Tag: LLM
-
Using LLMs to Find & Prioritize Vulnerabilities Is No Easy Task
The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/finding-and-prioritizing-vulnerabilities-no-easy-task
-
Using LLMs to Find & Prioritize Vulnerabilities Is No Easy Task
The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/finding-and-prioritizing-vulnerabilities-no-easy-task
-
Die neue Risiken durch agentische KI im Fokus – Warum LLM-Observability zum Sicherheitsfaktor für KI-Systeme wird
First seen on security-insider.de Jump to article: www.security-insider.de/warum-llm-observability-zum-sicherheitsfaktor-fuer-ki-systeme-wird-a-bd9def5d1852e535db0558409c91e25f/
-
When AI Attacks: OpenAI Models Autonomously Hack Hugging Face
Advanced LLMs escaped their sandboxes while attempting to achieve a non-malicious benchmark test objective. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/openai-models-autonomously-hack-hugging-face
-
OpenAI says model test was behind Hugging Face hack
At the time, Hugging Face said it wasn’t clear which LLM was used in the attack. OpenAI confirmed it was one of their models being tested for “maximal” cyber capabilities. First seen on cyberscoop.com Jump to article: cyberscoop.com/openai-chatgpt-hugging-face-cyberattack-data-poisoning/
-
Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Task
The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/finding-and-prioritizing-vulnerabilities-no-easy-task
-
Remediating Vulnerabilities With LLMs: Inside Ivanti’s Automation Push
Ivanti CSO Daniel Spicer says frontier models have shown surprising effectiveness in early stages; but cost and human-in-the-loop viability remain open questions. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/remediating-vulnerabilities-llms-ivanti-automation
-
F5 CEO On Massive AI Security Opportunity: LLMs Are ‘A Vulnerable Technology Today’
F5 is doubling down on enabling solution and service providers to capitalize on surging AI adoption through the recent launch of its unified platform for discovering, testing and securing AI models, according to F5 CEO François Locoh-Donou. First seen on crn.com Jump to article: www.crn.com/news/security/2026/f5-ceo-on-massive-ai-security-opportunity-llms-are-a-vulnerable-technology-today
-
PENTDEM AI Pentesting Daemon Uses 34 Security Tools to Automate WAF Bypass and Attack Chains
Tags: ai, attack, bug-bounty, cyber, firewall, LLM, open-source, penetration-testing, tool, vulnerability, wafPENTDEM is an open-source autonomous AI pentesting daemon that integrates 34 security tools with LLM-directed analysis to automate various tasks, including reconnaissance, vulnerability discovery, evidence validation, Web Application Firewall (WAF) fingerprinting, and multi-stage attack-path modeling. This Python-based project is designed for authorized security testing and bug-bounty workflows, offering both an autonomous agent mode and a…
-
Linux Creator Linus Torvalds Rejects Anti-AI Push and Defends LLM Tools
Linux creator and top-level kernel maintainer Linus Torvalds has made it clear that the Linux kernel project will not adopt an anti-AI stance. He believes that large language models and related tools should be assessed based on their technical value rather than dismissed outright. His comments were part of a discussion on the Linux Media…
-
1M+ Emails Use Hidden Text to Dupe AI Security Filters
Artificial intelligence and LLMs can be surprisingly ineffective against text salting, allowing phishing emails to slide right into your inbox. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/1m-emails-hidden-text-dupe-ai-security-filters
-
Single Prompt Enables ChatGPT to Execute Full Cyber-Attack Chain, Researchers Claim
Cybersecurity researchers tested Open AI GPT 5.5’s offensive cyber capabilities and the results showed how effective a frontier LLM can be for hackers First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/chatgpt55-to-execute-full/
-
TuxBot v3: The IoT Botnet Built With AI Bugs, Disclaimers and All
TuxBot v3, an AI-built IoT botnet for 17 architectures, shipped with LLM bugs and safety disclaimers the developer never removed. Palo Alto Networks’ Unit 42 identified a previously undocumented modular IoT botnet framework called TuxBot v3 Evolution, and it comes with an unusual detail: the developer used a large language model to write significant portions…
-
ThreatLocker CEO: ‘Fighting AI With AI’ Is Not A Winning Security Strategy
The idea of ‘fighting AI with AI’ is fundamentally the wrong approach for protecting against intensifying LLM-powered attacks, ThreatLocker CEO Danny Jenkins says in the inaugural episode of CRN’s new Security or Else! video series. First seen on crn.com Jump to article: www.crn.com/news/security/2026/threatlocker-ceo-fighting-ai-with-ai-is-not-a-winning-security-strategy
-
Attackers Combine MCP Recon With Cloud Metadata SSRF to Steal Service Account Tokens
Internet-wide reconnaissance is expanding beyond conventional application targets to include Model Context Protocol (MCP) services, AI assistant configuration files, and locally exposed LLM endpoints. A 14-day review of Apache and ModSecurity logs from a small, low-traffic shared host found roughly 200 requests tied to AI-agent reconnaissance, alongside routine WordPress, .env, Git, and Spring Boot Actuator…
-
New Relic startet kostenloses Observability-Programm für Startups bis Series A
Da Startups zunehmend auf LLMs, Agenten und KI-generierten Code setzen, liefern sie neue Funktionen und Änderungen oft in rasantem Tempo über ihren gesamten Tech-Stack hinweg aus. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/new-relic-startet-kostenloses-observability-programm-fuer-startups-bis-series-a/a45727/
