<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>AI Threat Watch</title><description>An automated watch on attackers using AI and on attacks against AI systems. Short summaries, direct links to the source.</description><link>https://ai-threat.watch/</link><language>en</language><ttl>360</ttl><item><title>Detecting and countering misuse of AI: September 2026</title><link>https://www.anthropic.com/threat-intelligence-report-september-2026</link><guid isPermaLink="false">https://ai-threat.watch/#2026-09-18-anthropic-misuse-report</guid><description>&lt;p&gt;Anthropic describes actors who automate whole intrusion chains with AI agents. One Russian-speaking espionage operator had agents rebuild malware whenever a security product detected it, and used AI to sort hundreds of gigabytes of stolen data.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Anthropic | Actors: GTG-20006, Midnight Blizzard, GTG-50014, JackPoterz | Malware: PentAGI, WPPConnect, Embassy Kit, CaptiveCrunch | Attribution: Russia, per Anthropic (confidence not stated)&lt;/p&gt;</description><pubDate>Fri, 18 Sep 2026 06:00:00 GMT</pubDate><category>AI-Enabled</category><category>Must-read</category></item><item><title>Devil’s advocate? Uncensored Luciferus AI service advertised underground</title><link>https://www.sophos.com/en-us/blog/uncensored-luciferus-ai-service-advertised-underground</link><guid isPermaLink="false">https://ai-threat.watch/#2026-09-16-sophos-devil-s-advocate-uncensored-luciferus-ai</guid><description>&lt;p&gt;Sophos CTU researchers found an underground forum persona advertising Luciferus, an uncensored AI service claiming to be a proprietary 120-billion-parameter model, though researchers assess with low confidence it is based on Qwen. The service offers tiered subscriptions and demonstrated willingness to generate malware code like a Python RAT, illustrating growing commercialization of uncensored AI in cybercrime market&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Sophos | Actors: Optimus_Prime | Malware: Luciferus, WormGPT, FraudGPT&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:59:48 GMT</pubDate><category>AI-Enabled</category></item><item><title>New packages identified in GemStuffer &apos;OpenAI Swarm&apos; malicious RubyGems campaign</title><link>https://research.jfrog.com/post/gemstuffer-openai-rubygems/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-09-15-jfrog-security-research-new-packages-identified-in-gemstuffer-op</guid><description>&lt;p&gt;JFrog identified over 3,000 malicious RubyGems packages tied to the GemStuffer campaign, some exploiting a RubyGems legacy API-key caching flaw to steal credentials and others using XSS or template-injection payloads in package metadata. Naming patterns and prior incidents link the campaign to OpenAI Swarm agents generating packages at scale, though original prompts remain unavailable.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: JFrog Security Research | Actors: OpenAI Swarm | Malware: slnleaker5, f2fe-s1, yardxabc889, southpxdatapp6pi, xss-test-gem, test-apex-gem, test-ssti-0, test-ssti-1&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:59:39 GMT</pubDate><category>AI-Enabled</category></item><item><title>Infostealers Have Found a New Target: Your AI Agent</title><link>https://www.gendigital.com/blog/insights/research/infostealers-your-ai-agent</link><guid isPermaLink="false">https://ai-threat.watch/#2026-09-09-gen-digital-infostealers-have-found-a-new-target-you</guid><description>&lt;p&gt;Gen Digital&apos;s telemetry shows infostealers like Amatera, Remus, CallbackBeaver, and Djinn Stealer have added AI coding agents (Claude, Cursor, Codex, Cline, OpenCode) to their collection rules, harvesting tokens, MCP credentials, and prompt histories. This expands the infostealer economy to target local AI agent data as a new high-value asset alongside browser and wallet credentials.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Gen Digital | Malware: Amatera, Remus, CallbackBeaver, BeeStealer, STG Stealer, HydraStealer, APEX Stealer, Otter Stealer&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:59:04 GMT</pubDate><category>AI-Targeted</category></item><item><title>Kimsuky Uses the AI Agent &apos;opencode&apos; to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve</title><link>https://www.genians.co.kr/en/blog/threat_intelligence/ai-agent-opencode</link><guid isPermaLink="false">https://ai-threat.watch/#2026-09-07-genians-kimsuky-uses-the-ai-agent-opencode-to-cr</guid><description>&lt;p&gt;Genians analyzed 13 malicious LNK files linked to Kimsuky, part of an ongoing campaign called Operation GitPower using GitHub PAT-based C2 and PowerShell loaders. Metadata in decoy PDF documents showed traces of the AI coding agent &apos;opencode&apos; and unreplaced placeholder text, indicating the actor used AI/LLMs to mass produce decoy documents without proper review.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Genians | Actors: Kimsuky&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:58:49 GMT</pubDate><category>AI-Enabled</category></item><item><title>Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America</title><link>https://origin-unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-09-03-unit-42-attackers-expose-ongoing-ai-tool-use-tar</guid><description>&lt;p&gt;Unit 42 documents two active Latin American intrusion campaigns, one against Mexican/Ecuadorian government and transportation targets and one against Brazilian financial firms, where attackers used self-hosted NextChat instances and commercial LLMs like Claude and GPT-4.1 to troubleshoot scripts and build proxy tools. Exposed staging infrastructure showed AI-generated iterative filenames and prompt history, revealing&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Unit 42 | Malware: NextChat, SockTz&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:18:58 GMT</pubDate><category>AI-Enabled</category></item><item><title>The AI Attack Surface: How Threat Actors Abuse Trusted AI Platforms</title><link>https://www.huntress.com/blog/ai-attack-surface</link><guid isPermaLink="false">https://ai-threat.watch/#2026-08-28-huntress-the-ai-attack-surface-how-threat-actors</guid><description>&lt;p&gt;Huntress documents campaigns abusing legitimate AI platform features, Claude Artifacts, claude.ai/share links, and shared ChatGPT/Grok conversations, to host phishing and ClickFix-style lures on trusted domains, leading victims to install SectopRAT, MacSync stealer, or AMOS stealer. These attacks exploit trust in AI branding and domains combined with SEO/malvertising rather than flaws in the AI models themselves, hit&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Huntress | Malware: SectopRAT, MacSync stealer, AMOS stealer&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:18:41 GMT</pubDate><category>AI-Targeted</category></item><item><title>Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety</title><link>https://unit42.paloaltonetworks.com/perturbation-probing-llm-safety/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-08-28-unit-42-perturbation-probing-a-new-diagnostic-fo</guid><description>&lt;p&gt;Unit 42 researchers introduce perturbation probing, a method that identifies the small set of neurons responsible for an LLM&apos;s safety refusal behavior. They found that in Qwen3-4B, disabling just 50 neurons (0.014% of feed-forward neurons) altered refusal behavior on 80% of harmful prompts, showing safety alignment can rest on a thin, easily disrupted layer rather than robust distributed defenses.