Tag: malicious
-
Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems
OpenAI confirmed their agents were behind a campaign in May that researchers say flooded the popular online code repository with malicious software packages. First seen on cyberscoop.com Jump to article: cyberscoop.com/openai-agents-malicious-rubygems-packages/
-
Anthropic Says AI Is Lowering the Bar for Sophisticated Attacks
Threat Report Finds Multi-Agent Tools Let Less-Skilled Actors Scale Complex Operations. Anthropic’s Threat Intelligence team identified a series of attempted attacks using its AI systems by malicious actors. The report focuses not on how fast AI systems develop exploits at scale, but on how broader, deeper attacks can emerge with just a few resources. First…
-
Anthropic Says AI Is Lowering the Bar for Sophisticated Attacks
Threat Report Finds Multi-Agent Tools Let Less-Skilled Actors Scale Complex Operations. Anthropic’s Threat Intelligence team identified a series of attempted attacks using its AI systems by malicious actors. The report focuses not on how fast AI systems develop exploits at scale, but on how broader, deeper attacks can emerge with just a few resources. First…
-
Anthropic Says AI Is Lowering the Bar for Sophisticated Attacks
Threat Report Finds Multi-Agent Tools Let Less-Skilled Actors Scale Complex Operations. Anthropic’s Threat Intelligence team identified a series of attempted attacks using its AI systems by malicious actors. The report focuses not on how fast AI systems develop exploits at scale, but on how broader, deeper attacks can emerge with just a few resources. First…
-
Hackers abused Claude to extract secrets from 1.8M Android apps
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/
-
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/1m-personalized-fraud-emails-3-days
-
How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, sponsored search results, and ClickFix-style lures. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/how-threat-actors-are-turning-trusted-ai-platforms-into-an-attack-surface/
-
Hackers Favor US Eastern Business Hours in M365 Phishing Campaign
KnowBe4 researchers observed a new phishing campaign leveraging Microsoft 365’s Direct Send to send malicious emails First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/hackers-us-business-hours-m365/
-
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controlled RealRTSP servers. The more severe vulnerability, tracked as CVE-2026-56711, is a heap out-of-bounds write flaw with a CVSS v4 score of…
-
Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/trezor-347-000-users-targeted-in-phishing-attacks-after-brevo-breach/
-
New AI Attack Hides Malicious Instructions in Normal-Looking Text to Evade Safety Filters
A newly disclosed prompt-crafting technique can hide policy-violating instructions inside ordinary-looking English prose, allowing malicious requests to pass through lightweight LLM safety filters before being recovered and processed by a more capable downstream model. Researchers found that carefully structured prose can make the first model miss an embedded instruction entirely, while the target model invests…
-
WordPress Blocks High-Risk Plugin Releases With New AI-Powered Automated Security Review
WordPress has launched an automated security review system that uses multiple AI models and Jetpack Scan to analyze every plugin release before distributing it to websites via the WordPress.org update API. This new control is designed to prevent vulnerable or malicious plugin updates from reaching millions of WordPress installations through dashboard-based, one-click updates. WordPress Blocks…
-
Imperva Customers Protected Against StyleSmuggler (CVE-2026-75650) in Adobe Commerce and Magento Open Source
TL;DR: CVE-2026-75650, dubbed StyleSmuggler, is a critical vulnerability affecting Adobe Commerce and Magento Open Source. The vulnerability allows an unauthenticated attacker to inject malicious PHP code into Magento’s template system and achieve remote code execution. Adobe assigned the vulnerability a CVSS score of 10.0 and… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/imperva-customers-protected-against-stylesmuggler-cve-2026-75650-in-adobe-commerce-and-magento-open-source/
-
Anthropic details bad actors’ efforts to misuse its AI for bioweapons
Report comes two days after former employee quit claiming company’s models could cause human extinction by 2030Criminals, state-sponsored groups, spyware vendors, scientists and propagandists have attempted to use Anthropic’s powerful artificial intelligence models to design missiles and bombs, create deadly pathogens and surveil dissidents, according to a<a href=”https://www.anthropic.com/threat-intelligence-report-september-2026#biological-misuse-sep-26″> threat intelligence report the company published on…
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
The Top 4 Threats We Found by Investigating Every Alert for a Quarter
Identity was the target in roughly half of all confirmed malicious activity. Prophet Security breaks down the four main attack patterns seen across customer environments between May and July 2026, and explains why some attacks succeeded while others were blocked. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/the-top-4-threats-we-found-by-investigating-every-alert-for-a-quarter/
-
Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds
A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O archive parser could allow a malicious static library to crash Xcode build processes or expose process memory through build logs. This flaw affects the parser used by Apple’s newer linker, ld-prime, as well as related developer tools, including libtool, ranlib, and potentially dyld_info. Apple Xcode Integer…
-
New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners
A phishing campaign that moves the credential-harvesting page out of attacker-controlled web infrastructure and into the victim’s browser. Unlike ordinary phishing kits, which host cloned login portals on domains that can eventually be detected and disrupted, this campaign delivers malicious content assembled only after a user follows the attack chain. A blob URL is a…
-
OpenAI pledges $1B to provide resources, training for frontline cyber defenders
Amid heightened scrutiny, the company will use frontier AI to help water, power and local government providers fight malicious actors. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/openai-pledges-1-billion-resources-cyber-defenders/829676/
-
Hackers Hijack Coder Module Registry to Distribute Credential-Stealing Malicious Packages
Coder has reported a significant software supply chain incident in which an unidentified threat actor redirected part of its official module registry traffic to attacker-controlled infrastructure. This led to the temporary distribution of tampered Terraform modules intended to steal credentials. The incident affected the registry at registry.coder.com on August 31, 2026, between 07:35 UTC and…
-
Known npm Worm Returns After 111 Days and Security Scanning Still Let It Through
A known Shai-Hulud npm worm payload has resurfaced after 111 days of inactivity, raising fresh questions about the effectiveness of registry-level malware screening. The May campaign demonstrated how quickly a single compromised maintainer account can turn into a software supply-chain incident. Attackers pushed malicious versions across npm packages, including widely used visualization and frontend dependencies.…
-
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems.According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake First seen on…
-
Kimsuky Uses OpenCode AI Agent and GitHub PATs in Operation GitPower Attacks
North Korea-linked threat actor Kimsuky has expanded its Operation GitPower activity with malicious LNK shortcuts, GitHub Personal Access Token (PAT)-authenticated payload delivery, and AI-generated decoy documents linked to the OpenCode coding agent. Genians Security Center analyzed 13 malicious LNK samples collected between August 11 and August 19, 2026. The files were delivered in ZIP archives…
-
Fake Minecraft Mod Drops Myth Stealer RAT to Steal Passwords and Remotely Control PCs
A trojanized Minecraft optimization mod posing as a companion to the legitimate Lithium project has been used to deploy Myth Stealer 3.2-FIX, a password-stealing malware family with remote-access, surveillance, persistence, and victim-harassment capabilities. The malicious archive, tracked as MythStealer.jar_, masquerades as Lithium Extras 0.15.0+mc1.21.1 by “soder.” It abuses the reputation of CaffeineMC’s legitimate Lithium performance…
-
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Tags: adobe, advisory, attack, backdoor, exploit, flaw, malicious, open-source, vulnerability, zero-dayAttackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store’s server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5.Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4.…
-
OpenAI pledges $1 billion to provide resources, training for frontline cyber defenders
Amid heightened scrutiny, the company will use frontier AI to help water, power and local government providers fight malicious actors. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/openai-pledges-1-billion-resources-cyber-defenders/829676/

