AI Agent Threats

Browse by attack type

Showing 521–540 of 563 threats, newest first

css-injectionweb-securitydata-exfiltrationbrowsernot-ai-agent-specificSurface: Human InterfacePropagation: None

This is a PortSwigger web security research post describing a CSS injection technique that exfiltrates attribute data via chained conditional CSS in inline style attributes, without needing selectors or stylesheet imports. It is a general web application security finding about browsers and CSS, with no relationship to AI agents, LLMs, agent frameworks, or agent-to-agent protocols such as MCP or A2A.

Updated Jul 5, 2026

supply-chainthird-party-skillsintegrity-verificationagent-securityvendor-reportASI04 · Agentic Supply ChainSurface: Supply ChainPropagation: None

This item is a vendor blog post from Unit 42 discussing general risks of integrating third-party 'skills' or plugins into enterprise AI agents, and advocating for integrity verification practices. It does not describe a specific vulnerability, exploit, or active threat, so it is classified as low severity informational content rather than a genuine incident.

Updated Jul 5, 2026

marketingsocmdrnot-a-threatvendor-contentSurface: Human InterfacePropagation: None

This item is a promotional blog post from Unit 42 about their SOC, MDR, and XSIAM services, framed around the statistic that attackers can move from initial access to exfiltration in 72 minutes. It does not describe any specific threat, vulnerability, or technique involving AI agents, agent frameworks, or agent protocols, so no genuine security issue can be extracted from it.

Updated Jul 5, 2026

cloud-securitybucket-hijackings3namespace-squattingcloud-storagenot-agenticSurface: Supply ChainPropagation: None

This Unit 42 research describes a cloud storage misconfiguration risk where attackers exploit globally unique bucket namespaces across cloud service providers to hijack references to deleted or unclaimed buckets, redirecting data intended for legitimate storage to attacker-controlled buckets. This is a traditional cloud infrastructure security issue and does not involve AI agents, agent frameworks, agent protocols (MCP/A2A), or inter-agent communication in any way. Severity is rated low strictly for relevance to AI agent security; the underlying cloud risk itself may carry higher severity in a pure cloud-security context, but that is out of scope here.

Updated Jul 5, 2026

agent-marketplaceskill-poisoninginfostealeragentic-fraudscanner-evasionopenclawclawhubASI04 · Agentic Supply ChainAML.T0010AML.T0018AML.T0048Surface: Supply ChainPropagation: Single Hop

Unit 42 identified malicious 'skills' distributed through OpenClaw's ClawHub marketplace that evade automated security scanning to deploy infostealer malware and carry out agentic financial fraud. This represents a supply chain threat where trusted third-party agent extensions become a vector for compromising the host system and any credentials or financial capabilities the agent has access to.

Updated Jul 5, 2026

owaspagentic-aitaxonomyannouncementindustry-newsnon-incidentSurface: Human InterfacePropagation: None

This item is a promotional/informational OWASP blog post announcing that its Agentic AI Threats and Mitigations taxonomy is being adopted by third-party tools (PENSAR, SPLX.AI Agentic Radar, AI&ME) and previewing an upcoming OWASP Top 10 for Agentic AI. It does not describe any vulnerability, exploit, or active threat, so no security risk is present in this data itself.

Updated Jul 5, 2026

owaspagentic-aiguidancestandardsnot-a-vulnerabilityindustry-newsSurface: Human InterfacePropagation: None

This item is a press release announcing that OWASP's GenAI Security Project published a Top 10 risks and mitigations list for agentic AI security. It is not a threat report, vulnerability disclosure, or incident; it describes a community guidance document rather than an active exploit or attack.

Updated Jul 5, 2026

owaspagentic-securityframeworkstandardsannouncementSurface: PlannerPropagation: None

This item is an announcement from OWASP GenAI Security Project introducing their new Top 10 list for Agentic AI Applications, a community-driven security framework rather than a specific vulnerability or attack. It describes a taxonomy/guidance resource, not an active threat, exploit, or incident.

Updated Jul 5, 2026

ctftrainingowaspagentic-aiannouncementno-threatSurface: Tool LayerPropagation: None

This item is a promotional announcement from OWASP GenAI Security Project about a new educational Capture-The-Flag environment called FinBot, designed to teach agentic AI security risks in a simulated financial services setting. It does not describe an actual vulnerability, exploit, or active threat, but rather a training tool for defenders and builders. No genuine security incident is present in this data.

Updated Jul 5, 2026

owaspASI06 · Memory Poisoningmemory-poisoningcontext-poisoningagentic-aiawarenessconceptualASI06 · Memory PoisoningSurface: MemoryPropagation: None

This item is an OWASP Gen AI Security Project blog post discussing memory and context poisoning as a conceptual risk category (ASI06) for agentic AI systems, not a report of a specific active exploit or vulnerability. It explains why persistent agent memory can become an attack surface if untrusted input is carried forward and later trusted, but contains no technical exploit details, affected products, or indicators of compromise. Severity is set to low because this is educational/awareness content rather than a disclosed incident or vulnerability.

Updated Jul 5, 2026

conceptualcultureover-relianceagentic-airisk-managementopinion-pieceSurface: Human InterfacePropagation: None

This is a conceptual/cultural commentary piece, not a disclosure of a specific vulnerability or exploit. It argues that organizations are gradually normalizing warning signs and over-reliance on LLM outputs in agentic systems, drawing an analogy to the Challenger disaster's 'normalization of deviance.' There is no concrete technical threat, proof-of-concept, or attack mechanism described.