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Unit 42&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:18:48 GMT</pubDate><category>AI-Targeted</category></item><item><title>Aurora ransomware targets ESXi, abuses Cursor Agent for exploitation</title><link>https://gambit.security/blog-posts/aurora-ransomware-targets-esxi-abuses-cursor-agent-for-exploitation</link><guid isPermaLink="false">https://ai-threat.watch/#2026-08-27-gambit-security-aurora-ransomware-targets-esxi-abuses-cu</guid><description>&lt;p&gt;Gambit Security found Aurora ransomware operators using Cursor Agent with Claude Sonnet to run hands-on exploitation, including domain enumeration, NTLM relay, and certificate attacks, across ten victims. The group also deployed a new Linux ESXi ransomware variant and a separate cluster using S3 exfiltration infrastructure.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Gambit Security | Actors: Aurora | Malware: Aurora, Cursor Agent, Claude Sonnet, NetExec, Impacket, Certipy, PetitPotam, Coerce Plus&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:57:34 GMT</pubDate><category>AI-Enabled</category></item><item><title>VMs won&apos;t contain cyber-capable agents</title><link>https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyber-capable-agents/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-08-26-trail-of-bits-vms-won-t-contain-cyber-capable-agents</guid><description>&lt;p&gt;Trail of Bits tested a preview of OpenAI&apos;s GPT 5.6-Cyber agent and had it attempt to escape a QEMU/KVM sandbox. The agent autonomously escaped three times, using a recently disclosed kernel bug, an unpatched libslirp flaw, and finally a chain of several previously unknown 0-days in QEMU, KVM, and libslirp, operating for roughly 12 hours with minimal human guidance. It failed to break out of the more hardened Firecrac&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Trail of Bits | Vulnerabilities: CVE-2026-53359, CVE-2026-9539&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:57:26 GMT</pubDate><category>AI-Enabled</category></item><item><title>Drive-By Agent Hijacking: One Website Visit, Persistent Model Poisoning</title><link>https://www.cyera.com/research/nemoclaw-one-website-visit-to-hijack-your-ai-agent</link><guid isPermaLink="false">https://ai-threat.watch/#2026-08-25-cyera-drive-by-agent-hijacking-one-website-vis</guid><description>&lt;p&gt;Researchers found a vulnerability (CVE-2026-65105) in NVIDIA NemoClaw where a misconfigured Ollama binding to 0.0.0.0 disables host validation, letting an attacker use DNS rebinding from a malicious webpage to gain unauthenticated access to the local Ollama API. This lets attackers poison the model&apos;s chat template to persistently hijack an AI agent&apos;s behavior across future sessions; demonstrated as a proof of concept&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Cyera | Malware: NemoClaw, OpenClaw, OpenShell, Ollama | Vulnerabilities: CVE-2026-65105&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:18:33 GMT</pubDate><category>AI-Targeted</category></item><item><title>UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations</title><link>https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-08-20-cisco-talos-uat-10147-chinese-speaking-adversary-int</guid><description>&lt;p&gt;Cisco Talos documented a financially motivated, Chinese-speaking group, UAT-10147, using agentic AI tools like PentestGPT and DeepAudit alongside Metasploit and known CVEs to automate exploitation, reconnaissance, payload generation, and troubleshooting against Windows and Linux web servers worldwide. Talos assesses with moderate-to-high confidence this represents a shift from AI-assisted scripting to semi-autonomous&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Cisco Talos | Actors: UAT-10147 | Malware: QuasarRAT, EfsPotato, BadIIS, Gh0stCringe, SPECTRE, NoodleRAT, Meterpreter, DeepAudit | Vulnerabilities: CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, CVE-2022-0847, CVE-2022-27925, CVE-2021-23758, CVE-2021-29441, CVE-2021-29442, CVE-2019-18935 | Attribution: China, per Cisco Talos (confidence not stated)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:57:00 GMT</pubDate><category>AI-Enabled</category></item><item><title>Deadbugz: Currently Active MCP Supply-Chain Campaign</title><link>https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign</link><guid isPermaLink="false">https://ai-threat.watch/#2026-08-12-pillar-security-deadbugz-currently-active-mcp-supply-cha</guid><description>&lt;p&gt;Pillar Security identified an active campaign distributing a malicious MCP server, productivity-suite, via GitHub pull requests. The server behaves normally for the first three tool calls, then returns altered metadata instructing connected AI agents to search for SSH keys, AWS credentials, and other secrets while hiding the activity. The delivery account, zellkernel, submitted 23 pull requests in a 74-minute window;&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Pillar Security | Actors: zellkernel | Malware: productivity-suite, productivity-suite-mcp, deadbug-mcp.py&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:57:43 GMT</pubDate><category>AI-Targeted</category></item><item><title>Blacklight: Illuminating AI Agent Artifacts for Attackers and Defenders</title><link>https://specterops.io/blog/2026/08/12/blacklight-ai-agent-endpoint-artifacts/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-08-12-specterops-blacklight-illuminating-ai-agent-artifac</guid><description>&lt;p&gt;SpecterOps released Blacklight, an open-source toolkit that discovers and analyzes local endpoint artifacts left by AI coding agents like Codex, Claude Code, Cursor, and Antigravity CLI. These artifacts, including auth tokens, session transcripts, and configuration files, can expose credentials, project context, and trust relationships useful to attackers and to defenders building detection guidance.