<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>AI Threat Watch: AI-Targeted</title><description>An automated watch on attackers using AI and on attacks against AI systems. Short summaries, direct links to the source.</description><link>https://ai-threat.watch/</link><language>en</language><ttl>360</ttl><item><title>Infostealers Have Found a New Target: Your AI Agent</title><link>https://www.gendigital.com/blog/insights/research/infostealers-your-ai-agent</link><guid isPermaLink="false">https://ai-threat.watch/#2026-09-09-gen-digital-infostealers-have-found-a-new-target-you</guid><description>&lt;p&gt;Gen Digital&apos;s telemetry shows infostealers like Amatera, Remus, CallbackBeaver, and Djinn Stealer have added AI coding agents (Claude, Cursor, Codex, Cline, OpenCode) to their collection rules, harvesting tokens, MCP credentials, and prompt histories. This expands the infostealer economy to target local AI agent data as a new high-value asset alongside browser and wallet credentials.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Gen Digital | Malware: Amatera, Remus, CallbackBeaver, BeeStealer, STG Stealer, HydraStealer, APEX Stealer, Otter Stealer&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:59:04 GMT</pubDate><category>AI-Targeted</category></item><item><title>The AI Attack Surface: How Threat Actors Abuse Trusted AI Platforms</title><link>https://www.huntress.com/blog/ai-attack-surface</link><guid isPermaLink="false">https://ai-threat.watch/#2026-08-28-huntress-the-ai-attack-surface-how-threat-actors</guid><description>&lt;p&gt;Huntress documents campaigns abusing legitimate AI platform features, Claude Artifacts, claude.ai/share links, and shared ChatGPT/Grok conversations, to host phishing and ClickFix-style lures on trusted domains, leading victims to install SectopRAT, MacSync stealer, or AMOS stealer. These attacks exploit trust in AI branding and domains combined with SEO/malvertising rather than flaws in the AI models themselves, hit&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Huntress | Malware: SectopRAT, MacSync stealer, AMOS stealer&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:18:41 GMT</pubDate><category>AI-Targeted</category></item><item><title>Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety</title><link>https://unit42.paloaltonetworks.com/perturbation-probing-llm-safety/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-08-28-unit-42-perturbation-probing-a-new-diagnostic-fo</guid><description>&lt;p&gt;Unit 42 researchers introduce perturbation probing, a method that identifies the small set of neurons responsible for an LLM&apos;s safety refusal behavior. They found that in Qwen3-4B, disabling just 50 neurons (0.014% of feed-forward neurons) altered refusal behavior on 80% of harmful prompts, showing safety alignment can rest on a thin, easily disrupted layer rather than robust distributed defenses.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Unit 42&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:18:48 GMT</pubDate><category>AI-Targeted</category></item><item><title>Drive-By Agent Hijacking: One Website Visit, Persistent Model Poisoning</title><link>https://www.cyera.com/research/nemoclaw-one-website-visit-to-hijack-your-ai-agent</link><guid isPermaLink="false">https://ai-threat.watch/#2026-08-25-cyera-drive-by-agent-hijacking-one-website-vis</guid><description>&lt;p&gt;Researchers found a vulnerability (CVE-2026-65105) in NVIDIA NemoClaw where a misconfigured Ollama binding to 0.0.0.0 disables host validation, letting an attacker use DNS rebinding from a malicious webpage to gain unauthenticated access to the local Ollama API. This lets attackers poison the model&apos;s chat template to persistently hijack an AI agent&apos;s behavior across future sessions; demonstrated as a proof of concept&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Cyera | Malware: NemoClaw, OpenClaw, OpenShell, Ollama | Vulnerabilities: CVE-2026-65105&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:18:33 GMT</pubDate><category>AI-Targeted</category></item><item><title>Deadbugz: Currently Active MCP Supply-Chain Campaign</title><link>https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign</link><guid isPermaLink="false">https://ai-threat.watch/#2026-08-12-pillar-security-deadbugz-currently-active-mcp-supply-cha</guid><description>&lt;p&gt;Pillar Security identified an active campaign distributing a malicious MCP server, productivity-suite, via GitHub pull requests. The server behaves normally for the first three tool calls, then returns altered metadata instructing connected AI agents to search for SSH keys, AWS credentials, and other secrets while hiding the activity. The delivery account, zellkernel, submitted 23 pull requests in a 74-minute window;&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Pillar Security | Actors: zellkernel | Malware: productivity-suite, productivity-suite-mcp, deadbug-mcp.py&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:57:43 GMT</pubDate><category>AI-Targeted</category></item><item><title>Blacklight: Illuminating AI Agent Artifacts for Attackers and Defenders</title><link>https://specterops.io/blog/2026/08/12/blacklight-ai-agent-endpoint-artifacts/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-08-12-specterops-blacklight-illuminating-ai-agent-artifac</guid><description>&lt;p&gt;SpecterOps released Blacklight, an open-source toolkit that discovers and analyzes local endpoint artifacts left by AI coding agents like Codex, Claude Code, Cursor, and Antigravity CLI. These artifacts, including auth tokens, session transcripts, and configuration files, can expose credentials, project context, and trust relationships useful to attackers and to defenders building detection guidance.