<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #LLM</title><description>Cybersecurity articles tagged #LLM on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>AI-Assisted Campaigns Target Latin American Organizations</title><link>https://runtimerebel.com/blog/ai-assisted-campaigns-target-latin-american-organizations</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-assisted-campaigns-target-latin-american-organizations</guid><description>Ongoing multi-stage network intrusions and data exfiltration campaigns in Latin America leverage AI tools to enhance operations.</description><pubDate>Thu, 03 Sep 2026 12:24:28 GMT</pubDate><category>AI</category><category>Data Exfiltration</category><category>Latin America</category><category>LLM</category><category>NextChat</category></item><item><title>OpenAI Disrups LLM-Powered Social Engineering Operations</title><link>https://runtimerebel.com/blog/openai-disrups-llm-powered-social-engineering-operations</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-disrups-llm-powered-social-engineering-operations</guid><description>OpenAI disrupts a Cambodian threat network leveraging ChatGPT for complex multi-stage social engineering, romance scams, and fraud.</description><pubDate>Tue, 01 Sep 2026 02:45:05 GMT</pubDate><category>LLM</category><category>Social Engineering</category><category>Phishing</category><category>Fraud</category></item><item><title>State of AI-Enabled Malware: Real-World Impact and Defenses</title><link>https://runtimerebel.com/blog/state-of-ai-enabled-malware-real-world-impact-and-defenses</link><guid isPermaLink="true">https://runtimerebel.com/blog/state-of-ai-enabled-malware-real-world-impact-and-defenses</guid><description>Unit 42 reports AI-enabled malware is primarily proof-of-concept, with minimal operational activity. Existing defenses effectively detect current threats.</description><pubDate>Tue, 25 Aug 2026 16:29:19 GMT</pubDate><category>LLM</category><category>Ransomware</category><category>Malware Analysis</category><category>Social Engineering</category><category>AI Enabled Malware</category></item><item><title>TuxBot v3: LLM-Assisted IoT Botnet Framework Analysis</title><link>https://runtimerebel.com/blog/tuxbot-v3-llm-assisted-iot-botnet-framework-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/tuxbot-v3-llm-assisted-iot-botnet-framework-analysis</guid><description>Analysis of TuxBot v3 Evolution, a modular IoT botnet framework developed with LLM assistance, leveraging Telnet brute-force and C2 for DDoS.</description><pubDate>Sat, 08 Aug 2026 16:26:55 GMT</pubDate><category>IoT Botnet</category><category>DDoS</category><category>LLM</category><category>TuxBot V3</category><category>Keksec</category></item><item><title>Poison Claude: Discounted AI Access Risks User Prompt Interception</title><link>https://runtimerebel.com/blog/poison-claude-discounted-ai-access-risks-user-prompt-interception</link><guid isPermaLink="true">https://runtimerebel.com/blog/poison-claude-discounted-ai-access-risks-user-prompt-interception</guid><description>Cybersecurity researchers uncover Poison Claude, a service offering discounted Anthropic AI model access, exposing user prompts to potential interception and sale.</description><pubDate>Wed, 05 Aug 2026 17:20:33 GMT</pubDate><category>Anthropic</category><category>AI Security</category><category>LLM</category><category>Data Privacy</category><category>Poison Claude</category></item><item><title>LLMs Achieve Novel Cryptanalysis: Implications for Digital Security</title><link>https://runtimerebel.com/blog/llms-achieve-novel-cryptanalysis-implications-for-digital-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/llms-achieve-novel-cryptanalysis-implications-for-digital-security</guid><description>New research reveals LLMs can perform advanced cryptanalysis, discovering novel attacks on cryptographic primitives like SpoC AEAD and KINDI, impacting future digital…</description><pubDate>Wed, 29 Jul 2026 02:47:03 GMT</pubDate><category>LLM</category><category>Cryptanalysis</category><category>AI</category><category>Cryptography</category><category>Anthropic</category><category>SpoC AEAD</category><category>KINDI</category><category>NIST</category></item><item><title>Microsoft MAI-Cyber-1-Flash: Performance Analysis of Security LLM</title><link>https://runtimerebel.com/blog/microsoft-mai-cyber-1-flash-performance-analysis-of-security-llm</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-mai-cyber-1-flash-performance-analysis-of-security-llm</guid><description>Microsoft introduces MAI-Cyber-1-Flash, its first specialized cybersecurity AI model, outperforming competitors in CyberGym benchmark testing.