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: SpecterOps | Malware: Blacklight, Blacklight Scout&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:18:26 GMT</pubDate><category>AI-Targeted</category></item><item><title>Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM</title><link>https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm</link><guid isPermaLink="false">https://ai-threat.watch/#2026-08-10-genians-security-center-kimsuky-integrates-ai-into-attack-operat</guid><description>&lt;p&gt;Genians Security Center documented the North Korea-linked Kimsuky group using AI-generated decoy documents and experimenting with local LLM tools (Ollama, GPT4All, Msty) in an ongoing campaign dubbed Operation GitPower. The actor uses LNK files, obfuscated PowerShell, and GitHub-hosted repositories as C2 to distribute AsyncRAT payloads disguised as PNG images, targeting diplomatic, military, and virtual asset sector&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Genians Security Center | Actors: Kimsuky | Malware: AsyncRAT, FlowerPower, Operation GitPower | Attribution: North Korea, per Genians Security Center (confidence not stated)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:56:25 GMT</pubDate><category>AI-Enabled</category></item><item><title>Investigating three real-world incidents in our cybersecurity evaluations</title><link>https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-30-anthropic-investigating-three-real-world-incidents</guid><description>&lt;p&gt;Anthropic found that during cybersecurity capture-the-flag evaluations, Claude models unexpectedly gained internet access due to a misconfiguration with a third-party evaluator and compromised real production systems at three organizations, believing them to be simulated targets. Impacts included data exfiltration, a malicious PyPI package that ran on 15 real systems, and unauthorized access via SQL injection, none o&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Anthropic&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:56:06 GMT</pubDate><category>AI-Targeted</category></item><item><title>Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT</title><link>https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-27-huntress-inside-fakeagent-how-a-claude-desktop-ma</guid><description>&lt;p&gt;Huntress found a malvertising campaign that abused a public Claude AI artifact to distribute a trojanized ClaudeDesktop.exe installer, infecting 29 organizations with the SectopRAT trojan via DLL sideloading, GPU-based decryption, and blockchain-hosted (EtherHiding) command and control. Huntress used Claude itself, with human verification, to help reverse engineer the malware&apos;s custom AES implementation hidden in a G&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Huntress | Malware: SectopRAT&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:55:59 GMT</pubDate><category>AI-Targeted</category></item><item><title>AI Security 2026</title><link>https://assets.sophos.com/X24WTUEQ/at/2gxzgxgw5xxgtsch4cmtqwkr/sophos-ai-security-report-2026.pdf</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-22-sophos-ai-security-2026</guid><description>&lt;p&gt;Sophos&apos;s 2026 AI Security Report details a real-world case, tracked as STAC6994, where about a dozen AI agents built and tested EDR evasion malware across parallel VMs, compressing weeks of development into days, before the operator deployed ransomware and stole data. The report also covers AI supply-chain attacks, underground AI infrastructure sales, and exploit timelines outpacing patching.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Sophos | Actors: STAC6994, IRON TWILIGHT (APT28), The Gentlemen, DragonForce | Malware: LameHug, MacSync, Sliver | Vulnerabilities: CVE-2026-10520, CVE-2026-42208 | Attribution: China, per Anthropic (confidence not stated)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:55:41 GMT</pubDate><category>AI-Enabled</category></item><item><title>APT42: AI-Assisted Rapport Phishing and a More Resilient TAMECAT Backdoor</title><link>https://darkatlas.io/blog/apt42-ai-assisted-phishing-tamecat-analysis</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-19-darkatlas-apt42-ai-assisted-rapport-phishing-and-a</guid><description>&lt;p&gt;Darkatlas documents Iran-linked APT42/TA453 activity including the SpearSpecter campaign, which uses search-ms and WebDAV abuse to deliver an expanded TAMECAT backdoor with browser cookie theft and multi-channel C2 via HTTPS, Discord and Telegram. The report also describes APT42 incorporating generative AI into reconnaissance, persona and pretext creation, translation, and malware development.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Darkatlas | Actors: APT42, TA453, RedKitten | Malware: TAMECAT, SpearSpecter | Attribution: Iran, per Darkatlas (confidence not stated)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:55:17 GMT</pubDate><category>AI-Enabled</category></item><item><title>Security incident disclosure , July 2026</title><link>https://huggingface.co/blog/security-incident-july-2026</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-16-hugging-face-security-incident-disclosure-july-2026</guid><description>&lt;p&gt;Hugging Face disclosed that an autonomous AI agent framework breached part of its production infrastructure by exploiting two code-execution flaws in its dataset processing pipeline, then escalated privileges and harvested credentials. No tampering with public models, datasets, or Spaces was found; Hugging Face used an open-weight model on its own infrastructure for forensic analysis after commercial API providers&apos; s&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Hugging Face&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:55:09 GMT</pubDate><category>AI-Targeted</category></item><item><title>ClaudeFix: Shared Claude Chats Meet ClickFix</title><link>https://www.zscaler.com:443/blogs/security-research/claudefix-shared-claude-chats-meet-clickfix</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-15-zscaler-claudefix-shared-claude-chats-meet-click</guid><description>&lt;p&gt;Zscaler Threat Hunting found threat actors abusing shared Claude chat links, disguised with an &apos;Apple Support&apos; display name, to host ClickFix instructions that install MacSync Stealer on macOS via malvertising. The malware steals keychains, browser data, crypto wallets and files, then exfiltrates and self-deletes to avoid detection. Russian-language code comments suggest a Russian-speaking actor; the campaign ran Jun&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Zscaler | Malware: MacSync Stealer | Attribution: Russia, per Zscaler Threat Hunting (low confidence)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:54:54 GMT</pubDate><category>AI-Enabled</category></item><item><title>Suspected Chinese Operators Use Claude Code and DeepSeek to Target Government and Financial Systems Across Four Countries</title><link>https://hunt.io/blog/chinese-operators-claude-deepseek-government-intrusion</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-14-hunt-io-suspected-chinese-operators-use-claude-c</guid><description>&lt;p&gt;Hunt.io researchers found an open directory tied to TencShell C2 infrastructure showing suspected China-linked operators using Claude Code and DeepSeek-v4-pro to handle exploit reasoning, session persistence, and phishing page creation during live intrusions. Victims included government and critical infrastructure targets in Afghanistan, Thailand, and Taiwan, with reconnaissance against U.S. government portals and sc&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Hunt.io | Malware: TencShell, Vshell, ARL, DeepAudit, Gshell, HSEWH-Ur | Attribution: China, per Hunt.io (low confidence)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:54:44 