-
Hackers can use 9 of the most popular AI tools to assemble massive botnets
“HalluSquatting” weaponizes LLMs’ inability to say “I don’t know.” First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/hackers-can-use-9-of-the-most-popular-ai-tools-to-assemble-massive-botnets/
-
JadePuffer: The First Complete LLM-Driven Ransomware Attack
An agentic threat actor successfully exploited a Langflow flaw to steal data from a production database server and encrypt other systems. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/jadepuffer-first-complete-llm-driven-ransomware-attack
-
SSH Attackers Use Single Exec Commands to Bypass Interactive Honeypot Analysis
SSH attackers are increasingly abusing single non-interactive exec commands over SSH to bypass traditional honeypot analysis, effectively turning post-authentication activity into short, automated probes rather than interactive shell sessions that deception systems were designed to study. Recent measurements on eleven LLM-backed SSH honeypots show that 99.23% of authenticated sessions consist of a single non-interactive exec…
-
Chinese LLMs Broaden the Gap Between Attackers & Defenders
Two new models from Chinese firms compete with top US mainstream and frontier models. Should cyber-defenders be worried? First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/chinese-llms-broaden-gap-between-attackers-and-defenders
-
Sysdig Details JADEPUFFER, the First Documented Agentic Ransomware Operation
A new Sysdig report traces how an LLM agent abused a Langflow flaw, stole credentials, reached production MySQL, and destroyed Nacos config data in minutes flat. First seen on hackread.com Jump to article: hackread.com/sysdig-jadepuffer-first-agentic-ransomware-operation/
-
Sysdig Details JADEPUFFER, the First Documented Agentic Ransomware Operation
A new Sysdig report traces how an LLM agent abused a Langflow flaw, stole credentials, reached production MySQL, and destroyed Nacos config data in minutes flat. First seen on hackread.com Jump to article: hackread.com/sysdig-jadepuffer-first-agentic-ransomware-operation/
-
JADEPUFFER Agentic Ransomware Uses LLM to Automate Database Extortion
The first instance of agentic ransomware: JADEPUFFER, an LLM-driven extortion operation that automated an end-to-end database-crippling campaign. The actor gained execution on an internet-facing Langflow instance via CVE-2025-3248, used the AI-host environment to harvest cloud and API credentials, and pivoted into a production MySQL/Nacos deployment to carry out a destructive, database-focused extortion playbook without a…
-
‘Phantom Squatting’: An Emerging AI-Driven Supply Chain Threat
LLMs consistently hallucinate Web domains for legitimate brands that attackers can register for malicious activity in a difficult-to-detect attack vector. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/phantom-squatting-ai-driven-supply-chain-threat
-
Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique
Tags: ai, attack, chatgpt, cybercrime, LLM, malicious, malware, programming, ransomware, software, toolesearch by:Alexey Bukhteyev Key Takeaways Introduction Over the past several years, large language models have reshaped software development, and malware development has followed the same path. Check Point Research has documented this trend from early experiments showing that AI systems could generate offensive components, to cases of cybercriminals using ChatGPT to create malicious tools, and…
-
Attackers Register AI-Hallucinated Domains to Deliver Phishing Kits and Malware
An emergent supply-chain attack vector they term >>phantom squatting,<< in which large language models (LLMs) routinely hallucinate plausible but nonexistent domains for legitimate brands and adversaries then preemptively register those domains to host phishing kits, malware, and other malicious infrastructure. By systematically probing two distinct LLM families across temperature settings, Unit 42 generated a 2.1…
-
AI-Powered Reverse Engineering Turns EDR Rule Analysis Into Automated Evasion Workflow
LLMs are reshaping endpoint security research by turning what used to be slow, manual reverse engineering into an automated, repeatable evasion workflow. Recent hands-on experiments with advanced models driving disassembly and local analysis show that a compact harness LLM plus disassembler, a shared state file, and a loop can recover EDR artifacts, decrypt local signature…
-
New attack provides one more reason why AI browsers are a bad idea
Telling an LLM that 2 + 2 = 5 is enough to make it follow forbidden instructions. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/06/ai-browsers-can-be-lulled-into-a-dream-world-where-guardrails-no-longer-apply/
-
AI-Generated Mythic Agents Challenge Static Signatures and Traditional Implant Detection
The emergence of LLM-driven >>disposable tooling<< is reshaping offensive tradecraft and forcing defenders to rethink detection models that rely on static signatures and known implant behaviors. Recent experiments demonstrating the automated generation of Mythic agents from prompt to deployment reveal a new threat class: ephemeral, single-use implants tailor-made by large language models and orchestration harnesses.…
-
Companies keep bolting AI onto their products, and the security bill is coming due
Companies keep bolting AI and LLM features onto their products, and the security results are starting to show a pattern. The vulnerabilities those features create get rated … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/29/products-ai-pentesting/