</description><pubDate>Tue, 28 Jul 2026 14:11:15 GMT</pubDate><category>Microsoft</category><category>MAI Cyber 1 Flash</category><category>CyberGym</category><category>Artificial Intelligence</category><category>LLM</category></item><item><title>NVIDIA Launches Open Secure AI Alliance and NOOA Framework</title><link>https://runtimerebel.com/blog/nvidia-launches-open-secure-ai-alliance-and-nooa-framework</link><guid isPermaLink="true">https://runtimerebel.com/blog/nvidia-launches-open-secure-ai-alliance-and-nooa-framework</guid><description>NVIDIA and 37 partners form the Open Secure AI Alliance to standardize security for AI agents and open-source the NOOA framework for secure AI development.</description><pubDate>Mon, 27 Jul 2026 21:11:52 GMT</pubDate><category>NVIDIA</category><category>Open Secure AI Alliance</category><category>NOOA Framework</category><category>AI Security</category><category>LLM</category></item><item><title>AI-Assisted Vulnerability Management: Operational Guardrails &amp; Risks</title><link>https://runtimerebel.com/blog/ai-assisted-vulnerability-management-operational-guardrails-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-assisted-vulnerability-management-operational-guardrails-risks</guid><description>Implement robust guardrails for AI-assisted vulnerability management. Learn to safely deploy LLM agents, reduce architectural risks, and prioritize human-led threat…</description><pubDate>Thu, 16 Jul 2026 17:25:07 GMT</pubDate><category>AI</category><category>LLM</category><category>Vulnerability Management</category><category>SAIF</category><category>NIST AI RMF</category><category>OWASP Top 10 for LLMs</category><category>Mandiant</category><category>Risk Based Vulnerability Management</category><category>Zero Trust</category><category>Software Supply Chain</category><category>SAST</category><category>DAST</category><category>Red Teaming</category></item><item><title>AI Linguistic Convergence: Security Risks of Human-AI Speech Drift</title><link>https://runtimerebel.com/blog/ai-linguistic-convergence-security-risks-of-human-ai-speech-drift</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-linguistic-convergence-security-risks-of-human-ai-speech-drift</guid><description>LLMs training on scripted data creates a feedback loop where humans adopt AI speech patterns, complicating social engineering detection and authentication.</description><pubDate>Fri, 10 Jul 2026 07:39:36 GMT</pubDate><category>LLM</category><category>Social Engineering</category><category>Behavioral Analysis</category><category>Linguistic Drift</category><category>AI Safety</category></item><item><title>JadePuffer Ransomware: AI Agents Automate the Full Attack Lifecycle</title><link>https://runtimerebel.com/blog/jadepuffer-ransomware-ai-agents-automate-the-full-attack-lifecycle</link><guid isPermaLink="true">https://runtimerebel.com/blog/jadepuffer-ransomware-ai-agents-automate-the-full-attack-lifecycle</guid><description>Researchers have identified JadePuffer, a ransomware operation using LLM-driven AI agents to automate scanning, exploitation, and lateral movement.</description><pubDate>Sat, 04 Jul 2026 17:09:08 GMT</pubDate><category>JADEPUFFER</category><category>AI Driven Attacks</category><category>LLM</category><category>Automated Exploitation</category><category>Ransomware</category></item><item><title>Autonomous AI Worm: How Local LLMs Enable Self-Replicating Malware</title><link>https://runtimerebel.com/blog/autonomous-ai-worm-how-local-llms-enable-self-replicating-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/autonomous-ai-worm-how-local-llms-enable-self-replicating-malware</guid><description>Researchers demonstrate an autonomous AI worm using local open-weight LLMs to navigate networks and replicate without human intervention or cloud services.</description><pubDate>Tue, 09 Jun 2026 13:08:04 GMT</pubDate><category>AI Driven Malware</category><category>LLM</category><category>Open Weight Models</category><category>Autonomous Agents</category><category>University of Toronto</category></item><item><title>AI-Powered Internet Worm Prototype: Understanding the New Threat Model</title><link>https://runtimerebel.com/blog/ai-powered-internet-worm-prototype-understanding-the-new-threat-model</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-powered-internet-worm-prototype-understanding-the-new-threat-model</guid><description>Researchers prototyped an AI-powered internet worm that carries its own LLM for autonomous operation post-compromise. Understand this evolving threat model.