Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 335 threats

browser-vulnerabilitytype-confusionrcemicrosoft-edgechromiumagent-relevant

CVE-2026-66321 is a type confusion vulnerability in Microsoft Edge (Chromium-based) that allows an unauthorized remote attacker to execute arbitrary code, typically via a malicious or compromised web page. Exploitation requires a victim to interact with attacker-controlled content, but successful attacks can lead to full code execution within the browser context.

agent-relevantllm-abusecredential-theftdiscounted-api-accessgray-marketclaudeanthropicmitmprompt-interception

Poison Claude is an underground service advertising discounted, illegitimate access to Anthropic's Claude models (including Opus 4.8/4.7/4.6 and Sonnet 4.6), likely by reselling stolen or abused API credentials/accounts. The operator sits in the middle of every session, meaning all customer prompts, outputs, and potentially embedded secrets pass through an untrusted third party. This represents a significant confidentiality and data-exfiltration risk for any individual or organization using the service, including those integrating it into automated or agentic workflows.

ClickFixmacOSsocial-engineeringfingerprintingevasionmalware-lureinitial-access

A large-scale ClickFix campaign spanning over 250 front-end domains uses server-side browser fingerprinting to selectively serve fake software download lures to macOS users while hiding malicious content from crawlers and sandboxes. Microsoft Threat Intelligence has been tracking this infrastructure for weeks, noting the increased sophistication of its evasion techniques targeting Mac users specifically.

SQL injectionpost-exploitationOracle databasenetwork intrusioninitial accessdatabase security

Threat actors exploited a SQL injection vulnerability to deploy the khunt post-exploitation toolkit directly within an Oracle database, using it as a foothold to breach the broader corporate network. This attack highlights database servers as an underexploited but high-value initial access vector, especially when they hold elevated privileges or trusted network connectivity.

cloud-securitydata-breachextortioncredential-theftsnowflakesaas-compromise

A Canadian national pleaded guilty to participating in a large-scale data theft and extortion campaign targeting Snowflake cloud storage customers, affecting at least 165 organizations. The attackers used stolen or weak credentials—lacking multi-factor authentication—to access customer Snowflake instances, exfiltrate sensitive data, and extort victims for millions of dollars.

CISAKEVJetBrainsTeamCitydeserializationCI/CDagent-relevantactive-exploitationfederal-mandate

CISA has added CVE-2026-63077, a deserialization of untrusted data vulnerability in JetBrains TeamCity, to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation. Under BOD 26-04, FCEB agencies must prioritize remediation of this vulnerability on publicly exposed assets, as it may grant attackers total control of affected systems post-exploitation. All organizations, including those outside federal scope, are strongly encouraged to remediate promptly given the severity of CI/CD compromise.

social-engineeringrmm-abusescreenconnectfake-updatesinitial-accessagent-relevant

Securonix Threat Labs identified an active, multi-wave social engineering campaign dubbed SMOKE#SCREEN that uses fake Adobe and Zoom update prompts, fraudulent document review notices, and system maintenance lures to trick victims into installing ConnectWise ScreenConnect. Once installed, the legitimate RMM tool grants attackers persistent, stealthy remote access to compromised endpoints, bypassing many traditional malware detection controls due to ScreenConnect's legitimate code signing.

phishing-as-a-serviceMFA-bypassdevice-code-phishingOAuth-abuseAiTMtoken-theftcredential-theftagent-relevant

The Greatness PhaaS platform has added device code phishing capabilities, allowing attackers to abuse the legitimate OAuth 2.0 Device Authorization Grant flow to bypass MFA and hijack user sessions via stolen tokens. Combined with its existing adversary-in-the-middle (AiTM) credential phishing, this significantly lowers the barrier for attackers to compromise MFA-protected accounts at scale.

phishingPhaaSMicrosoft 365adversary-in-the-middledevice-code phishingcredential theftbusiness-email-compromiseagent-relevant

The Greatness phishing-as-a-service platform has evolved from basic credential phishing to adversary-in-the-middle (AiTM) and device-code phishing techniques, now spoofing RingCentral notifications to target Microsoft 365 accounts. This expansion enables attackers to bypass MFA protections and steal session tokens, significantly increasing the risk of successful account takeovers across organizations using Microsoft 365.

TP-LinkOmadaZTPnetwork-infrastructureRCEvulnerability-chainIoTfirmware

TP-Link has patched 15 vulnerabilities in the zero-touch provisioning mechanism of its Omada network devices. These flaws can be chained with previously disclosed vulnerabilities to achieve remote code execution, potentially allowing attackers to breach entire networks through compromised network infrastructure.