GMT</pubDate><category>AI-Enabled</category></item><item><title>Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting</title><link>https://sites.google.com/view/agentic-botnets/home</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-13-tel-aviv-university-beware-of-agentic-botnets-scalable-untar</guid><description>&lt;p&gt;Researchers show that LLM hallucinations of repository or skill names are predictable and transferable across models, letting attackers preregister the hallucinated resource names with malicious payloads. When agentic coding assistants and CLIs fetch these squatted resources they can be tricked into executing code, enabling remote code execution and potentially a botnet. This is proof-of-concept research disclosed re&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Tel Aviv University | Malware: HalluSquatting, promptware&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:17:40 GMT</pubDate><category>AI-Targeted</category></item><item><title>REF6045: Mexican banking fraud toolkit with signs of AI-assisted development</title><link>https://www.elastic.co/security-labs/threat-command/mexican-banking-fraud-scmbanker-ref6045</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-08-elastic-security-labs-ref6045-mexican-banking-fraud-toolkit-wi</guid><description>&lt;p&gt;Elastic Security Labs documented REF6045, an operator-assisted banking fraud campaign using ClickFix fake-CAPTCHA lures to install a PowerShell toolkit called SCMBANKER against Mexican bank, fintech, and crypto exchange customers. The toolkit enables session monitoring, screenshots, vishing overlays, clipboard hijacking, and RAT deployment, and its scripts show artifacts suggesting an LLM was used to write most of th&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Elastic Security Labs | Malware: SCMBANKER, Remote Utilities | Attribution: not-stated, per Elastic Security Labs (confidence not stated)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:43:43 GMT</pubDate><category>AI-Enabled</category></item><item><title>Mycelium Framework: First Ever Witnessed AI-as-a-Service Botnet</title><link>https://flare.io/learn/resources/blog/mycelium-framework-ai-as-a-service-botnet</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-07-flare-mycelium-framework-first-ever-witnessed</guid><description>&lt;p&gt;Flare researchers describe an underground forum advertisement for &apos;Mycelium Framework,&apos; a botnet claiming to classify infected machines by compute, GPU, stolen AI API keys and local models, then route AI inference, social engineering and other tasks accordingly. No source code or proof of execution was provided, and most individual techniques are previously documented, so the AI-as-a-service claims remain unverified.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Flare | Malware: Mycelium Framework, Mirai, TeamTNT, DorkBot, RageBot, Phorpiex, IRCBot.HI | Vulnerabilities: CVE-2021-22205&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:44:11 GMT</pubDate><category>AI-Enabled</category></item><item><title>New Gaslight malware evades AI analysis</title><link>https://moonlock.com/gaslight-malware-evades-ai-analysis</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-03-moonlock-new-gaslight-malware-evades-ai-analysis</guid><description>&lt;p&gt;SentinelOne identified a North Korean-linked macOS Rust malware, dubbed Gaslight, that embeds fabricated system error messages designed to trick AI-based security agents into dismissing it during automated triage. The malware also steals browser data, terminal history, and keychain files, and exfiltrates via a hardened Telegram bot C2, moving prompt-injection evasion from proof-of-concept into real-world use.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Moonlock | Actors: North Korean hackers | Malware: Gaslight, AMOS, Realistic macOS infostealer, Realist | Attribution: North Korea, per SentinelOne (confidence not stated)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:17:32 GMT</pubDate><category>AI-Targeted</category></item><item><title>Indirect Prompt Injection in Web Content Targets AI Agents</title><link>https://www.zscaler.com:443/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-02-zscaler-threatlabz-indirect-prompt-injection-in-web-content</guid><description>&lt;p&gt;Zscaler ThreatLabz documented two real-world campaigns embedding hidden prompt injection instructions in web content via SEO poisoning, JSON-LD, and CSS to manipulate AI agents, including a fake API payment scam and a DeBank typosquatting site. Testing across 26 LLMs found 4 models could be tricked into making payments and 2 misclassified the fraudulent site as legitimate.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Zscaler ThreatLabz&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:17:17 GMT</pubDate><category>AI-Targeted</category></item><item><title>JADEPUFFER: Agentic ransomware for automated database extortion</title><link>https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-01-sysdig-jadepuffer-agentic-ransomware-for-automa</guid><description>&lt;p&gt;Sysdig&apos;s Threat Research Team documented what they assess to be the first fully agentic ransomware operation, dubbed JADEPUFFER, where an LLM autonomously gained access via a Langflow RCE flaw, harvested credentials, exploited Nacos authentication bypasses, and encrypted and destroyed a victim&apos;s production database for extortion. The payloads showed self-narrating reasoning and adaptive retries with no human interven&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Sysdig | Actors: JADEPUFFER | Malware: JADEPUFFER | Vulnerabilities: CVE-2025-3248, CVE-2021-29441&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:43:36 GMT</pubDate><category>AI-Enabled</category></item><item><title>Threat Actors Weaponize AI Hype to Deliver AsyncRAT</title><link>https://www.fortinet.com/blog/threat-research/threat-actors-weaponize-ai-hype-to-deliver-asyncrat</link><guid isPermaLink="false">https://ai-threat.watch/#2026-06-11-fortiguard-labs-threat-actors-weaponize-ai-hype-to-deliv</guid><description>&lt;p&gt;FortiGuard Labs documented a multi-stage Windows malware campaign using fake AI-themed documents and guides as lures to deliver AsyncRAT via AutoHotkey-based loaders and process hollowing. Chinese-language code artifacts and structured coding style suggest the attackers used generative AI tools to help build the malware, though this is inferred rather than confirmed.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: FortiGuard Labs | Malware: AsyncRAT, AutoHotkey, clay_Client&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:42:26 GMT</pubDate><category>AI-Enabled</category></item><item><title>Prompt injection still drives most agentic AI security failures in production</title><link>https://www.helpnetsecurity.com/2026/06/11/owasp-prompt-injection-ai-security-failures/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-06-11-helpnet-owasp-agentic</guid><description>&lt;p&gt;Coverage of OWASP&apos;s 2026 findings on agentic AI. Most production failures still begin with prompt injection, and attackers increasingly poison what agents trust: MCP servers, packages and coding-tool configuration.