Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 120 threats

ai-model-theftknowledge-distillationintellectual-propertyapi-abusellmanthropicterms-of-service-violationagent-relevant

Anthropic disclosed that it identified and disrupted large-scale illicit knowledge distillation operations targeting its Claude model, attributed to seven China-based AI labs including Alibaba, Moonshot, DeepSeek, Z.ai, and MiniMax. These operations allegedly used systematic, high-volume API querying of Claude to extract outputs used to train competing models, violating Anthropic's usage policies rather than exploiting a technical vulnerability.

os-command-injectiondellscgunauthenticatednetwork-applianceinput-validation

Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application versions prior to 5.36.00.16 and 5.36.00.00 respectively contain an OS command injection vulnerability that can be exploited remotely without authentication. Successful exploitation could lead to script injection, potentially enabling unauthorized command execution on the affected appliance.

command-injectiondellunauthenticatednetwork-appliancescript-injection

Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application contain a command injection vulnerability that could allow an unauthenticated remote attacker to inject malicious scripts. The flaw carries a moderate CVSS score of 5.3, indicating limited but real risk to affected deployments.

chromebrowser-vulnerabilityextensionsprivilege-escalationsandbox-bypass

CVE-2026-87544 is an incorrect authorization vulnerability in Google Chrome's Extensions component that allows a remote attacker to bypass system access restrictions and reach a privileged page via a crafted HTML page. Google classifies the Chromium security severity as Low, though the NVD CVSS score of 9.8 appears inconsistent with the vendor's own assessment. Affects Chrome versions prior to 153.0.8010.36.

androidmobile-fraudgoogle-playsocial-engineeringfake-appsscam

Threat actors are exploiting Google Play's Early Access program, intended for pre-release beta feedback, to distribute thousands of deceptive Android apps promising fake money, rewards, casino winnings, and premium content. This abuse allows fraudulent apps to bypass some standard vetting scrutiny while still appearing on the legitimate Play Store, increasing user trust and installation rates.

roundupandroidphishingbrowser-extensionssupply-chainscam-shopsvulnerability-digest

This is a weekly aggregated security news digest covering approximately 200 Android vulnerabilities, browser-based phishing techniques using malicious extensions, and a network of roughly 119,000 fraudulent online storefronts. The report is a compilation of disparate stories rather than a single coordinated campaign, spanning exposed systems, aging unpatched bugs, malicious browser extensions, and risky software packages.

vpnmisconfigurationdata-exposureexposed-serverproxycloud-security

Surfshark disclosed that attackers accessed one of its internal testing/proxy servers after a configuration error left it exposed to the public internet. The incident highlights ongoing risks from misconfigured internal infrastructure at network service providers, though the scope of user data exposure has not been fully detailed.

windows-serverpatch-issueremote-desktopavailabilityreliability-bug

Microsoft's September 2026 security updates for Windows Server 2019, 2022, and 2025 are causing Remote Desktop Services (RDS) failures, blocking user connections and in some cases requiring a hard reset to restore service. This is a patch quality/regression issue rather than an exploited vulnerability, but it poses an operational availability risk for organizations relying on RDS for remote access.

chromeandroidwebviewauthorization-bypasssocial-engineeringbrowser-security

A missing authorization vulnerability in WebView on Google Chrome for Android prior to version 153.0.8010.36 allows a remote attacker to bypass system access restrictions via crafted network traffic combined with social engineering. Google/Chromium rates this as Medium severity, indicating exploitation requires user interaction and does not grant full system compromise on its own.

law-enforcement-actionscam-marketplacecryptocurrencypig-butcheringtelegramorganized-crimedoj

The U.S. Department of Justice disrupted Xinbi Guarantee, an online marketplace facilitating scam services for Chinese organized crime groups, seizing associated Telegram channels and freezing $52.8 million in cryptocurrency. The action also included physical disruption of 13 scam compounds in Madagascar linked to romance and investment scam operations (commonly known as 'pig butchering' schemes).

bluetoothiothardware-vulnerabilityproximity-attackconsumer-device

CERT/CC has disclosed that Skullcandy Dime 3 wireless earbuds will accept Bluetooth pairing requests from any nearby device without requiring user confirmation. This flaw could allow an attacker within Bluetooth range to eavesdrop on audio or hijack the connection without the victim's knowledge or consent.