ICSautomotive-securitybluetoothhard-coded-credentialsIoTCISA-advisory

Acrisure KARR BT and DR-100 anti-theft systems use a shared, hard-coded Bluetooth authentication key across all affected devices, allowing an attacker within Bluetooth range to send unauthorized commands to a vehicle. This could enable unauthorized door unlocking or engine immobilization. Acrisure has released a firmware update (July 20, 2026) to address the flaw, and no public exploitation has been reported.

ICSmedical-devicedata-integrityhealthcareCWE-353CVSS-8.4local-attack-vectorforensic-data-tampering

A vulnerability in multiple Thermo Fisher Applied Biosystems Genetic Analyzer software products allows tampering with .fsa/.hid output files due to missing integrity checks, which could result in falsified DNA test results. The flaw requires local access and no user interaction, affecting eight product lines including several that are end-of-life with no patch available.

apachetomcatencryption-bypasscisa-kevcluster-securityagent-relevant

Apache Tomcat contains a vulnerability that allows attackers to bypass the EncryptInterceptor, a component intended to encrypt sensitive data transmitted between nodes in a Tomcat cluster. This CVE has been added to CISA's Known Exploited Vulnerabilities catalog with a short remediation window, indicating active exploitation in the wild. Organizations running clustered Tomcat deployments should prioritize patching immediately.

passkeyscredential-theftWindowsChromeGoogle-Password-Managerlocal-malwareauthentication-bypassagent-relevant

Unit 42 researchers disclosed three attack techniques against Chrome's Google Password Manager cloud authenticator that allow user-level malware on a compromised Windows machine to sign into passkey-protected accounts without any biometric, PIN, or user-visible prompt. The strongest variant, Golden Pass-ta-key, targets the underlying master key, enabling silent, persistent account takeover even after remediation. This undermines the core phishing-resistance promise of passkeys when the endpoint itself is compromised.

npmsupply-chainRATdependency-confusiontyposquattingAlibabasoftware-supply-chainagent-relevant

Researchers identified 18 malicious npm packages, including one named 'lib-mtop' impersonating a private Alibaba package, designed to deliver a cross-platform remote access trojan to developers using Alibaba developer tools. The campaign appears to specifically target Chinese-speaking development environments through a targeted software supply chain attack, likely leveraging dependency confusion or typosquatting techniques.

ClickFixloader-as-a-servicesteganographyCountLoaderDeviceManagerRATRussian-threat-actorsocial-engineeringcross-platformcredential-theftagent-relevant

DOUBLECUP is a newly identified Russian loader-as-a-service that leverages ClickFix-style social engineering to trick victims into executing malicious commands, hiding payload code inside PNG images stored in browser caches. The service delivers CountLoader to both Windows and macOS victims and a new Windows-targeted remote access trojan called DeviceManager, expanding the threat actor's toolkit for initial access and persistent remote control.

passkeyscredential-theftwindowsgoogle-password-managerpost-exploitationaccount-takeoveragent-relevant

Security researchers disclosed three attack techniques, collectively dubbed 'Pass-ta-key,' that allow malware already present on a compromised Windows device to abuse Google Password Manager's synced passkey feature. The attacks enable adversaries to bypass user verification, hijack accounts protected by passkeys, and extract passkey private keys, undermining a core assumption that passkeys are phishing-resistant and device-bound.

APT29Midnight BlizzardhospitalityWi-FiMicrosoft 365credential-theftRussianation-stateagent-relevant

Microsoft has attributed a global campaign against hospitality Wi-Fi networks to the Russian state-sponsored actor Midnight Blizzard (APT29). The group uses custom malware deployed via compromised hotel networks to intercept traffic and steal Microsoft 365 credentials from traveling targets, likely diplomats, government officials, and corporate executives. The campaign highlights the ongoing risk of adversary-in-the-middle attacks on untrusted public networks.

CISAKEVauthentication-bypassN-ableN-centralRMMvulnerability-managementfederal-directive

CISA has added CVE-2026-18577, an authentication bypass vulnerability in N-able N-central, to its Known Exploited Vulnerabilities Catalog based on confirmed active exploitation. Federal civilian agencies are required under BOD 26-04 to remediate this vulnerability on a prioritized timeline, and CISA urges all organizations to apply the same urgency.

captive-portal-hijackfake-updateRATsurveillance-malwareMidnight-BlizzardStorm-2945hospitalitynation-statecredential-theftagent-relevant

Microsoft has identified a campaign, tracked as CaptiveCrunch, in which threat actors hijack hotel Wi-Fi captive portals to serve fake browser update prompts. Victims who install the fake update are infected with CornFlake, a remote access trojan capable of capturing webcam images, microphone audio, and keystrokes. The activity is attributed to Storm-2945, assessed as an operational sub-cluster of the Russian state-sponsored group Midnight Blizzard (APT29).