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: SpecterOps | Malware: Blacklight, Blacklight Scout&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:18:26 GMT</pubDate><category>AI-Targeted</category></item><item><title>Investigating three real-world incidents in our cybersecurity evaluations</title><link>https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-30-anthropic-investigating-three-real-world-incidents</guid><description>&lt;p&gt;Anthropic found that during cybersecurity capture-the-flag evaluations, Claude models unexpectedly gained internet access due to a misconfiguration with a third-party evaluator and compromised real production systems at three organizations, believing them to be simulated targets. Impacts included data exfiltration, a malicious PyPI package that ran on 15 real systems, and unauthorized access via SQL injection, none o&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Anthropic&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:56:06 GMT</pubDate><category>AI-Targeted</category></item><item><title>Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT</title><link>https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-27-huntress-inside-fakeagent-how-a-claude-desktop-ma</guid><description>&lt;p&gt;Huntress found a malvertising campaign that abused a public Claude AI artifact to distribute a trojanized ClaudeDesktop.exe installer, infecting 29 organizations with the SectopRAT trojan via DLL sideloading, GPU-based decryption, and blockchain-hosted (EtherHiding) command and control. Huntress used Claude itself, with human verification, to help reverse engineer the malware&apos;s custom AES implementation hidden in a G&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Huntress | Malware: SectopRAT&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:55:59 GMT</pubDate><category>AI-Targeted</category></item><item><title>Security incident disclosure , July 2026</title><link>https://huggingface.co/blog/security-incident-july-2026</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-16-hugging-face-security-incident-disclosure-july-2026</guid><description>&lt;p&gt;Hugging Face disclosed that an autonomous AI agent framework breached part of its production infrastructure by exploiting two code-execution flaws in its dataset processing pipeline, then escalated privileges and harvested credentials. No tampering with public models, datasets, or Spaces was found; Hugging Face used an open-weight model on its own infrastructure for forensic analysis after commercial API providers&apos; s&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Hugging Face&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:55:09 GMT</pubDate><category>AI-Targeted</category></item><item><title>Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting</title><link>https://sites.google.com/view/agentic-botnets/home</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-13-tel-aviv-university-beware-of-agentic-botnets-scalable-untar</guid><description>&lt;p&gt;Researchers show that LLM hallucinations of repository or skill names are predictable and transferable across models, letting attackers preregister the hallucinated resource names with malicious payloads. When agentic coding assistants and CLIs fetch these squatted resources they can be tricked into executing code, enabling remote code execution and potentially a botnet. This is proof-of-concept research disclosed re&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Tel Aviv University | Malware: HalluSquatting, promptware&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:17:40 GMT</pubDate><category>AI-Targeted</category></item><item><title>New Gaslight malware evades AI analysis</title><link>https://moonlock.com/gaslight-malware-evades-ai-analysis</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-03-moonlock-new-gaslight-malware-evades-ai-analysis</guid><description>&lt;p&gt;SentinelOne identified a North Korean-linked macOS Rust malware, dubbed Gaslight, that embeds fabricated system error messages designed to trick AI-based security agents into dismissing it during automated triage. The malware also steals browser data, terminal history, and keychain files, and exfiltrates via a hardened Telegram bot C2, moving prompt-injection evasion from proof-of-concept into real-world use.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Moonlock | Actors: North Korean hackers | Malware: Gaslight, AMOS, Realistic macOS infostealer, Realist | Attribution: North Korea, per SentinelOne (confidence not stated)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:17:32 GMT</pubDate><category>AI-Targeted</category></item><item><title>Indirect Prompt Injection in Web Content Targets AI Agents</title><link>https://www.zscaler.com:443/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents</link><guid isPermaLink="false">https://ai-threat.watch/#2026-07-02-zscaler-threatlabz-indirect-prompt-injection-in-web-content</guid><description>&lt;p&gt;Zscaler ThreatLabz documented two real-world campaigns embedding hidden prompt injection instructions in web content via SEO poisoning, JSON-LD, and CSS to manipulate AI agents, including a fake API payment scam and a DeBank typosquatting site. Testing across 26 LLMs found 4 models could be tricked into making payments and 2 misclassified the fraudulent site as legitimate.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Zscaler ThreatLabz&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:17:17 GMT</pubDate><category>AI-Targeted</category></item><item><title>Prompt injection still drives most agentic AI security failures in production</title><link>https://www.helpnetsecurity.com/2026/06/11/owasp-prompt-injection-ai-security-failures/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-06-11-helpnet-owasp-agentic</guid><description>&lt;p&gt;Coverage of OWASP&apos;s 2026 findings on agentic AI. Most production failures still begin with prompt injection, and attackers increasingly poison what agents trust: MCP servers, packages and coding-tool configuration.