered a cyberattack that forced the company to shut down parts of its IT infrastructure. Details on the attack vector, threat actor, and data impact have not been disclosed. The incident highlights ongoing targeting of transportation and logistics companies by threat actors.
CISA added CVE-2008-4128, a Cross-Site Request Forgery vulnerability in Cisco IOS, to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. Federal Civilian Executive Branch agencies must remediate this per BOD 26-04, and CISA recommends all organizations prioritize patching this vulnerability on publicly exposed assets.
Ledger's Donjon security team demonstrated a physical fault-injection attack using a precisely timed laser pulse against the secure chip in Tangem crypto wallet cards, allowing an attacker to reset the card's password without knowledge of the original credential. Once reset, the attacker gains full control of the wallet and can transfer out any stored funds. The attack requires specialized equipment, physical possession of the card, and cannot be remediated via software patch since it exploits hardware-level fault injection.
Siemens Mendix Studio Pro contains a code injection vulnerability (CVE-2026-48192) in its build pipeline file parsing logic, allowing arbitrary code execution when a user opens a specially crafted malicious project. Exploitation requires user interaction and local access, limiting the attack surface but posing risk to developers and organizations using Mendix for low-code application development.
Dutch police report strong indications that Dutch hackers were behind a February breach at telecommunications provider Odido. Details on the attack vector, data exfiltrated, and threat actor identity remain limited at this stage of the investigation.
An Armenian national has pleaded guilty in U.S. federal court to participating in Ryuk ransomware attacks against American companies, facing up to 15 years in prison. This is a legal/law enforcement development rather than a new active threat campaign, though it underscores the continued prosecution of Ryuk-affiliated actors.
A vulnerability in Progress MOVEit Transfer's Custom Reports module allows improper neutralization of special elements in data query logic, potentially enabling unauthorized data access or manipulation. This affects versions before 2025.0.7 and 2025.1.0 through 2025.1.3, and is reminiscent of prior MOVEit vulnerabilities that were exploited at scale for mass data theft.
GitHub has released npm version 12, which disables automatic execution of package install scripts by default and deprecates granular access tokens (GATs) that could be used to bypass two-factor authentication. This is a defensive supply-chain security improvement aimed at reducing the risk of malicious packages executing arbitrary code during installation, a common vector in npm supply-chain attacks.
Datadog Security Labs identified multiple overlapping campaigns systematically enumerating corporate GitHub organizations, repositories, and user accounts via the GitHub API. Operators use dormant 'ghost' accounts and compromised OAuth tokens or personal access tokens to blend in with legitimate traffic while conducting reconnaissance, likely as a precursor to supply-chain or targeted intrusion operations.
A contributor to the OpenMandriva Linux distribution reportedly attempted to sabotage the project following an internal dispute among maintainers. The distribution's team detected and responded to the incident, though specifics on the exact method and scope of the sabotage attempt remain limited in the initial reporting.
Schneider Electric's Easergy MiCOM Px40 Series protection relays contain hard-coded credentials (CWE-798) exposed via the SNMP protocol, allowing an unauthenticated remote attacker to access basic device identification information. The vulnerability affects a wide range of firmware versions across nearly all Px40 relay models used in medium, high, and extra high voltage protection applications worldwide.
Schneider Electric PowerChute Serial Shutdown versions 1.4 and earlier contain seven distinct vulnerabilities spanning path traversal, CRLF injection, weak authentication throttling, uncontrolled resource consumption, and sensitive information logging. Successful exploitation could allow attackers to overwrite critical files, forge log data, exhaust system resources, or expose sensitive information, though no public exploitation has been reported. Schneider Electric has released version 1.5 to remediate all identified issues.
Krebs on Security reports that a startup soliciting zero-day vulnerabilities in popular software for large payouts is operated by individuals with histories of fraud, fake intelligence companies, and a defunct AI-based lobbying platform run under assumed identities. This raises significant vendor-trust and supply-chain risk concerns for any organization considering selling vulnerabilities to, or purchasing exploit intelligence from, this entity. There is no confirmed active exploitation tied to this report, but the operators' background suggests elevated risk of exploit misuse, data misrepresentation, or fraudulent business practices.
A threat actor dubbed Lurking Lizard has been running a residential proxy business since at least August 2022 using more than 230 lookalike domains that distribute trojanized software installers, including fake 7-Zip installers. Victims who download these fake installers unknowingly turn their devices into residential proxy exit nodes, which are then resold for anonymized traffic routing, potentially including malicious or fraudulent activity.
CISA disclosed two vulnerabilities in Digi International's PortServer TS and Digi One SP/SP IA/IA serial-to-network devices: an authentication bypass allowing unauthenticated access to restricted web resources, and a stored XSS flaw exploitable by authenticated administrators. These are legacy, end-of-life industrial devices used across critical manufacturing, communications, IT, and transportation sectors, with no vendor firmware fix planned for the XSS issue.
CVE-2026-9182 is an unrestricted file upload vulnerability in ArcGIS Server that allows an unauthenticated attacker to upload arbitrary crafted files to an affected endpoint. This could lead to further compromise such as web shell deployment or remote code execution depending on server configuration and processing of uploaded files.
A large-scale phishing campaign impersonates over 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, using fake job interview lures to steal Google account credentials from marketing professionals. The attackers leverage trusted brand names and recruitment pretexts to bypass victim skepticism and harvest credentials likely for account takeover, further phishing, or resale.
A medium-severity XML External Entity (XXE) vulnerability affects Schneider Electric EcoStruxure IT Data Center Expert versions 9.1.1 and prior, allowing an authenticated attacker to disclose server-side file contents via crafted XML payloads to SOAP service endpoints. Schneider Electric has released version 9.1.2 to remediate the issue, and no known public exploitation has been reported.
A joint law enforcement and industry operation involving Google disrupted NetNut, a residential proxy network built on approximately 2 million compromised Android devices, including smart TVs and streaming boxes. The infrastructure allowed threat actors and paying customers to route traffic through unwitting victims' devices, enabling anonymized malicious activity such as credential stuffing, ad fraud, and scraping. The takedown cuts off access to this proxy pool but does not necessarily remediate infections on affected devices.
CubeSpace CW0057 Reaction Wheel firmware versions prior to 5.0.20 fail to properly verify cryptographic signatures on firmware updates, relying only on CRC-32 integrity checks. An attacker with physical access could upload arbitrary malicious firmware without authentication, though the device remains recoverable via an independent bootloader.