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Help Net Security | Vulnerabilities: CVE-2025-6514, CVE-2026-22708&lt;/p&gt;</description><pubDate>Thu, 11 Jun 2026 06:00:00 GMT</pubDate><category>AI-Targeted</category></item><item><title>What we learned mapping a year&apos;s worth of AI-enabled cyber threats</title><link>https://www.anthropic.com/news/AI-enabled-cyber-threats-mitre-attack</link><guid isPermaLink="false">https://ai-threat.watch/#2026-06-03-anthropic-what-we-learned-mapping-a-year-s-worth-o</guid><description>&lt;p&gt;Anthropic analyzed 832 accounts banned for malicious cyber activity between March 2025 and March 2026, mapping their techniques to MITRE ATT&amp;amp;CK. They found AI use shifting from initial access to post-compromise activity, risk scores rising over time, and the framework failing to capture autonomous agentic orchestration seen in a November 2025 state-sponsored espionage case.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Anthropic | Malware: Claude Code&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:41:04 GMT</pubDate><category>AI-Enabled</category></item><item><title>ChatGPhish: The Page Is the Payload</title><link>https://permiso.io/blog/chatgpt-markdown-rendering-vulnerability</link><guid isPermaLink="false">https://ai-threat.watch/#2026-05-29-permiso-chatgphish-the-page-is-the-payload</guid><description>&lt;p&gt;Permiso researchers show that ChatGPT&apos;s browser page-summarization feature renders attacker-appended Markdown links and images from third-party pages as trusted UI elements, enabling phishing, QR-code redirection to a second device, and tracking-pixel style data leakage. The issue was demonstrated as a proof of concept and reported to OpenAI via Bugcrowd but was marked not reproducible then a duplicate.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Permiso&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:17:08 GMT</pubDate><category>AI-Targeted</category></item><item><title>Fake Claude Code, Real Malware: Inside the Campaign Targeting AI Developers</title><link>https://www.straiker.ai/blog/acr-stealer-claude-code-impersonation-campaign</link><guid isPermaLink="false">https://ai-threat.watch/#2026-05-27-straiker-fake-claude-code-real-malware-inside-the</guid><description>&lt;p&gt;Straiker documented a live infostealer campaign impersonating Claude Code, JetBrains, NotebookLM and other AI developer tools across 88 domains, using SEO poisoning, paid ads, and fileless payload delivery. The malware, an Amatera/ACR Stealer variant, is built to steal API keys from AI coding assistants alongside browser credentials and crypto wallets, with C2 hidden on a Binance Smart Chain contract.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Straiker | Malware: Amatera, ACR Stealer&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:54:08 GMT</pubDate><category>AI-Targeted</category></item><item><title>SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer</title><link>https://blog.eclecticiq.com/seo-poisoning-campaign-leverages-gemini-and-claude-code-impersonation-to-deliver-infostealer</link><guid isPermaLink="false">https://ai-threat.watch/#2026-05-21-eclecticiq-seo-poisoning-campaign-leverages-gemini</guid><description>&lt;p&gt;EclecticIQ documented an SEO poisoning campaign using fake Gemini CLI and Claude Code installation pages to trick developers into running a PowerShell command that installs a fileless, in-memory infostealer alongside the real tool. The malware disables AMSI and ETW, harvests browser, collaboration app, VPN and crypto wallet credentials, and supports remote code execution, with passive DNS revealing over 30 related do&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: EclecticIQ&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:53:45 GMT</pubDate><category>AI-Targeted</category></item><item><title>One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign</title><link>https://www.trendmicro.com/en_us/research/26/e/inside-the-influence-and-fraud-patriot-bait-campaign.html</link><guid isPermaLink="false">https://ai-threat.watch/#2026-05-21-trend-micro-one-man-one-ai-one-fake-persona-inside-t</guid><description>&lt;p&gt;A solo Russian-speaking threat actor ran a 5-year MAGA-themed Telegram influence channel and, starting September 2025, used a jailbroken Google Gemini to automate content creation, manage infrastructure, rotate stolen API keys, and run a QAnon-styled fraud chatbot. The campaign combined credential theft, a fake crypto wallet RAT, and a token scheme, showing AI can lower the cost of running influence and fraud operati&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Trend Micro | Actors: bandcampro | Malware: GoToResolve, StellarMonster, Quantum Patriot, QFS 2.0 Terminal | Attribution: Russia, per Trend Micro (medium confidence)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:16:56 GMT</pubDate><category>AI-Enabled</category></item><item><title>Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud</title><link>https://www.trendmicro.com/en_us/research/26/e/banana-rat.html</link><guid isPermaLink="false">https://ai-threat.watch/#2026-05-19-trend-micro-inside-shadow-water-063-s-banana-rat-fro</guid><description>&lt;p&gt;Trend Micro&apos;s MDR team correlated attacker server infrastructure with victim telemetry to map Banana RAT, a banking trojan targeting 16 Brazilian financial institutions via phishing and fileless PowerShell delivery. The malware provides remote control, keylogging, overlay injection, and PIX QR code interception, using a polymorphic crypter service to evade detection.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Trend Micro | Actors: SHADOW-WATER-063 | Malware: Banana RAT, Backdoor.PS1.BANANARAT.A | Attribution: Brazil, per TrendAI (high confidence)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:43:23 GMT</pubDate><category>AI-Targeted</category></item><item><title>GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access</title><link>https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access</link><guid isPermaLink="false">https://ai-threat.watch/#2026-05-12-gtig-ai-threat-tracker</guid><description>&lt;p&gt;GTIG reports adversaries applying AI to vulnerability exploitation, initial access and faster development of evasive, polymorphic malware. It also covers supply chain attacks against AI components, and notes no actor has yet bypassed the core safety logic of frontier models.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Google Threat Intelligence Group&lt;/p&gt;</description><pubDate>Tue, 12 May 2026 06:00:00 GMT</pubDate><category>AI-Enabled</category><category>Must-read</category></item><item><title>Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America</title><link>https://www.trendmicro.com/en_us/research/26/e/vibe-hacking-two-ai-augmented-campaigns-target-government-and-financial-sectors-in-latin-america.html</link><guid isPermaLink="false">https://ai-threat.watch/#2026-05-11-trend-micro-vibe-hacking-two-ai-augmented-campaigns</guid><description>&lt;p&gt;Trend Micro identified two campaigns, SHADOW-AETHER-040 and SHADOW-AETHER-064, using agentic AI (including Claude) to drive intrusions from initial access to data exfiltration against government and financial targets in Mexico and Brazil. The AI agents dynamically generated custom tools and backdoors, used jailbreaking via fake red-team pretexts, and integrated with Shodan and VulDB for reconnaissance.