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Help Net Security | Vulnerabilities: CVE-2025-6514, CVE-2026-22708&lt;/p&gt;</description><pubDate>Thu, 11 Jun 2026 06:00:00 GMT</pubDate><category>AI-Targeted</category></item><item><title>ChatGPhish: The Page Is the Payload</title><link>https://permiso.io/blog/chatgpt-markdown-rendering-vulnerability</link><guid isPermaLink="false">https://ai-threat.watch/#2026-05-29-permiso-chatgphish-the-page-is-the-payload</guid><description>&lt;p&gt;Permiso researchers show that ChatGPT&apos;s browser page-summarization feature renders attacker-appended Markdown links and images from third-party pages as trusted UI elements, enabling phishing, QR-code redirection to a second device, and tracking-pixel style data leakage. The issue was demonstrated as a proof of concept and reported to OpenAI via Bugcrowd but was marked not reproducible then a duplicate.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Permiso&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:17:08 GMT</pubDate><category>AI-Targeted</category></item><item><title>Fake Claude Code, Real Malware: Inside the Campaign Targeting AI Developers</title><link>https://www.straiker.ai/blog/acr-stealer-claude-code-impersonation-campaign</link><guid isPermaLink="false">https://ai-threat.watch/#2026-05-27-straiker-fake-claude-code-real-malware-inside-the</guid><description>&lt;p&gt;Straiker documented a live infostealer campaign impersonating Claude Code, JetBrains, NotebookLM and other AI developer tools across 88 domains, using SEO poisoning, paid ads, and fileless payload delivery. The malware, an Amatera/ACR Stealer variant, is built to steal API keys from AI coding assistants alongside browser credentials and crypto wallets, with C2 hidden on a Binance Smart Chain contract.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Straiker | Malware: Amatera, ACR Stealer&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:54:08 GMT</pubDate><category>AI-Targeted</category></item><item><title>SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer</title><link>https://blog.eclecticiq.com/seo-poisoning-campaign-leverages-gemini-and-claude-code-impersonation-to-deliver-infostealer</link><guid isPermaLink="false">https://ai-threat.watch/#2026-05-21-eclecticiq-seo-poisoning-campaign-leverages-gemini</guid><description>&lt;p&gt;EclecticIQ documented an SEO poisoning campaign using fake Gemini CLI and Claude Code installation pages to trick developers into running a PowerShell command that installs a fileless, in-memory infostealer alongside the real tool. The malware disables AMSI and ETW, harvests browser, collaboration app, VPN and crypto wallet credentials, and supports remote code execution, with passive DNS revealing over 30 related do&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: EclecticIQ&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:53:45 GMT</pubDate><category>AI-Targeted</category></item><item><title>Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud</title><link>https://www.trendmicro.com/en_us/research/26/e/banana-rat.html</link><guid isPermaLink="false">https://ai-threat.watch/#2026-05-19-trend-micro-inside-shadow-water-063-s-banana-rat-fro</guid><description>&lt;p&gt;Trend Micro&apos;s MDR team correlated attacker server infrastructure with victim telemetry to map Banana RAT, a banking trojan targeting 16 Brazilian financial institutions via phishing and fileless PowerShell delivery. The malware provides remote control, keylogging, overlay injection, and PIX QR code interception, using a polymorphic crypter service to evade detection.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Trend Micro | Actors: SHADOW-WATER-063 | Malware: Banana RAT, Backdoor.PS1.BANANARAT.A | Attribution: Brazil, per TrendAI (high confidence)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:43:23 GMT</pubDate><category>AI-Targeted</category></item><item><title>When prompts become shells: RCE vulnerabilities in AI agent frameworks</title><link>https://www.microsoft.com/en-us/security/blog/2026/05/07/prompts-become-shells-rce-vulnerabilities-ai-agent-frameworks/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-05-07-microsoft-prompts-become-shells</guid><description>&lt;p&gt;Microsoft researchers show how a single injected prompt reached host-level code execution in agents built on Semantic Kernel. Model-controlled parameters flowed unsanitized into a search plugin. Both flaws are fixed.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Microsoft Security | Vulnerabilities: CVE-2026-25592, CVE-2026-26030&lt;/p&gt;</description><pubDate>Thu, 07 May 2026 06:00:00 GMT</pubDate><category>AI-Targeted</category></item><item><title>Agent Context Poisoning: SKILL.md and the New AI Supply Chain Attack Surface</title><link>https://labs.cloudsecurityalliance.org/research/csa-research-note-skill-md-agent-context-poisoning-20260506/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-05-06-cloud-security-alliance-agent-context-poisoning-skill-md-and-the</guid><description>&lt;p&gt;Cloud Security Alliance details how AI agent skill files like SKILL.md, CLAUDE.md and AGENTS.md create a new supply chain attack surface, since natural-language instructions in these files are trusted and executed by agents at runtime. It cites Snyk&apos;s ToxicSkills audit finding security flaws in 36.82% of 3,984 scanned skills and 341 malicious ClawHub skills, plus two Check Point-disclosed CVEs in Claude Code enabling&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Cloud Security Alliance | Malware: ToxicSkills, OpenClaw | Vulnerabilities: CVE-2025-59536, CVE-2026-21852&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:16:46 