Updated Jul 5, 2026

conference-talksecurity-researchcomputer-use-agentscoding-agentsmonth-of-ai-bugsawarenessSurface: Tool LayerPropagation: None

This item is a announcement/recap of a conference presentation (39C3) by Embrace The Red covering prior security research into AI computer-use and coding agent vulnerabilities, including demos from the 'Month of AI Bugs' series. It contains no new technical vulnerability details itself, just links to a talk recording and slides, so it does not describe a standalone actionable threat.

Updated Jul 5, 2026

data-exfiltrationmarkdown-injectionzero-clickprompt-injectionchatgptbing-chatdisclosuremitigation-paperASI05 · Unsafe Code ExecutionAML.T0051AML.T0024Surface: ModelPropagation: None

This item is a retrospective and largely positive report: OpenAI published a paper detailing mitigations for a long-known zero-click data exfiltration technique in which a language model can be manipulated into rendering attacker-controlled URLs (e.g., markdown images) that leak conversation data to an external server. The underlying vulnerability class was disclosed by the author nearly three years ago and was already mitigated by Microsoft in Bing Chat in 2023; this post covers OpenAI's newer, more formal write-up of defenses. Severity is moderate rather than critical because this is historical/defensive reporting on a well-understood, largely mitigated issue rather than a new active exploit.

Updated Jul 5, 2026

prompt-injectionunicode-tagsskillssupply-chainhidden-instructionsagent-backdoorgeminiclaudegrokASI04 · Agentic Supply ChainAML.T0051AML.T0043Surface: Supply ChainPropagation: Single Hop

A researcher demonstrated that AI 'Skills' (packaged capability bundles used by agent platforms) can be backdoored using invisible Unicode Tag codepoints that are stripped by human reviewers but still interpreted as instructions by models like Gemini, Claude, and Grok. This allows a malicious or compromised Skill to pass code review while silently injecting attacker instructions into the agent's context, enabling supply-chain prompt injection that survives manual auditing.

Updated Jul 5, 2026

prompt-injectioncommand-and-controlpromptwarememory-poisoningagentic-browsingpersistenceASI01 · Goal HijackingAML.T0051AML.T0054Surface: PlannerPropagation: Single Hop

This post describes 'promptware'-based command and control, where prompt injection payloads act like malware to give attackers persistent, remote-controlled influence over an AI agent's actions. It builds on prior research showing that combining browsing tools with persistent memory features can create a full C2 channel, letting an attacker issue ongoing instructions to a compromised agent over time.

Updated Jul 5, 2026

langgraphlangchainweak-hashcache-keycvelow-severitycwe-328ASI08 · Cascading FailuresSurface: MemoryPropagation: None

A low-severity vulnerability was identified in LangGraph's Task Result Cache where the internal _freeze function uses a weak hash for generating default cache keys. Exploitation requires high attack complexity and remote access, with a CVSS score of 3.1, making practical exploitation difficult. A fix is pending via an open pull request.

Updated Jul 5, 2026 · CVSS 3.1

MCPSSRFmcp-wikiunvalidated-inputtool-poisoningunpatchedASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

A server-side request forgery flaw exists in the mcp-wiki/wiki-summary component of AIAnytime Awesome-MCP-Server, where the 'url' argument passed to an MCP tool is not validated before the server fetches it. A remote attacker can supply this MCP-exposed tool with an internal or attacker-controlled URL to make the server issue requests on their behalf, potentially reaching internal network resources. The vendor has been notified but has not responded or patched the issue.

Updated Jul 5, 2026 · CVSS 6.3

commentaryvulnerability-researchai-agentsdual-useoffensive-securitytrend-observationSurface: ModelPropagation: None

This is a brief opinion/commentary post observing that AI agents are becoming effective at finding software vulnerabilities at scale, referencing a tweet and a prior LinkedIn post about a coming 'AI Vulnerability Cataclysm.' It does not describe a specific vulnerability, exploit, attack technique, or affected system, so it does not constitute a genuine, actionable security threat in itself.

Updated Jul 5, 2026

prompt-injectionadversarial-imagecross-model-attackmemory-toolindirect-injectionclaudechatgptmultimodalASI03 · Identity SpoofingAML.T0051AML.T0054Surface: MemoryPropagation: Single Hop

A researcher demonstrated that an image generated by ChatGPT could act as a carrier for an indirect prompt injection that hijacked Claude Opus 4.7's memory tool, causing it to persist false memories into future conversations. This shows that even hardened, reasoning-heavy models remain vulnerable to multimodal adversarial inputs crafted using puzzle-like framing to bypass safety reasoning.

Updated Jul 5, 2026

TOCTOUcomputer-use-agentrace-conditionbrowser-agentChatGPT-OperatorUI-confirmation-bypassASI06 · Memory PoisoningSurface: PlannerPropagation: None

This research describes a time-of-check-to-time-of-use (TOCTOU) attack against computer-use AI agents like ChatGPT Operator, where a malicious page or element changes between the moment the agent evaluates it and the moment it acts, causing the agent (and a supervising human) to click or execute something different from what was reviewed. The author reproduced a previously disclosed Google-reported vulnerability and demonstrated it live at a security conference. This is a legitimate and impactful vulnerability class for autonomous browser/UI-driving agents.

Updated Jul 5, 2026