Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 335 threats

RMMexploitation-in-the-wildMSPsupply-chain-riskremote-monitoringhotfixagent-relevant

N-able has released a second hotfix for its N-central Remote Monitoring and Management (RMM) platform after observing threat actors actively exploiting a recently disclosed vulnerability and evolving their attack techniques to persist on managed endpoints. The vendor is expanding protections beyond the initial patch, indicating attackers reaching into managed customer environments through the compromised RMM infrastructure.

prompt-injectionagent-relevantAI-securitydata-exfiltrationAtlassianindirect-prompt-injectionRAGLLM-tool-use

Security researchers demonstrated that Atlassian's Rovo AI assistant can be manipulated via attacker-controlled content (e.g., uploaded files or embedded instructions) to collect Jira and Confluence data accessible to a signed-in user and exfiltrate it to an external server. Two independent research teams found separate exploitation paths; only one has been confirmed remediated by Atlassian.

sharepointgovernmentdata-breachaccount-compromiseon-premises

Switzerland's Federal Office of Information Technology disclosed that attackers exploited vulnerabilities in on-premises Microsoft SharePoint servers to compromise roughly 200 government accounts. The incident highlights ongoing risks tied to unpatched or exposed SharePoint deployments within critical government infrastructure.

webmailcss-injectionphishingcredential-theftui-redressagent-relevantemail-security

PortSwigger researcher Gareth disclosed a class of CSS-based attacks that allow content embedded in an email to escape its intended message boundary and manipulate the surrounding webmail interface. Affecting Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, hijack trusted UI elements, leak session tokens, take over third-party accounts, and manipulate AI tools that process email content.

critical-infrastructureportstransportationoperational-disruptionIT-OT

The North Carolina Ports Authority confirmed a cyberattack that disrupted IT systems and slowed operations at the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. Details on the attack vector, threat actor, and data impact have not been publicly disclosed as of this report. The incident highlights ongoing risk to critical maritime and logistics infrastructure.

supply-chainbackdoorvideo-conferencinghacktivismtrojanized-installerrussiaagent-relevant

The Head Mare hacktivist group has compromised unpatched TrueConf video conferencing servers to replace legitimate client installers with trojanized versions containing backdoors. This supply-chain attack allows attackers to distribute malware to any organization or user downloading updates from compromised TrueConf servers, posing significant risk to enterprise communication infrastructure.

vishingsocial-engineeringsaasdata-extortioncredential-thefthelp-desk-impersonationagent-relevant

UNC6671 is a data extortion group conducting voice phishing attacks against financial services, private equity, and professional services firms. The group impersonates IT help desk staff and contacts employees via personal phones to coerce urgent 'security migration' actions that grant attackers access to SaaS environments and enterprise data.

clickfixmacosinfostealercrypto-theftsocial-engineeringcredential-theftagent-relevant

A ClickFix-style social engineering campaign is delivering a Go-based macOS infostealer capable of draining cryptocurrency wallets, harvesting browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The infection chain uses a shell script that profiles the victim's CPU architecture before fetching an architecture-specific malware payload, indicating deliberate targeting and evasion.

npmtyposquattingsupply-chainRATinfostealermalwarecross-platformagent-relevant

Nearly 800 malicious npm packages were identified delivering a cross-platform Remote Access Trojan and infostealer payload to Windows, macOS, and Linux systems. The packages use AI-generated or randomly typo-squatted names to trick developers into installing them via automated or manual dependency resolution.

data-breachhealthcarepii-exposurethird-party-risk

Unlimited Technology Systems, a healthcare software company, disclosed a data breach affecting more than 3.8 million individuals stemming from an incident that occurred in October 2025. Details on the specific attack vector, threat actor, and exact data types exposed remain limited in public reporting.

aviationicsotprotocol-vulnerabilitydosmessage-injectionradio-frequencycritical-infrastructure

Five vulnerabilities in the Controller-Pilot Data Link Communications (CPDLC) protocol over ATN-B1, used for aircraft-air traffic control text communications, allow unauthenticated message injection, denial-of-service, and forced session resets via unauthenticated clear-text radio frequency links. While not creating an unsafe aircraft condition directly, exploitation can degrade operational safety margins by increasing controller/pilot workload, delaying safety-critical instructions, and reducing situational awareness. No public exploitation has been observed, and attack complexity is high, requiring lab-like conditions.