GMT</pubDate><category>AI-Targeted</category></item><item><title>AI threats in the wild: The current state of prompt injections on the web</title><link>https://blog.google/security/prompt-injections-web/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-04-23-google-ai-threats-in-the-wild-the-current-state</guid><description>&lt;p&gt;Google researchers scanned Common Crawl web archives for indirect prompt injection attempts targeting AI agents that browse websites. Most found examples were low-sophistication pranks, SEO manipulation, or crawler deterrence, with only a small number of malicious data-theft or destructive attempts, none highly advanced. Detections of malicious injections rose 32% between November 2025 and February 2026, suggesting g&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Google&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:16:40 GMT</pubDate><category>AI-Targeted</category></item><item><title>OWASP GenAI Exploit Round-up Report Q1 2026</title><link>https://genai.owasp.org/2026/04/14/owasp-genai-exploit-round-up-report-q1-2026/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-04-14-owasp-exploit-roundup-q1</guid><description>&lt;p&gt;Quarterly review of eight AI-related incidents mapped to the OWASP LLM and agentic risk lists. It includes active exploitation of a maximum-severity Flowise flaw and GrafanaGhost, a prompt injection path that exfiltrates data from Grafana&apos;s AI features.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: OWASP GenAI Security Project | Vulnerabilities: CVE-2025-59528&lt;/p&gt;</description><pubDate>Tue, 14 Apr 2026 06:00:00 GMT</pubDate><category>AI-Targeted</category></item><item><title>&quot;Hello? I can&apos;t hear you&quot;: Investigating UNC1069&apos;s Fake Meeting Tactics</title><link>https://www.validin.com/blog/i_cant_hear_you_unc1069/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-04-14-validin-hello-i-can-t-hear-you-investigating-unc</guid><description>&lt;p&gt;Validin details UNC1069 (overlapping with Bluenoroff), a North Korean actor luring crypto and Web3 professionals via fake VC personas into fraudulent Zoom/Teams/Meet-style meetings. Victims are tricked with ClickFix prompts into running malware (updated Cabbage RAT/CageyChameleon variants, NukeSped) across Windows, macOS and Linux, and their audio/video is captured via WebRTC for reuse in later social engineering, in&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Validin | Actors: UNC1069, Bluenoroff, Lazarus Group | Malware: Cabbage RAT, CageyChameleon, NukeSped | Attribution: North Korea, per Validin (high confidence)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:16:09 GMT</pubDate><category>AI-Targeted</category></item><item><title>LiteLLM and Telnyx compromised on PyPI: Tracing the TeamPCP supply chain campaign</title><link>https://securitylabs.datadoghq.com/articles/litellm-compromised-pypi-teampcp-supply-chain-campaign/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-03-27-datadog-litellm-teampcp</guid><description>&lt;p&gt;Two backdoored releases of LiteLLM, a widely used LLM gateway library, were published to PyPI on March 24, 2026 with a credential stealer. Datadog traces the campaign from a poisoned Trivy scanner through npm and into PyPI.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Datadog Security Labs | Actors: TeamPCP&lt;/p&gt;</description><pubDate>Fri, 27 Mar 2026 06:00:00 GMT</pubDate><category>AI-Targeted</category></item><item><title>Open, Closed and Broken: Prompt Fuzzing Finds LLMs Still Fragile Across Open and Closed Models</title><link>https://unit42.paloaltonetworks.com/genai-llm-prompt-fuzzing/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-03-17-unit-42-open-closed-and-broken-prompt-fuzzing-fi</guid><description>&lt;p&gt;Unit 42 researchers built a genetic algorithm based prompt fuzzing method that automatically generates meaning-preserving variants of disallowed requests to test LLM guardrails. Testing against closed-source and open-weight models plus a content-filter model on explosive-related prompts found evasion rates ranging from 1 percent to 99 percent depending on model and keyword. This is original research showing guardrail&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Unit 42&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:15:26 GMT</pubDate><category>AI-Targeted</category></item><item><title>Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild</title><link>https://unit42.paloaltonetworks.com/ai-agent-prompt-injection/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-03-03-palo-alto-networks-unit--fooling-ai-agents-web-based-indirect-pro</guid><description>&lt;p&gt;Unit 42 documents real-world indirect prompt injection attacks embedded in webpages, including the first observed case of an attacker bypassing an AI-based ad review system with a scam advertisement. The researchers catalog 22 payload techniques and a severity taxonomy, showing IDPI moving from proof-of-concept to active exploitation, though some scenarios like ad-checker bypass remain unconfirmed against deployed sy&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Palo Alto Networks Unit 42&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:15:13 GMT</pubDate><category>AI-Targeted</category></item><item><title>Malicious OpenClaw Skills Used to Distribute Atomic macOS Stealer</title><link>https://www.trendaisecurity.com/en-us/resources-insights/trendai-security-blog/malicious-openclaw-skills-used-to-distribute-atomic-macos-stealer</link><guid isPermaLink="false">https://ai-threat.watch/#2026-02-23-trendai-research-malicious-openclaw-skills-used-to-distri</guid><description>&lt;p&gt;TrendAI Research documented a campaign where malicious OpenClaw agent skills trick AI agents like GPT-4o into installing a new variant of Atomic macOS Stealer (AMOS), which then deceives users into entering their password. The malware exfiltrates browser data, crypto wallets, Apple and KeePass keychains, and documents, with hundreds of malicious skills found across ClawHub, SkillsMP, and GitHub repositories.