Advertisement
AI-Assisted Campaigns Target Latin American Organizations
Ongoing multi-stage network intrusions and data exfiltration campaigns in Latin America leverage AI tools to enhance operations.
OpenAI Disrups LLM-Powered Social Engineering Operations
OpenAI disrupts a Cambodian threat network leveraging ChatGPT for complex multi-stage social engineering, romance scams, and fraud.
State of AI-Enabled Malware: Real-World Impact and Defenses
Unit 42 reports AI-enabled malware is primarily proof-of-concept, with minimal operational activity. Existing defenses effectively detect current threats.
TuxBot v3: LLM-Assisted IoT Botnet Framework Analysis
Analysis of TuxBot v3 Evolution, a modular IoT botnet framework developed with LLM assistance, leveraging Telnet brute-force and C2 for DDoS.
Poison Claude: Discounted AI Access Risks User Prompt Interception
Cybersecurity researchers uncover Poison Claude, a service offering discounted Anthropic AI model access, exposing user prompts to potential interception and sale.
LLMs Achieve Novel Cryptanalysis: Implications for Digital Security
New research reveals LLMs can perform advanced cryptanalysis, discovering novel attacks on cryptographic primitives like SpoC AEAD and KINDI, impacting future digital…
Advertisement
Microsoft MAI-Cyber-1-Flash: Performance Analysis of Security LLM
Microsoft introduces MAI-Cyber-1-Flash, its first specialized cybersecurity AI model, outperforming competitors in CyberGym benchmark testing.
NVIDIA Launches Open Secure AI Alliance and NOOA Framework
NVIDIA and 37 partners form the Open Secure AI Alliance to standardize security for AI agents and open-source the NOOA framework for secure AI development.
AI-Assisted Vulnerability Management: Operational Guardrails & Risks
Implement robust guardrails for AI-assisted vulnerability management. Learn to safely deploy LLM agents, reduce architectural risks, and prioritize human-led threat…
AI Linguistic Convergence: Security Risks of Human-AI Speech Drift
LLMs training on scripted data creates a feedback loop where humans adopt AI speech patterns, complicating social engineering detection and authentication.
JadePuffer Ransomware: AI Agents Automate the Full Attack Lifecycle
Researchers have identified JadePuffer, a ransomware operation using LLM-driven AI agents to automate scanning, exploitation, and lateral movement.
Autonomous AI Worm: How Local LLMs Enable Self-Replicating Malware
Researchers demonstrate an autonomous AI worm using local open-weight LLMs to navigate networks and replicate without human intervention or cloud services.
AI-Powered Internet Worm Prototype: Understanding the New Threat Model
Researchers prototyped an AI-powered internet worm that carries its own LLM for autonomous operation post-compromise. Understand this evolving threat model.
AI-Assisted Exploit Development Shorthand Vulnerability Windows
AI tools enable attackers to develop exploits for newly disclosed CVEs in hours, outpacing traditional vulnerability scanner detection capabilities.
LLM Text-in-Text Steganography: Emerging Covert Channel Risks
Analysis of how Large Language Models enable sophisticated text-in-text steganography for covert communication, data exfiltration, and C2 operations.
AI-Driven Exploit Development: How Adversaries Automate Attacks
Cyber adversaries are leveraging Large Language Models to accelerate exploit development and automate complex attack chains, posing new risks to cloud security.
AI Impact on Vulnerability Management: Real-World Trends and Risks
Analyze how artificial intelligence impacts vulnerability research and discovery, separating industry hype from technical reality for security professionals.
AI Diffusion in Cybercrime: How Hackers Exploit LLM Tools
An analysis of how cybercriminals discuss and adopt AI tools, highlighting the diffusion of LLM exploitation techniques in underground forums.
Anthropic Claude Mythos: Dual-Use AI for Cyber Defense and Offense
Anthropic's Claude Mythos AI, part of Project Glasswing, promises to revolutionize software security but also risks enhancing adversary capabilities.
LLMs & Access Control: Mitigating Policy Drift and Authorization Risks
LLMs can silently degrade access control policies in Rego and Cedar, leading to authorization risks and least-privilege model erosion.
AI-Enhanced Cyberattacks: Microsoft Details LLM Abuse by APT Groups
Microsoft reveals how nation-state actors like APT28 and Crimson Sandstorm are using AI to automate reconnaissance and refine social engineering lures.
LLM-Assisted Deanonymization: Scaling Automated Identity Discovery
New research highlights how LLM agents automate the deanonymization of anonymous online posts across Reddit and Hacker News with high precision and scale.
Entropy Deficiencies in LLM-Generated Passwords
Research indicates that Large Language Models produce predictable passwords with biased character distributions, increasing vulnerability to targeted attacks.
Data Poisoning Risks in Real-Time AI Search and Ingestion
A recent experiment highlights how rapid web scraping for AI models like Gemini and ChatGPT enables data poisoning attacks through unverified web content.