Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 335 threats

icsotbuilding-automationxsscwe-79johnson-controlsmetasyscisa-advisory

A high-severity persistent cross-site scripting vulnerability affects Johnson Controls Metasys building automation systems (versions 12–15), allowing a low-privilege user to inject a malicious payload via a crafted URL that executes in other users' sessions, including administrators. This could lead to session hijacking and unauthorized access within critical infrastructure environments such as commercial facilities, manufacturing, energy, and government sites. No public exploitation has been reported to CISA at this time, but patches or vendor guidance are available for supported versions.

ransomwareEDR-evasionsafe-modedata-exfiltrationakiradouble-extortion

An Akira ransomware affiliate compromised a target network and rebooted a system into Safe Mode with Networking to disable endpoint detection and response (EDR) protections. The attacker successfully exfiltrated data but failed to deploy the encryption payload, resulting in a partial (extortion-only) compromise rather than full ransomware impact.

spywaremercenary-spywaremobile-securityiosnation-statesurveillancetargeted-attack

Apple has issued new 'Threat Notification' alerts warning select iPhone users that they have been targeted by mercenary spyware attacks. These notifications, part of Apple's ongoing threat intelligence program, indicate highly targeted, sophisticated attacks typically associated with commercial spyware vendors like NSO Group or Intellexa rather than broad-based malware campaigns.

ICSSiemensprivilege-escalationpath-traversalvulnerabilityCVECISA-advisorylicensing-server

Siemens License Server (SLS) versions prior to 5.1 and 5.3 are affected by two vulnerabilities: an insecure sudoers policy enabling local privilege escalation to root, and a path traversal flaw allowing remote unauthenticated attackers to read arbitrary files. Siemens has released patched versions and CISA has published an advisory recommending immediate updates.

ICSCISA-advisorySiemensout-of-bounds-readfile-parsingCVE-2026-64629critical-manufacturing

Siemens Parasolid, a 3D geometric modeling kernel used in CAD/CAM/CAE software across critical manufacturing, contains an out-of-bounds read vulnerability (CVE-2026-64629) triggered when parsing malformed X_T files. Successful exploitation could crash the application or allow arbitrary code execution in the context of the current process. Siemens has released patched versions (V38.0.235 and V38.1.230) and users are advised to update.

AI-securityLLMreasoning-APIsession-replaycredential-exposureAPI-key-leakageagent-relevantOpenAIAnthropicGoogle

Researchers disclosed a flaw in how OpenAI, Anthropic, and Google encode and carry hidden chain-of-thought reasoning between API calls, allowing encrypted reasoning objects from one session to be replayed into another session. This cross-session replay allowed weaker models to decode or expose internal reasoning content from stronger models, including sensitive data such as API keys and passwords captured in session logs.

androidmobile-malwarenfc-relayratbanking-trojancredit-card-fraudfraud

A newly identified Android malware campaign pairs a novel NFC relay tool called WindRelay with the established SpyNote RAT to capture and relay victims' live credit card data to attackers in real time. The combo also facilitates taking out fraudulent loans using stolen victim information, indicating a financially motivated criminal operation targeting mobile banking users.

data-theftsalesforceservicenowmisconfigurationcustomer-portalexposed-dataanonymous-accesssaas-security

A campaign dubbed 'City-Forum' is using custom tooling to systematically harvest data exposed to anonymous/unauthenticated users through misconfigured Salesforce Experience Cloud sites and ServiceNow customer portals. The attackers exploit overly permissive guest-user access controls rather than a software vulnerability, allowing bulk extraction of sensitive records without authentication.

patch-tuesdaymicrosoftwindowszero-dayvulnerability-managementagent-relevant

Microsoft's August 2026 Patch Tuesday addresses nearly 398 vulnerabilities across Windows and supported software, including one flaw already under active exploitation and two others that were publicly disclosed prior to patching. Organizations should prioritize patching the actively exploited vulnerability to reduce risk of compromise.

zoomzero-clickannotation-toolvideo-conferencingclient-hijackrcescreen-sharing

A flaw in Zoom's screen annotation feature could have allowed any meeting participant to hijack the client of another attendee, including the presenter, without any user interaction. The vulnerability required no click, download, or visible prompt, making it a fully zero-click, in-meeting attack vector. This poses significant risk to organizations relying on Zoom for internal and external communications, including those coordinating distributed teams or automated workflows via meeting integrations.