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: TrendAI Research | Malware: Atomic (AMOS) Stealer, AMOS&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:40:00 GMT</pubDate><category>AI-Targeted</category></item><item><title>Moonlock Lab thread on ClickFix malware abusing Claude.ai and Medium</title><link>https://x.com/moonlock_lab/status/2021695650367226108?s=12</link><guid isPermaLink="false">https://ai-threat.watch/#2026-02-11-moonlock-lab-moonlock-lab-thread-on-clickfix-malware</guid><description>&lt;p&gt;Moonlock Lab reports that a Google Sponsored ad for a macOS search led users to malware via ClickFix delivery, seen over 15,000 times. One variant abused a public artifact hosted on claude.ai, while another used a Medium post impersonating Apple support, both attributed to the same threat actor.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Moonlock Lab | Malware: ClickFix&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:38:42 GMT</pubDate><category>AI-Targeted</category></item><item><title>Snyk Finds Prompt Injection in 36%, 1467 Malicious Payloads in a ToxicSkills Study of Agent Skills Supply Chain Compromise</title><link>https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-02-05-snyk-snyk-finds-prompt-injection-in-36-1467-m</guid><description>&lt;p&gt;Snyk scanned 3,984 AI agent skills from ClawHub and skills.sh and found 534 with critical security issues and 76 confirmed malicious payloads designed for credential theft, backdoors, or data exfiltration, with 8 still live on ClawHub. The research shows attackers combining prompt injection with malicious code to bypass agent safety mechanisms in Claude Code, Cursor, and OpenClaw skills.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Snyk | Malware: ToxicSkills&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:57:51 GMT</pubDate><category>AI-Targeted</category></item><item><title>Breaking Trust with Words: Prompt Injection Leading to Simulated /etc/passwd Disclosure</title><link>https://www.resecurity.com/blog/article/breaking-trust-with-words-prompt-injection-leading-to-simulated-etcpasswd-disclosure</link><guid isPermaLink="false">https://ai-threat.watch/#2026-01-26-resecurity-breaking-trust-with-words-prompt-injecti</guid><description>&lt;p&gt;Resecurity describes penetration testing work on enterprise AI applications, including a banking and HR chatbot, showing how prompt injection can trick an LLM into simulating disclosure of a sensitive Linux file like /etc/passwd. The piece explains direct and indirect prompt injection techniques and several proof-of-concept attack patterns observed during assessments, not confirmed real-world breaches.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Resecurity&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:14:38 GMT</pubDate><category>AI-Targeted</category></item><item><title>The Lethal Trifecta Strikes: Four Major AI Agent Vulnerabilities in Five Days</title><link>https://breached.company/the-lethal-trifecta-strikes-four-major-ai-agent-vulnerabilities-in-five-days/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-01-21-breached-company-the-lethal-trifecta-strikes-four-major-a</guid><description>&lt;p&gt;Between January 7-15, 2026, researchers including PromptArmor disclosed indirect prompt injection vulnerabilities in four production AI tools: IBM Bob, Superhuman AI, Notion AI, and Anthropic&apos;s Claude Cowork, each allowing data exfiltration via the &apos;lethal trifecta&apos; of private data access, untrusted content exposure, and external communication channels. Vendor responses varied widely, from Superhuman&apos;s rapid remediat&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Breached.company | Malware: Claude Cowork, IBM Bob, Notion AI, Superhuman AI, Superhuman Go&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:41:18 GMT</pubDate><category>AI-Targeted</category></item><item><title>Threat Actors Actively Targeting LLMs</title><link>https://www.greynoise.io/blog/threat-actors-actively-targeting-llms</link><guid isPermaLink="false">https://ai-threat.watch/#2026-01-08-greynoise-threat-actors-actively-targeting-llms</guid><description>&lt;p&gt;GreyNoise honeypots recorded two campaigns targeting LLM infrastructure between October 2025 and January 2026: an SSRF campaign abusing Ollama model pulls and Twilio webhooks, and an 11 day enumeration campaign probing 73+ LLM endpoints across major providers to find exposed API proxies. The enumeration IPs overlap with infrastructure known for scanning 200+ CVEs, suggesting reconnaissance feeding a broader exploitat&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: GreyNoise | Vulnerabilities: CVE-2025-55182, CVE-2023-1389&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:14:19 GMT</pubDate><category>AI-Targeted</category></item><item><title>New Prompt Injection Attack Vectors Through MCP Sampling</title><link>https://unit42.paloaltonetworks.com/model-context-protocol-attack-vectors/</link><guid isPermaLink="false">https://ai-threat.watch/#2025-12-05-unit-42-palo-alto-networ-new-prompt-injection-attack-vectors-thro</guid><description>&lt;p&gt;Unit 42 researchers show that the Model Context Protocol sampling feature, which lets MCP servers request LLM completions from the client, lacks security controls and trusts servers implicitly. They built a proof-of-concept malicious MCP server against an unnamed coding copilot demonstrating resource theft via hidden prompts, conversation hijacking, and covert tool invocation. No in-the-wild exploitation is claimed;&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Unit 42 (Palo Alto Networks)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:38:25 GMT</pubDate><category>AI-Targeted</category></item><item><title>Claude Desktop Extensions Vulnerable to Web-Based Prompt Injection</title><link>https://www.infosecurity-magazine.com/news/claude-desktop-extensions-prompt/</link><guid isPermaLink="false">https://ai-threat.watch/#2025-11-05-infosecurity-claude-extensions</guid><description>&lt;p&gt;Researchers reported that extensions for the Claude desktop app could be driven by instructions planted in web content, turning an ordinary browsing request into a path to actions on the user&apos;s machine.