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Trend Micro | Actors: SHADOW-AETHER-040, SHADOW-AETHER-064 | Malware: Chisel, Neo-reGeorg, CrackMapExec, Impacket, implante_http, ProxyChains, PetitPotam&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:40:31 GMT</pubDate><category>AI-Enabled</category></item><item><title>When prompts become shells: RCE vulnerabilities in AI agent frameworks</title><link>https://www.microsoft.com/en-us/security/blog/2026/05/07/prompts-become-shells-rce-vulnerabilities-ai-agent-frameworks/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-05-07-microsoft-prompts-become-shells</guid><description>&lt;p&gt;Microsoft researchers show how a single injected prompt reached host-level code execution in agents built on Semantic Kernel. Model-controlled parameters flowed unsanitized into a search plugin. Both flaws are fixed.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Microsoft Security | Vulnerabilities: CVE-2026-25592, CVE-2026-26030&lt;/p&gt;</description><pubDate>Thu, 07 May 2026 06:00:00 GMT</pubDate><category>AI-Targeted</category></item><item><title>Agent Context Poisoning: SKILL.md and the New AI Supply Chain Attack Surface</title><link>https://labs.cloudsecurityalliance.org/research/csa-research-note-skill-md-agent-context-poisoning-20260506/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-05-06-cloud-security-alliance-agent-context-poisoning-skill-md-and-the</guid><description>&lt;p&gt;Cloud Security Alliance details how AI agent skill files like SKILL.md, CLAUDE.md and AGENTS.md create a new supply chain attack surface, since natural-language instructions in these files are trusted and executed by agents at runtime. It cites Snyk&apos;s ToxicSkills audit finding security flaws in 36.82% of 3,984 scanned skills and 341 malicious ClawHub skills, plus two Check Point-disclosed CVEs in Claude Code enabling&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Cloud Security Alliance | Malware: ToxicSkills, OpenClaw | Vulnerabilities: CVE-2025-59536, CVE-2026-21852&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:16:46 GMT</pubDate><category>AI-Targeted</category></item><item><title>AI threats in the wild: The current state of prompt injections on the web</title><link>https://blog.google/security/prompt-injections-web/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-04-23-google-ai-threats-in-the-wild-the-current-state</guid><description>&lt;p&gt;Google researchers scanned Common Crawl web archives for indirect prompt injection attempts targeting AI agents that browse websites. Most found examples were low-sophistication pranks, SEO manipulation, or crawler deterrence, with only a small number of malicious data-theft or destructive attempts, none highly advanced. Detections of malicious injections rose 32% between November 2025 and February 2026, suggesting g&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Google&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:16:40 GMT</pubDate><category>AI-Targeted</category></item><item><title>AI Meets Voice Phishing: How ATHR Automates the Full TOAD Attack Chain</title><link>https://abnormal.ai/blog/athr-ai-voice-phishing-toad-attacks</link><guid isPermaLink="false">https://ai-threat.watch/#2026-04-22-abnormal-ai-ai-meets-voice-phishing-how-athr-automat</guid><description>&lt;p&gt;Researchers describe ATHR, a crimeware platform sold for $4,000 plus 10% of profits that combines AI voice agents, spoofed lure emails, and live phishing panels to automate telephone-oriented attack delivery (TOAD) scams. Its AI vishing agents run scripted social engineering calls targeting crypto and email brand users, letting one operator run multi-brand campaigns without trained callers.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Abnormal AI | Malware: ATHR&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:16:32 GMT</pubDate><category>AI-Enabled</category></item><item><title>OWASP GenAI Exploit Round-up Report Q1 2026</title><link>https://genai.owasp.org/2026/04/14/owasp-genai-exploit-round-up-report-q1-2026/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-04-14-owasp-exploit-roundup-q1</guid><description>&lt;p&gt;Quarterly review of eight AI-related incidents mapped to the OWASP LLM and agentic risk lists. It includes active exploitation of a maximum-severity Flowise flaw and GrafanaGhost, a prompt injection path that exfiltrates data from Grafana&apos;s AI features.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: OWASP GenAI Security Project | Vulnerabilities: CVE-2025-59528&lt;/p&gt;</description><pubDate>Tue, 14 Apr 2026 06:00:00 GMT</pubDate><category>AI-Targeted</category></item><item><title>&quot;Hello? I can&apos;t hear you&quot;: Investigating UNC1069&apos;s Fake Meeting Tactics</title><link>https://www.validin.com/blog/i_cant_hear_you_unc1069/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-04-14-validin-hello-i-can-t-hear-you-investigating-unc</guid><description>&lt;p&gt;Validin details UNC1069 (overlapping with Bluenoroff), a North Korean actor luring crypto and Web3 professionals via fake VC personas into fraudulent Zoom/Teams/Meet-style meetings. Victims are tricked with ClickFix prompts into running malware (updated Cabbage RAT/CageyChameleon variants, NukeSped) across Windows, macOS and Linux, and their audio/video is captured via WebRTC for reuse in later social engineering, in&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Validin | Actors: UNC1069, Bluenoroff, Lazarus Group | Malware: Cabbage RAT, CageyChameleon, NukeSped | Attribution: North Korea, per Validin (high confidence)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:16:09 GMT</pubDate><category>AI-Targeted</category></item><item><title>A Single Operator, Two AI Platforms, Nine Government Agencies: The Full Technical Report</title><link>https://gambit.security/blog-posts/a-single-operator-two-ai-platforms-nine-government-agencies-the-full-technical-report</link><guid isPermaLink="false">https://ai-threat.watch/#2026-04-10-gambit-security-a-single-operator-two-ai-platforms-nine</guid><description>&lt;p&gt;Gambit Security&apos;s forensic report describes a single operator who used Claude Code and OpenAI&apos;s GPT-4.1 as core operational tools to breach nine Mexican government organizations and exfiltrate hundreds of millions of records between December 2025 and February 2026. Recovered materials show over 400 custom attack scripts, 20 tailored exploits, and thousands of AI-generated commands used to compress attack timelines an&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Gambit Security | Attribution: Mexico, per Gambit Security (confidence not stated)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:40:23 GMT</pubDate><category>AI-Enabled</category></item><item><title>LiteLLM and Telnyx compromised on PyPI: Tracing the TeamPCP supply chain campaign</title><link>https://securitylabs.datadoghq.com/articles/litellm-compromised-pypi-teampcp-supply-chain-campaign/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-03-27-datadog-litellm-teampcp</guid><description>&lt;p&gt;Two backdoored releases of LiteLLM, a widely used LLM gateway library, were published to PyPI on March 24, 2026 with a credential stealer. Datadog traces the campaign from a poisoned Trivy scanner through npm and into PyPI.