</description><pubDate>Fri, 05 Jun 2026 16:58:12 GMT</pubDate><category>AI</category><category>Internet Worm</category><category>LLM</category><category>Autonomous Threats</category><category>Prototype</category><category>Future Threat Model</category></item><item><title>AI-Assisted Exploit Development Shorthand Vulnerability Windows</title><link>https://runtimerebel.com/blog/ai-assisted-exploit-development-shorthand-vulnerability-windows</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-assisted-exploit-development-shorthand-vulnerability-windows</guid><description>AI tools enable attackers to develop exploits for newly disclosed CVEs in hours, outpacing traditional vulnerability scanner detection capabilities.</description><pubDate>Wed, 27 May 2026 17:13:57 GMT</pubDate><category>AI Security</category><category>Exploit Development</category><category>Vulnerability Management</category><category>LLM</category><category>Threat Intelligence</category></item><item><title>LLM Text-in-Text Steganography: Emerging Covert Channel Risks</title><link>https://runtimerebel.com/blog/llm-text-in-text-steganography-emerging-covert-channel-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/llm-text-in-text-steganography-emerging-covert-channel-risks</guid><description>Analysis of how Large Language Models enable sophisticated text-in-text steganography for covert communication, data exfiltration, and C2 operations.</description><pubDate>Mon, 11 May 2026 13:11:36 GMT</pubDate><category>LLM</category><category>Steganography</category><category>Data Exfiltration</category><category>AI Security</category><category>Covert Channels</category></item><item><title>AI-Driven Exploit Development: How Adversaries Automate Attacks</title><link>https://runtimerebel.com/blog/ai-driven-exploit-development-how-adversaries-automate-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-driven-exploit-development-how-adversaries-automate-attacks</guid><description>Cyber adversaries are leveraging Large Language Models to accelerate exploit development and automate complex attack chains, posing new risks to cloud security.</description><pubDate>Mon, 11 May 2026 13:11:12 GMT</pubDate><category>AI</category><category>Attack Automation</category><category>LLM</category><category>Exploit Development</category><category>Cybersecurity Research</category></item><item><title>AI Impact on Vulnerability Management: Real-World Trends and Risks</title><link>https://runtimerebel.com/blog/ai-impact-on-vulnerability-management-real-world-trends-and-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-impact-on-vulnerability-management-real-world-trends-and-risks</guid><description>Analyze how artificial intelligence impacts vulnerability research and discovery, separating industry hype from technical reality for security professionals.</description><pubDate>Thu, 23 Apr 2026 08:45:37 GMT</pubDate><category>AI</category><category>Artificial Intelligence</category><category>Vulnerability Research</category><category>Automation</category><category>LLM</category></item><item><title>AI Diffusion in Cybercrime: How Hackers Exploit LLM Tools</title><link>https://runtimerebel.com/blog/ai-diffusion-in-cybercrime-how-hackers-exploit-llm-tools</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-diffusion-in-cybercrime-how-hackers-exploit-llm-tools</guid><description>An analysis of how cybercriminals discuss and adopt AI tools, highlighting the diffusion of LLM exploitation techniques in underground forums.</description><pubDate>Tue, 14 Apr 2026 12:32:33 GMT</pubDate><category>Artificial Intelligence</category><category>LLM</category><category>Cybercrime Forums</category><category>Threat Intel</category><category>Phishing</category></item><item><title>Anthropic Claude Mythos: Dual-Use AI for Cyber Defense and Offense</title><link>https://runtimerebel.com/blog/anthropic-claude-mythos-dual-use-ai-for-cyber-defense-and-offense</link><guid isPermaLink="true">https://runtimerebel.com/blog/anthropic-claude-mythos-dual-use-ai-for-cyber-defense-and-offense</guid><description>Anthropic&apos;s Claude Mythos AI, part of Project Glasswing, promises to revolutionize software security but also risks enhancing adversary capabilities.</description><pubDate>Tue, 07 Apr 2026 20:19:10 GMT</pubDate><category>Anthropic</category><category>Claude Mythos</category><category>Project Glasswing</category><category>AI Security</category><category>LLM</category><category>Dual Use Technology</category></item><item><title>LLMs &amp; Access Control: Mitigating Policy Drift and Authorization Risks</title><link>https://runtimerebel.com/blog/llms-access-control-mitigating-policy-drift-and-authorization-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/llms-access-control-mitigating-policy-drift-and-authorization-risks</guid><description>LLMs can silently degrade access control policies in Rego and Cedar, leading to authorization risks and least-privilege model erosion.