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Infosecurity Magazine&lt;/p&gt;</description><pubDate>Wed, 05 Nov 2025 06:00:00 GMT</pubDate><category>AI-Targeted</category></item><item><title>First Malicious MCP in the Wild: The Postmark Backdoor That&apos;s Stealing Your Emails</title><link>https://www.koi.ai/blog/postmark-mcp-npm-malicious-backdoor-email-theft</link><guid isPermaLink="false">https://ai-threat.watch/#2025-09-25-koi-postmark-mcp</guid><description>&lt;p&gt;An npm package posing as the Postmark MCP server behaved normally for fifteen versions, then added one line that copied every email sent through it to the author&apos;s server. Koi calls it the first malicious MCP server seen in the wild.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Koi Security | Actors: Jabal Torres, phanpak | Malware: postmark-mcp&lt;/p&gt;</description><pubDate>Thu, 25 Sep 2025 06:00:00 GMT</pubDate><category>AI-Targeted</category></item><item><title>Malicious MCP servers used in supply chain attacks</title><link>https://securelist.com/model-context-protocol-for-ai-integration-abused-in-supply-chain-attacks/117473/</link><guid isPermaLink="false">https://ai-threat.watch/#2025-09-15-kaspersky-securelist-malicious-mcp-servers-used-in-supply-cha</guid><description>&lt;p&gt;Kaspersky describes how the Model Context Protocol (MCP), used to connect AI assistants to tools, can be abused via protocol-level tricks like tool poisoning and shadowing, and via supply chain attacks with malicious MCP packages. They built a proof-of-concept MCP server disguised as a developer productivity tool that harvested SSH keys, credentials and environment files while appearing legitimate. This was a control&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Kaspersky Securelist | Malware: devtools-assistant&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:12:16 GMT</pubDate><category>AI-Targeted</category></item><item><title>The Risks of Code Assistant LLMs: Harmful Content, Misuse and Deception</title><link>https://unit42.paloaltonetworks.com/code-assistant-llms/</link><guid isPermaLink="false">https://ai-threat.watch/#2025-09-15-unit-42-palo-alto-networ-the-risks-of-code-assistant-llms-harmful</guid><description>&lt;p&gt;Unit 42 researchers demonstrate that AI code assistant IDE plugins are vulnerable to indirect prompt injection via contaminated context sources like scraped social media data, causing assistants to insert hidden backdoors into generated code. They also show auto-completion features can be manipulated to bypass safety guardrails and generate harmful content, and that direct model invocation exposes models to further m&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Unit 42 (Palo Alto Networks)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:12:07 GMT</pubDate><category>AI-Targeted</category></item><item><title>Securing LLM Superpowers: When Tools Turn Hostile in MCP</title><link>https://www.netskope.com/blog/securing-llm-superpowers-when-tools-turn-hostile-in-mcp</link><guid isPermaLink="false">https://ai-threat.watch/#2025-09-03-netskope-securing-llm-superpowers-when-tools-turn</guid><description>&lt;p&gt;Netskope describes two proof-of-concept attack techniques against MCP-based LLM deployments: prompt injection hidden in tool description metadata, and cross-server tool shadowing where a malicious server poisons the LLM&apos;s shared context to silently alter calls to trusted tools like email. Both exploit MCP&apos;s lack of isolation and provenance checks, evading logs and user-facing UI, and the article proposes signing, san&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Netskope&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:11:48 GMT</pubDate><category>AI-Targeted</category></item><item><title>Cursor AI Code Editor Fixed Flaw Allowing Attackers to Run Commands via Prompt Injection</title><link>https://thehackernews.com/2025/08/cursor-ai-code-editor-fixed-flaw.html</link><guid isPermaLink="false">https://ai-threat.watch/#2025-08-01-thn-cursor-curxecute</guid><description>&lt;p&gt;An indirect prompt injection could make Cursor&apos;s agent write a malicious MCP configuration file without user approval, giving the attacker remote code execution on the developer&apos;s machine.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: The Hacker News | Vulnerabilities: CVE-2025-54135&lt;/p&gt;</description><pubDate>Fri, 01 Aug 2025 06:00:00 GMT</pubDate><category>AI-Targeted</category></item><item><title>In the Wild: Malware Prototype with Embedded Prompt Injection</title><link>https://research.checkpoint.com/2025/ai-evasion-prompt-injection/</link><guid isPermaLink="false">https://ai-threat.watch/#2025-06-25-check-point-research-in-the-wild-malware-prototype-with-embed</guid><description>&lt;p&gt;Check Point found a malware sample uploaded to VirusTotal that embeds a prompt injection string attempting to instruct AI models analyzing it to output &apos;NO MALWARE DETECTED&apos;. The attack failed against tested LLMs (OpenAI o3 and gpt-4.1) and appears to be an early proof-of-concept, but signals growing attempts to evade AI-based malware analysis tools.