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Datadog Security Labs | Actors: TeamPCP&lt;/p&gt;</description><pubDate>Fri, 27 Mar 2026 06:00:00 GMT</pubDate><category>AI-Targeted</category></item><item><title>Open, Closed and Broken: Prompt Fuzzing Finds LLMs Still Fragile Across Open and Closed Models</title><link>https://unit42.paloaltonetworks.com/genai-llm-prompt-fuzzing/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-03-17-unit-42-open-closed-and-broken-prompt-fuzzing-fi</guid><description>&lt;p&gt;Unit 42 researchers built a genetic algorithm based prompt fuzzing method that automatically generates meaning-preserving variants of disallowed requests to test LLM guardrails. Testing against closed-source and open-weight models plus a content-filter model on explosive-related prompts found evasion rates ranging from 1 percent to 99 percent depending on model and keyword. This is original research showing guardrail&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Unit 42&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:15:26 GMT</pubDate><category>AI-Targeted</category></item><item><title>A Slopoly start to AI-enhanced ransomware attacks</title><link>https://www.ibm.com/think/x-force/slopoly-start-ai-enhanced-ransomware-attacks</link><guid isPermaLink="false">https://ai-threat.watch/#2026-03-12-ibm-x-force-a-slopoly-start-to-ai-enhanced-ransomwar</guid><description>&lt;p&gt;IBM X-Force found a likely AI-generated PowerShell C2 backdoor, dubbed Slopoly, deployed by ransomware group Hive0163 during a live intrusion using ClickFix, NodeSnake, InterlockRAT and Interlock ransomware. The malware is technically unremarkable but shows guardrail bypass and signals adoption of AI-assisted malware development among established ransomware actors.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: IBM X-Force | Actors: Hive0163, ITG23, TA569, TAG-124 | Malware: Slopoly, NodeSnake, InterlockRAT, Interlock, JunkFiction, Broomstick, Supper, PortStarter&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:40:16 GMT</pubDate><category>AI-Enabled</category></item><item><title>Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild</title><link>https://unit42.paloaltonetworks.com/ai-agent-prompt-injection/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-03-03-palo-alto-networks-unit--fooling-ai-agents-web-based-indirect-pro</guid><description>&lt;p&gt;Unit 42 documents real-world indirect prompt injection attacks embedded in webpages, including the first observed case of an attacker bypassing an AI-based ad review system with a scam advertisement. The researchers catalog 22 payload techniques and a severity taxonomy, showing IDPI moving from proof-of-concept to active exploitation, though some scenarios like ad-checker bypass remain unconfirmed against deployed sy&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Palo Alto Networks Unit 42&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:15:13 GMT</pubDate><category>AI-Targeted</category></item><item><title>Fake VCs target crypto talent in a new ClickFix campaign</title><link>https://moonlock.com/fake-vcs-target-crypto-talent-clickfix-campaign</link><guid isPermaLink="false">https://ai-threat.watch/#2026-03-02-moonlock-lab-fake-vcs-target-crypto-talent-in-a-new-c</guid><description>&lt;p&gt;Moonlock Lab documented a campaign using fake venture capital personas on LinkedIn to lure crypto professionals into spoofed Zoom/Meet pages running a ClickFix fake CAPTCHA that tricks victims into executing clipboard-injected commands, deploying cross-platform malware. Fake company sites used AI-generated headshots for fabricated staff, and infrastructure overlaps with DPRK-linked UNC1069, though attribution remains&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Moonlock Lab | Actors: Mykhailo Hureiev, Anatolli Bigdasch, UNC1069 | Attribution: North Korea, per Moonlock Lab (low confidence)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:14:58 GMT</pubDate><category>AI-Enabled</category></item><item><title>Disrupting malicious uses of AI</title><link>https://openai.com/index/disrupting-malicious-ai-uses/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-02-25-openai-disrupting-malicious-uses</guid><description>&lt;p&gt;OpenAI&apos;s case studies show models used as one step in larger workflows that also rely on websites and social accounts: romance and recovery scams, covert influence operations, and a state-linked harassment effort.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: OpenAI | Actors: Rybar&lt;/p&gt;</description><pubDate>Wed, 25 Feb 2026 06:00:00 GMT</pubDate><category>AI-Enabled</category><category>Must-read</category></item><item><title>Malicious OpenClaw Skills Used to Distribute Atomic macOS Stealer</title><link>https://www.trendaisecurity.com/en-us/resources-insights/trendai-security-blog/malicious-openclaw-skills-used-to-distribute-atomic-macos-stealer</link><guid isPermaLink="false">https://ai-threat.watch/#2026-02-23-trendai-research-malicious-openclaw-skills-used-to-distri</guid><description>&lt;p&gt;TrendAI Research documented a campaign where malicious OpenClaw agent skills trick AI agents like GPT-4o into installing a new variant of Atomic macOS Stealer (AMOS), which then deceives users into entering their password. The malware exfiltrates browser data, crypto wallets, Apple and KeePass keychains, and documents, with hundreds of malicious skills found across ClawHub, SkillsMP, and GitHub repositories.