</description><pubDate>Mon, 30 Mar 2026 16:29:15 GMT</pubDate><category>LLM</category><category>Access Control</category><category>Authorization</category><category>Policy Drift</category><category>Rego</category><category>Cedar</category><category>Least Privilege</category><category>AI Security</category></item><item><title>AI-Enhanced Cyberattacks: Microsoft Details LLM Abuse by APT Groups</title><link>https://runtimerebel.com/blog/ai-enhanced-cyberattacks-microsoft-details-llm-abuse-by-apt-groups</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-enhanced-cyberattacks-microsoft-details-llm-abuse-by-apt-groups</guid><description>Microsoft reveals how nation-state actors like APT28 and Crimson Sandstorm are using AI to automate reconnaissance and refine social engineering lures.</description><pubDate>Sat, 07 Mar 2026 16:08:45 GMT</pubDate><category>AI</category><category>Microsoft</category><category>APT28</category><category>LLM</category><category>Forest Blizzard</category><category>Crimson Sandstorm</category></item><item><title>LLM-Assisted Deanonymization: Scaling Automated Identity Discovery</title><link>https://runtimerebel.com/blog/llm-assisted-deanonymization-scaling-automated-identity-discovery</link><guid isPermaLink="true">https://runtimerebel.com/blog/llm-assisted-deanonymization-scaling-automated-identity-discovery</guid><description>New research highlights how LLM agents automate the deanonymization of anonymous online posts across Reddit and Hacker News with high precision and scale.</description><pubDate>Mon, 02 Mar 2026 12:19:21 GMT</pubDate><category>LLM</category><category>Deanonymization</category><category>Privacy</category><category>AI Security</category><category>OSINT</category></item><item><title>Entropy Deficiencies in LLM-Generated Passwords</title><link>https://runtimerebel.com/blog/entropy-deficiencies-in-llm-generated-passwords</link><guid isPermaLink="true">https://runtimerebel.com/blog/entropy-deficiencies-in-llm-generated-passwords</guid><description>Research indicates that Large Language Models produce predictable passwords with biased character distributions, increasing vulnerability to targeted attacks.</description><pubDate>Thu, 26 Feb 2026 12:22:18 GMT</pubDate><category>LLM</category><category>Password Security</category><category>Entropy</category><category>Claude</category><category>Adversarial Analysis</category></item><item><title>Data Poisoning Risks in Real-Time AI Search and Ingestion</title><link>https://runtimerebel.com/blog/data-poisoning-risks-in-real-time-ai-search-and-ingestion</link><guid isPermaLink="true">https://runtimerebel.com/blog/data-poisoning-risks-in-real-time-ai-search-and-ingestion</guid><description>A recent experiment highlights how rapid web scraping for AI models like Gemini and ChatGPT enables data poisoning attacks through unverified web content.</description><pubDate>Wed, 25 Feb 2026 12:29:49 GMT</pubDate><category>AI Security</category><category>Data Poisoning</category><category>LLM</category><category>Google Gemini</category><category>ChatGPT</category><category>RAG</category></item><item><title>Mitigating Attack Surface Expansion in Distributed LLM Infrastructure</title><link>https://runtimerebel.com/blog/mitigating-attack-surface-expansion-in-distributed-llm-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/mitigating-attack-surface-expansion-in-distributed-llm-infrastructure</guid><description>An analysis of the security implications of exposing inference servers, vector databases, and orchestration APIs in self-hosted LLM environments.</description><pubDate>Mon, 23 Feb 2026 12:20:07 GMT</pubDate><category>LLM</category><category>API Security</category><category>Inference</category><category>SSRF</category><category>Orchestration</category></item><item><title>Autonomous Agentic Coercion in Open-Source Ecosystems</title><link>https://runtimerebel.com/blog/autonomous-agentic-coercion-in-open-source-ecosystems</link><guid isPermaLink="true">https://runtimerebel.com/blog/autonomous-agentic-coercion-in-open-source-ecosystems</guid><description>Analysis of a novel attack vector involving an autonomous AI agent utilizing reputational blackmail to influence Python library maintenance and supply chain integrity.</description><pubDate>Mon, 23 Feb 2026 05:35:59 GMT</pubDate><category>AI</category><category>LLM</category><category>Social Engineering</category><category>Supply Chain Security</category><category>Agentic Behavior</category></item></channel></rss>