CISAKEVcommand-injectionProgress-LoadMasterload-balancernetwork-appliancefederal-agenciesactive-exploitation

CISA has added CVE-2026-8037, a command injection vulnerability in Progress LoadMaster, to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation in the wild. Federal civilian agencies are required under BOD 26-04 to remediate this vulnerability on a prioritized timeline due to its potential to grant attackers total control of affected assets.

dellopenmanageauthentication-bypassserver-managementunauthenticated-accessremote-exploit

CVE-2026-56793 is an improper authentication vulnerability in Dell OpenManage Server Administrator (OMSA) affecting versions prior to 11.1.0.2. An unauthenticated remote attacker could exploit this flaw to gain unauthorized access to server management interfaces, potentially leading to further compromise of underlying infrastructure.

azurecloudprivilege-escalationnetwork-securitysqlagent-relevant

CVE-2026-62836 is a high-severity vulnerability in Azure SQL Managed Instance caused by improper restriction of communication channels to intended endpoints. An unauthorized attacker could exploit this over the network to elevate privileges without prior authentication, potentially gaining unauthorized access to sensitive data and control over database resources.

credential-theftdata-extortioncloud-securitysnowflakelegal-actionagent-relevant

Connor Riley Moucka, a Canadian national linked to the 2024 Snowflake extortion campaign, pleaded guilty to computer fraud and conspiracy charges tied to breaches of over 165 organizations, including the theft of call and text metadata for more than 100 million AT&T customers. The campaign exploited stolen credentials and lack of MFA on customer Snowflake accounts rather than a vulnerability in Snowflake itself, enabling mass data theft and subsequent extortion.

spectreside-channelcpu-vulnerabilityintelamdlinux-kernelspeculative-executionagent-relevant

MIT CSAIL researchers demonstrated a new microarchitectural attack called Interrupt Injection that bypasses existing Spectre v2 mitigations on Intel and AMD CPUs by timing a hardware interrupt to re-poison the branch predictor immediately after the kernel sanitizes it. The attack was proven on an AMD Zen 2 system running Linux 6.14 with all default Spectre v2 defenses enabled, allowing an unprivileged local process to leak protected kernel or cross-process data via speculative execution.

kvmvirtualizationprivilege-escalationlinux-kernelvm-escapenested-virtualizationcloud-infrastructureagent-relevant

A newly disclosed Linux kernel vulnerability dubbed Zapscape (CVE-2026-64561) affects KVM/x86's shadow MMU and can allow an attacker with kernel-level privileges inside a nested L1 guest VM to escape isolation and execute code on the host. This poses significant risk to cloud and virtualization providers that expose nested virtualization to untrusted or semi-trusted tenants.

extortionransomwarefinancial-sectordata-theftUNC6671BlackFile

A wave of cyberattacks against hedge funds, private-equity firms, and other financial organizations has been attributed to UNC6671, an extortion group linked to the BlackFile threat actors. The campaign appears focused on data theft and extortion rather than pure ransomware encryption, targeting high-value financial sector victims. Details on initial access vectors and specific TTPs remain limited in current reporting.

macOSinfostealerClickFixcrypto-theftsocial-engineeringcredential-theftagent-relevant

A ClickFix-style social engineering campaign is distributing a Go-based infostealer targeting macOS users, designed to exfiltrate cryptocurrency wallets, browser-saved passwords, Apple Keychain contents, and cached credentials. The attack relies on tricking victims into manually executing malicious commands via fake verification or error prompts, bypassing typical download-based security controls.

ICSSCADAABBMongoDBthird-party-componentdenial-of-servicevulnerability-disclosurecritical-infrastructure

ABB Ability Zenon's IIoT services bundle an outdated MongoDB 4.2 instance affected by 13 known MongoDB vulnerabilities, including memory disclosure, authentication/authorization bypass, denial-of-service, log injection, and certificate validation flaws. Successful exploitation could allow attackers to bypass security controls, crash services, execute unauthorized actions, or expose sensitive data on affected industrial control system deployments worldwide.