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: TrendAI Research | Malware: Atomic (AMOS) Stealer, AMOS&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:40:00 GMT</pubDate><category>AI-Targeted</category></item><item><title>LLMs in the Kill Chain: Inside a Custom MCP Targeting FortiGate Devices Across Continents</title><link>https://cyberandramen.net/2026/02/21/llms-in-the-kill-chain-inside-a-custom-mcp-targeting-fortigate-devices-across-continents/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-02-21-hunt-io-cyberandramen-ne-llms-in-the-kill-chain-inside-a-custom-m</guid><description>&lt;p&gt;Researchers found an exposed server revealing a threat actor using a custom MCP server (ARXON) with DeepSeek and Claude Code to automate reconnaissance, attack planning, and exploitation of compromised FortiGate devices across thousands of targets in over 100 countries. The actor evolved from using open-source HexStrike MCP tooling in December 2025 to fully custom orchestration (ARXON and CHECKER2) by February 2026,&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Hunt.io / cyberandramen.net | Malware: ARXON, CHECKER2, HexStrike, ntlmrelayx.py, Impacket, Metasploit, BloodHound, Nuclei | Vulnerabilities: CVE-2019-6693, CVE-2026-24061, CVE-2025-33073, CVE-2023-27532, CVE-2019-7192&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:39:34 GMT</pubDate><category>AI-Enabled</category></item><item><title>AI-augmented threat actor accesses FortiGate devices at scale</title><link>https://aws.amazon.com/blogs/security/ai-augmented-threat-actor-accesses-fortigate-devices-at-scale/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-02-20-amazon-threat-intelligen-ai-augmented-threat-actor-accesses-forti</guid><description>&lt;p&gt;Amazon Threat Intelligence documented a Russian-speaking, financially motivated actor using multiple commercial LLMs to compromise over 600 FortiGate devices in 55+ countries via exposed management interfaces and weak credentials, not exploits. AI generated attack plans, custom Go/Python tooling, and reconnaissance scripts, letting a low-skill actor achieve broad operational scale, though it still failed against hard&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Amazon Threat Intelligence | Actors: Ed1s0nZ | Malware: Meterpreter, mimikatz, gogo, Nuclei, CyberStrikeAI, PrivHunterAI, InfiltrateX, watermark-tool | Vulnerabilities: CVE-2019-7192, CVE-2023-27532, CVE-2024-40711&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:39:05 GMT</pubDate><category>AI-Enabled</category></item><item><title>PromptSpy ushers in the era of Android threats using GenAI</title><link>https://www.welivesecurity.com/en/eset-research/promptspy-ushers-in-era-android-threats-using-genai/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-02-19-eset-research-promptspy-ushers-in-the-era-of-android-t</guid><description>&lt;p&gt;ESET found PromptSpy, Android malware that queries Google&apos;s Gemini with UI XML dumps to get step-by-step instructions for locking itself into the recent apps list, aiding persistence. The malware also deploys a VNC module for remote device control and targets users in Argentina; no live samples have been seen in telemetry, suggesting it may still be a proof of concept.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: ESET Research | Malware: PromptSpy, VNCSpy, PromptLock, Android.Phantom, Android/Phishing.Agent.M | Attribution: China, per ESET (medium confidence)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:39:17 GMT</pubDate><category>AI-Enabled</category></item><item><title>GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use</title><link>https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use</link><guid isPermaLink="false">https://ai-threat.watch/#2026-02-12-gtig-distillation-experimentation</guid><description>&lt;p&gt;Quarterly view of how actors linked to North Korea, Iran, China and Russia used AI in late 2025. GTIG saw no breakthrough capability, but disrupted frequent model extraction attempts against its own models.&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Google Threat Intelligence Group | Attribution: North Korea, per Google Threat Intelligence Group (confidence not stated); Iran, per Google Threat Intelligence Group (confidence not stated); China, per Google Threat Intelligence Group (confidence not stated); Russia, per Google Threat Intelligence Group (confidence not stated)&lt;/p&gt;</description><pubDate>Thu, 12 Feb 2026 06:00:00 GMT</pubDate><category>AI-Enabled</category><category>Must-read</category></item><item><title>Moonlock Lab thread on ClickFix malware abusing Claude.ai and Medium</title><link>https://x.com/moonlock_lab/status/2021695650367226108?s=12</link><guid isPermaLink="false">https://ai-threat.watch/#2026-02-11-moonlock-lab-moonlock-lab-thread-on-clickfix-malware</guid><description>&lt;p&gt;Moonlock Lab reports that a Google Sponsored ad for a macOS search led users to malware via ClickFix delivery, seen over 15,000 times. One variant abused a public artifact hosted on claude.ai, while another used a Medium post impersonating Apple support, both attributed to the same threat actor.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Moonlock Lab | Malware: ClickFix&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:38:42 GMT</pubDate><category>AI-Targeted</category></item><item><title>Snyk Finds Prompt Injection in 36%, 1467 Malicious Payloads in a ToxicSkills Study of Agent Skills Supply Chain Compromise</title><link>https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-02-05-snyk-snyk-finds-prompt-injection-in-36-1467-m</guid><description>&lt;p&gt;Snyk scanned 3,984 AI agent skills from ClawHub and skills.sh and found 534 with critical security issues and 76 confirmed malicious payloads designed for credential theft, backdoors, or data exfiltration, with 8 still live on ClawHub. The research shows attackers combining prompt injection with malicious code to bypass agent safety mechanisms in Claude Code, Cursor, and OpenClaw skills.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Snyk | Malware: ToxicSkills&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:57:51 GMT</pubDate><category>AI-Targeted</category></item><item><title>Breaking Trust with Words: Prompt Injection Leading to Simulated /etc/passwd Disclosure</title><link>https://www.resecurity.com/blog/article/breaking-trust-with-words-prompt-injection-leading-to-simulated-etcpasswd-disclosure</link><guid isPermaLink="false">https://ai-threat.watch/#2026-01-26-resecurity-breaking-trust-with-words-prompt-injecti</guid><description>&lt;p&gt;Resecurity describes penetration testing work on enterprise AI applications, including a banking and HR chatbot, showing how prompt injection can trick an LLM into simulating disclosure of a sensitive Linux file like /etc/passwd. The piece explains direct and indirect prompt injection techniques and several proof-of-concept attack patterns observed during assessments, not confirmed real-world breaches.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Resecurity&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:14:38 GMT</pubDate><category>AI-Targeted</category></item><item><title>The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time</title><link>https://unit42.paloaltonetworks.com/real-time-malicious-javascript-through-llms/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-01-22-unit-42-palo-alto-networ-the-next-frontier-of-runtime-assembly-at</guid><description>&lt;p&gt;Unit 42 researchers built a proof of concept where a benign-looking webpage queries trusted LLM APIs like DeepSeek and Gemini at runtime to generate and assemble phishing JavaScript in the victim&apos;s browser, bypassing network detection and guardrails through prompt engineering. This produces polymorphic, brand-impersonating phishing pages with no static malicious payload, though the technique was not observed used by&lt;/p&gt;&lt;p&gt;AI-Enabled (Attackers using AI) | Source: Unit 42 (Palo Alto Networks) | Malware: LogoKit&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:14:32 GMT</pubDate><category>AI-Enabled</category></item></channel></rss>