SandwormAPTRussiatrojanized-softwareVPNsocial-engineeringjob-lurecredential-theftIT-professionalsagent-relevant

The Russian state-linked threat group Sandworm is targeting system administrators and IT professionals with fake job offers designed to lure victims into installing a trojanized WireGuard VPN client. The campaign, active since at least May 2026, aims to compromise privileged accounts and gain persistent access to enterprise networks through social engineering and malicious software.

ransomwareblockchaindata-leakresilient-infrastructuredecentralized-C2extortion

DeadLock is a ransomware operation that leverages blockchain-backed decentralized infrastructure to host its victim communication portals and data-leak sites, making takedown efforts by law enforcement and security researchers significantly more difficult. This resilience model represents an evolving trend among ransomware groups seeking to evade traditional infrastructure disruption tactics.

CISAKEVvulnerability-managementCiscoWindowsMetabaseSQL-injectionuse-after-freeheap-overflowBOD-26-04agent-relevant

CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog: a heap inspection flaw in Cisco Secure Firewall ASA/FTD, a use-after-free in the Windows Ancillary Function Driver for WinSock, and a SQL injection vulnerability in Metabase. Federal agencies are required under BOD 26-04 to remediate these on a prioritized timeline, and all organizations are strongly encouraged to patch given confirmed in-the-wild exploitation.

medical-deviceiotbluetooth-low-energyhidden-functionalityhardware-vulnerabilityhealthcareunauthenticated-access

The Pulsetto Vagus Nerve Stimulator firmware accepts undisclosed, unauthenticated Bluetooth Low Energy commands that are not issued by the official companion app but are still processed by the device. Successful exploitation could allow a nearby attacker to disable electrical safety mechanisms or alter stimulation output settings, posing a physical safety risk to users. The vendor has not responded to CISA's coordination attempts, and no patch is currently available.

windowsprivilege-escalationuse-after-freekernel-driverCISA-KEVagent-relevant

CVE-2026-68820 is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys) that allows a locally authenticated attacker to escalate privileges to SYSTEM. It has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, with federal agencies required to remediate by August 25, 2026.

ciscoasaftdfirewalldoscisa-kevnetwork-infrastructureunauthenticated-rce-risk

A heap inspection vulnerability in Cisco Secure Firewall ASA and FTD allows an unauthenticated, remote attacker to trigger an unexpected device reload, causing a denial-of-service condition. CISA has added this CVE to its Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, with a mandated remediation due date of August 14, 2026.

weekly-recapsupply-chainzero-dayMCPagent-relevantrouter-backdoorAI-security

This week's roundup highlights a Metabase zero-day, supply-chain attacks targeting Model Context Protocol (MCP) tooling used in AI agent ecosystems, and backdoors found in consumer/enterprise routers. The report is an aggregated digest rather than a single incident, but the MCP supply-chain angle is directly relevant to organizations deploying AI agents and LLM tool-use frameworks.

ransomwarechina-linkedstorm-1175n-centralrmm-exploitationdouble-extortion

Microsoft has identified Storm-1175, a financially motivated China-linked threat actor, deploying a new ransomware strain called StormEncryptor, marking a shift from their prior use of Medusa ransomware. Initial access is suspected to involve exploitation of a flaw in N-central, a remote monitoring and management (RMM) platform commonly used by MSPs to administer client endpoints and infrastructure.

wordpresssupply-chainplugin-compromiseadmin-takeoverweb-security

A threat actor compromised the upstream infrastructure of BdThemes, a premium WordPress plugin developer, and tampered with a remote JSON feed served to site administrators. This modified feed was used to silently create rogue administrator accounts on affected WordPress installations, granting attackers persistent backend access.

OTICScritical-infrastructureenergyAPNcellular-networkremote-accessindustrial-control-systems

Hackers breached the operational technology (OT) network of a small Polish heat-and-power plant serving approximately 50,000 residents by exploiting a private Access Point Name (APN) used for remote cellular connectivity. The incident, disclosed as having occurred the prior year, highlights how insufficiently secured private cellular networks can serve as an overlooked pathway into critical infrastructure control systems.