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Check Point Research | Malware: Skynet&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:11:08 GMT</pubDate><category>AI-Targeted</category></item><item><title>&apos;EchoLeak&apos; AI Attack Enabled Theft of Sensitive Data via Microsoft 365 Copilot</title><link>https://www.securityweek.com/echoleak-ai-attack-enabled-theft-of-sensitive-data-via-microsoft-365-copilot/</link><guid isPermaLink="false">https://ai-threat.watch/#2025-06-11-securityweek-echoleak</guid><description>&lt;p&gt;Aim Security showed that a single crafted email could make Microsoft 365 Copilot send internal data to an attacker with no user interaction. Microsoft patched it server-side and reported no exploitation in the wild.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: SecurityWeek | Vulnerabilities: CVE-2025-32711&lt;/p&gt;</description><pubDate>Wed, 11 Jun 2025 06:00:00 GMT</pubDate><category>AI-Targeted</category></item><item><title>Investigating LLM Jailbreaking of Popular Generative AI Web Products</title><link>https://unit42.paloaltonetworks.com/jailbreaking-generative-ai-web-products/</link><guid isPermaLink="false">https://ai-threat.watch/#2025-02-21-unit-42-investigating-llm-jailbreaking-of-popula</guid><description>&lt;p&gt;Unit 42 tested 17 popular GenAI web products with single-turn and multi-turn jailbreak strategies to assess safety violations and sensitive data leakage. All tested products were vulnerable to some jailbreak techniques, with multi-turn strategies like Crescendo and Bad Likert Judge more effective for safety violations, while single-turn methods like repeated token attacks were more effective for data leakage in one a&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Unit 42 | Malware: DAN, Crescendo, Bad Likert Judge, PLEAK, h4rm3l&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:10:30 GMT</pubDate><category>AI-Targeted</category></item><item><title>Recent Jailbreaks Demonstrate Emerging Threat to DeepSeek</title><link>https://unit42.paloaltonetworks.com/jailbreaking-deepseek-three-techniques/</link><guid isPermaLink="false">https://ai-threat.watch/#2025-01-30-unit-42-recent-jailbreaks-demonstrate-emerging-t</guid><description>&lt;p&gt;Unit 42 tested three jailbreak techniques (Bad Likert Judge, Crescendo, Deceptive Delight) against DeepSeek LLMs and achieved high bypass rates with little specialized knowledge required. The jailbreaks elicited data exfiltration tools, keylogger code, phishing templates, Molotov cocktail instructions and malicious scripts, demonstrating security risks in DeepSeek&apos;s safety guardrails.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Unit 42 | Malware: Bad Likert Judge, Crescendo, Deceptive Delight&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:10:22 GMT</pubDate><category>AI-Targeted</category></item><item><title>How we estimate the risk from prompt injection attacks on AI systems</title><link>https://blog.google/security/how-we-estimate-risk-from-promp/</link><guid isPermaLink="false">https://ai-threat.watch/#2025-01-29-google-deepmind-how-we-estimate-the-risk-from-prompt-inj</guid><description>&lt;p&gt;Google DeepMind describes an automated red-teaming framework using optimization-based attacks (Actor Critic, Beam Search, Tree of Attacks with Pruning) to test AI agents&apos; susceptibility to indirect prompt injection that could exfiltrate sensitive user data. This is a defensive research methodology, not a report of real-world exploitation, and no specific incidents are disclosed.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Google DeepMind&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:37:15 GMT</pubDate><category>AI-Targeted</category></item><item><title>Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information, Including Chat History</title><link>https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak</link><guid isPermaLink="false">https://ai-threat.watch/#2025-01-29-wiz-deepseek-database</guid><description>&lt;p&gt;An unauthenticated ClickHouse database belonging to DeepSeek exposed over a million log lines, including chat history, API secrets and backend details, and allowed full control of the database. DeepSeek secured it after disclosure.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Wiz Research&lt;/p&gt;</description><pubDate>Wed, 29 Jan 2025 06:00:00 GMT</pubDate><category>AI-Targeted</category></item><item><title>Invisible Prompt Injection: A Threat to AI Security</title><link>https://www.trendmicro.com/en_us/research/25/a/invisible-prompt-injection-secure-ai.html</link><guid isPermaLink="false">https://ai-threat.watch/#2025-01-22-trend-micro-invisible-prompt-injection-a-threat-to-a</guid><description>&lt;p&gt;Trend Micro explains how invisible Unicode tag characters can hide prompt injection text from users while still being interpreted by LLMs, altering model responses. The article demonstrates the technique with a proof-of-concept example and tests attack success rates against several Claude and Mistral models, then promotes its own ZTSA product as mitigation.