path-traversalunauthenticatedremote-code-executiondellscgvulnerabilitynetwork-appliance

A path traversal vulnerability in Dell SCG 5.0 Appliance and Application allows an unauthenticated remote attacker to escape restricted directories, potentially leading to remote code execution. The flaw affects versions prior to 5.36.00.16 (Appliance) and 5.36.00.00 (Application) and carries a CVSS score of 6.5, indicating medium severity despite the RCE potential.

complianceregulatoryEU-CRAvulnerability-disclosureSBOMsoftware-supply-chain

This is a regulatory compliance advisory, not an active exploit or malware campaign. The EU Cyber Resilience Act imposes new mandatory vulnerability reporting requirements effective September 11, requiring software vendors to report actively exploited vulnerabilities to authorities within 24 hours of awareness. The article emphasizes that organizations must maintain precise records of software composition and vulnerability discovery timelines to meet these tight deadlines.

fraudphishingfake-shopspayment-card-thefte-commerce-frauddomain-abuse

DoppelCart is a large-scale fraud operation leveraging over 119,000 fake e-commerce domains to trick consumers into entering payment card details on fraudulent storefronts. The scale of the infrastructure suggests automated domain generation and templated site deployment, enabling rapid scaling and takedown resilience. The primary impact is financial fraud and payment card data theft against consumers and, by extension, brands whose identities may be spoofed.

ICSIoThard-coded-credentialsphysical-accessIP-cameraCISA-advisoryfirmwarebootloader

CareCam Pro IP Cameras (ANJIA AJL33PC0801 firmware) contain a hard-coded credential used for bootloader authentication, allowing an attacker with physical access to gain privileged bootloader access and fully compromise the device. The vendor has not responded to CISA's coordination attempts, and no patch is currently available. Exploitation requires physical access and is not remotely exploitable.

data-breachthird-party-risksupply-chainpii-exposurefulfillment-vendorcryptocurrency

Hardware wallet maker Trezor disclosed that 67,000 U.S. customers had personal data exposed in a breach at its shipping partner ShipMonk, despite the data reportedly having been deleted. Exposed information includes names, emails, phone numbers, shipping addresses, and order numbers spanning November 2019 to August 2021. Trezor confirmed the breach does not compromise the security of its hardware wallets or private keys.

phishingunicode-smugglingemail-security-evasionsocial-engineeringagent-relevant

Threat actors are embedding invisible Unicode characters within phishing emails to conceal malicious lures and evade email security filters, a technique known as ASCII smuggling. This allows attackers to bypass keyword-based and pattern-matching detection systems while presenting deceptive content to human victims or automated parsers.

passkeysFIDO2authentication-bypassidentitysocial-engineeringcredential-recovery-abuseagent-relevant

Researchers have catalogued 39 distinct methods that undermine passkey-based authentication without breaking FIDO2 cryptography itself, instead targeting weak points like enrollment, recovery flows, synced credential stores, and user-facing prompts. These attacks exploit implementation and process gaps across platforms rather than cryptographic flaws, meaning organizations relying on passkeys as a phishing-proof control may still be exposed to account takeover.

post-quantum-cryptographyPQCcryptographic-migrationpolicy-advisoryquantum-computingCISAG7

CISA and the G7 Cyber Security Working Group have jointly issued a call to action urging governments and organizations to begin transitioning to post-quantum cryptography (PQC) in order to protect sensitive data, authentication systems, and critical infrastructure from future quantum computing threats. This is a strategic/policy advisory rather than an active exploit, emphasizing awareness, national strategy development, R&D, public-private partnerships, and procurement integration.

phishingunicode-evasionemail-securitysocial-engineeringfilter-bypassagent-relevant

Microsoft identified a high-volume phishing campaign that embeds invisible Unicode tag characters within financial lure words (e.g., 'funding') to evade traditional email security filters. The technique splits keywords at the character level so pattern-matching and keyword-based detection engines fail to flag the malicious content, while the text still renders normally to human recipients.