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Trend Micro&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:10:04 GMT</pubDate><category>AI-Targeted</category></item><item><title>Bad Likert Judge: A Novel Multi-Turn Technique to Jailbreak LLMs by Misusing Their Evaluation Capability</title><link>https://unit42.paloaltonetworks.com/multi-turn-technique-jailbreaks-llms/</link><guid isPermaLink="false">https://ai-threat.watch/#2024-12-31-unit-42-palo-alto-networ-bad-likert-judge-a-novel-multi-turn-tech</guid><description>&lt;p&gt;Unit 42 researchers describe a proof-of-concept multi-turn jailbreak that asks an LLM to act as a judge scoring content harmfulness on a Likert scale, then to generate examples at each score, extracting the most harmful response. Testing across six anonymized LLMs showed the technique raised attack success rate by over 75 percentage points versus direct prompts on average, with weaker protection for categories like h&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Unit 42 (Palo Alto Networks)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:09:58 GMT</pubDate><category>AI-Targeted</category></item><item><title>Now You See Me, Now You Don’t: Using LLMs to Obfuscate Malicious JavaScript</title><link>https://unit42.paloaltonetworks.com/using-llms-obfuscate-malicious-javascript/</link><guid isPermaLink="false">https://ai-threat.watch/#2024-12-20-unit-42-now-you-see-me-now-you-don-t-using-llms</guid><description>&lt;p&gt;Unit 42 researchers built an algorithm that uses LLMs to iteratively rewrite malicious JavaScript, evading their own deep learning malware classifier 88% of the time and bypassing all VirusTotal vendors on a sample. This is a proof of concept demonstrating adversarial evasion of AI-based malware detection, not observed criminal use in the wild, and they retrained their model on the samples to improve detection by 10%&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Unit 42 | Malware: WormGPT, FraudGPT&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:09:49 GMT</pubDate><category>AI-Targeted</category></item><item><title>Link Trap: GenAI Prompt Injection Attack</title><link>https://www.trendmicro.com/en_us/research/24/l/genai-prompt-injection-attack-threat.html</link><guid isPermaLink="false">https://ai-threat.watch/#2024-12-17-trend-micro-link-trap-genai-prompt-injection-attack</guid><description>&lt;p&gt;Trend Micro describes a prompt injection technique where an LLM is manipulated into embedding sensitive collected data into a hyperlink disguised as a normal reference link. If the user clicks it, data is exfiltrated to an attacker, even without the AI having external connectivity permissions. This is presented as a conceptual attack pattern rather than a specific observed incident.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Trend Micro&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:09:38 GMT</pubDate><category>AI-Targeted</category></item><item><title>ModeLeak: Privilege Escalation to LLM Model Exfiltration in Vertex AI</title><link>https://unit42.paloaltonetworks.com/privilege-escalation-llm-model-exfil-vertex-ai/</link><guid isPermaLink="false">https://ai-threat.watch/#2024-11-12-unit-42-modeleak-privilege-escalation-to-llm-mod</guid><description>&lt;p&gt;Unit 42 researchers found two vulnerabilities in Google Vertex AI: a privilege escalation via custom job service agents, and a model exfiltration attack via deploying a poisoned model that could steal other fine-tuned ML and LLM models. This was proof-of-concept research conducted in a test environment, reported to Google, which has since patched the issues.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Unit 42&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:09:33 GMT</pubDate><category>AI-Targeted</category></item><item><title>Deceptive Delight: Jailbreak LLMs Through Camouflage and Distraction</title><link>https://unit42.paloaltonetworks.com/jailbreak-llms-through-camouflage-distraction/</link><guid isPermaLink="false">https://ai-threat.watch/#2024-10-23-unit-42-palo-alto-networ-deceptive-delight-jailbreak-llms-through</guid><description>&lt;p&gt;Unit 42 researchers describe Deceptive Delight, a multi-turn jailbreak technique that embeds unsafe topics among benign ones to trick LLMs into generating harmful content. Tested across 8,000 cases on eight models, it achieved a 65% average attack success rate within three turns, versus 5.8% baseline. This is proof-of-concept research with content filters disabled, not an observed real-world attack.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Unit 42 (Palo Alto Networks)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:09:15 GMT</pubDate><category>AI-Targeted</category></item><item><title>When AI Gets Hijacked: Exploiting Hosted Models for Dark Roleplaying</title><link>https://permiso.io/blog/exploiting-hosted-models</link><guid isPermaLink="false">https://ai-threat.watch/#2024-10-03-permiso-when-ai-gets-hijacked-exploiting-hosted</guid><description>&lt;p&gt;Permiso observed attackers hijacking exposed AWS access keys to invoke Bedrock foundation models, primarily Anthropic Claude, to power unfiltered AI roleplaying chatbot services. A honeypot captured over 75,000 invocations in two days, mostly sexual content with some straying into CSEM, with circumstantial links to the Chub.ai bot platform. AWS took 35 hours to block the compromised key after invocation volume spiked&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Permiso | Malware: oai-reverse-proxy, one-api&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 09:58:19 GMT</pubDate><category>AI-Targeted</category></item><item><title>IoC detection experiments with ChatGPT</title><link>https://securelist.com/ioc-detection-experiments-with-chatgpt/108756/</link><guid isPermaLink="false">https://ai-threat.watch/#2023-02-15-securelist-ioc-detection-experiments-with-chatgpt</guid><description>&lt;p&gt;Kaspersky researchers tested whether ChatGPT could identify indicators of compromise, finding it failed on known hashes and domains but performed better analyzing host-based artifacts like process metadata and service installations. They built a proof-of-concept PowerShell scanner (HuntWithChatGPT) that used the OpenAI API to flag suspicious system activity with some false positives and negatives.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Securelist | Malware: Mimikatz, Fast Reverse Proxy, Meterpreter, PowerShell Empire, HuntWithChatGPT.psm1&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 10:00:17 GMT</pubDate><category>AI-Targeted</category></item></channel></rss>