{"data":[{"id":"20c00376-4203-47b6-b336-1fe1a49ea148","title":"AI malware just removed the human from the attack loop","summary":"Cisco Talos researchers describe CLOSEDQUORUM, a malware binary they call the first \"LLM-as-C2\" architecture, which uses a panel of large language model judges to automate command-and-control and steal credentials. It targets LSASS credential dumping and browser saved passwords in Chrome, Edge and Firefox, plus crypto wallets such as MetaMask, Ethereum and Exodus. Cisco Talos states there is not yet any confirmation of its deployment in the wild.","sourceUrl":"https://www.csoonline.com/article/4225264/ai-malware-just-removed-the-human-from-the-attack-loop.html","publishedAt":"2026-09-23T00:39:51.000Z","severity":"medium","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["Google","Microsoft","Mistral"],"affectedVendorsRaw":["DeepSeek","Qwen","Mistral","Google Gemini"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["other"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-09-23T00:39:51.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null},{"id":"4230ff0a-3e5e-47ff-af80-826541282c97","title":"AI-powered attack exploited PaperCut flaws to hack 395 organizations","summary":"A likely Russian-speaking threat actor used hundreds of AI agents, built on OpenAI's Codex and DeepSeek models with commodity offensive tools, to exploit CVE-2026-81578 and CVE-2026-82078 in PaperCut NG/MF servers starting August 31, according to GreyNoise. GreyNoise says the campaign compromised at least 440 PaperCut instances tied to 395 organizations in 48 countries, with administrator privileges obtained at 12 organizations, mostly in education.","sourceUrl":"https://www.bleepingcomputer.com/news/security/ai-powered-attack-exploited-papercut-flaws-to-hack-395-organizations/","publishedAt":"2026-09-10T15:55:56.000Z","severity":"medium","cvssSeverity":null,"cvssScore":null,"labels":["security","industry"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["OpenAI"],"affectedVendorsRaw":["OpenAI Codex","DeepSeek","PaperCut NG/MF","Netlas"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"System administrators are advised to apply PaperCut's emergency security updates addressing CVE-2026-81578 and CVE-2026-82078 immediately, and follow the vendor's recommendations in this bulletin.","attackType":["other"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-09-10T15:55:56.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null},{"id":"f2fca19e-7c2b-451f-a1e4-cf73f5c863b8","title":"AI agents wage near-autonomous cyberattack on Asian government networks","summary":"Dream, a cybersecurity firm, reported that multiple AI agents built on Hermes and OpenClaw ran a near-autonomous intrusion campaign against government networks in Asia over four days in early July. The agents produced 1,395 files, cracked 85 credentials, and exfiltrated thousands of personnel records. Taiwan's Ministry of Digital Affairs separately reported an AI agent-assisted attack on government agencies in the same period, though neither party has confirmed a link between the two.","sourceUrl":"https://www.csoonline.com/article/4209210/ai-agents-wage-near-autonomous-cyberattack-on-asian-government-networks.html","publishedAt":"2026-08-13T13:23:10.000Z","severity":"medium","cvssSeverity":null,"cvssScore":null,"labels":["security","industry"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Hermes","OpenClaw","DeepSeek-V4-Flash"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["other"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-08-13T13:23:10.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null},{"id":"df83a479-175c-4480-8a3c-8aec5e429c7e","title":"OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns","summary":"OpenAI has flagged its unreleased model Astra as potentially reaching the 'critical' tier of its Preparedness Framework, which covers models that can autonomously build zero-day exploits or design and execute end-to-end cyberattacks from a high-level goal. In response, the company has paused internal Astra projects that lack new security controls, including isolated testing, network restrictions and improved model weight protections. OpenAI has also clarified that Astra was not responsible for the recent Hugging Face hack.","sourceUrl":"https://www.securityweek.com/openais-upcoming-astra-model-raises-autonomous-cyberattack-concerns/","publishedAt":"2026-08-10T14:33:36.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","safety"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["OpenAI","Anthropic","Meta"],"affectedVendorsRaw":["OpenAI","Astra","GPT-5.6-Sol","Anthropic","Meta","Hugging Face","Claude","ChatGPT Atlas","Atlassian Rovo"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Isolated testing setups, strict network restrictions, improved model weight protections, and universal monitoring of Astra's actions across agentic applications, with internal chain-of-thought evaluation to intercept high-risk or misaligned behavior. Internal projects that do not meet these requirements are paused.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-08-10T14:33:36.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"nation_state","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null},{"id":"0ce2aeda-9455-4f77-b1a5-f7065c5d9789","title":"Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks","summary":"Unit 42 identified an AI-enabled autonomous hacking campaign by a Chinese-speaking threat actor, using the aliases knaithe and KnYuan. The actor used DeepSeek through the Hermes Agent framework, controlled via Telegram, to enumerate targets with FOFA, download exploit code and attempt exploits against infrastructure using seven vulnerabilities. When initial exploitation failed, the agent autonomously searched for critical-severity CVEs and pivoted to higher-value targets.","sourceUrl":"https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/","publishedAt":"2026-07-30T10:00:52.000Z","severity":"medium","cvssSeverity":null,"cvssScore":null,"labels":["security","industry"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["OpenAI"],"affectedVendorsRaw":["DeepSeek","Hermes Agent","Qwen","GLM","Kimi","MiniMax","Claude Code","Codex"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["other"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-07-30T10:00:52.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null},{"id":"3088b01b-9b29-44a7-b1a4-61b8e47a86e1","title":"CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks","summary":"CERT-In, the Indian Computer Emergency Response Team, has issued guidelines requiring organizations to patch critical vulnerabilities in internet-exposed systems within 12 hours of being flagged, where feasible. The guidance responds to threat actors using AI tools and large language models to automate vulnerability discovery and exploitation. CERT-In published the 38-page blueprint on Monday.","sourceUrl":"https://thehackernews.com/2026/05/cert-in-mandates-12-hour-patching-for.html","publishedAt":"2026-05-26T09:13:02.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","policy"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Patch critical security vulnerabilities in internet-exposed systems within 12 hours of being flagged where feasible, and adopt continuous, risk-based vulnerability and patch management practices.","attackType":["prompt_injection","jailbreak"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-05-26T09:13:02.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":null,"llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null},{"id":"1d603887-ea29-498c-8a51-47e6c0cb9a6c","title":"From teen hacker to Iron Dome researcher, this founder raised $28M to fight AI phishing","summary":"Ocean, an agentic email security startup founded by Shay Shwartz, emerged from stealth with $28 million in total funding, led by Lightspeed Venture Partners. The platform uses a small language model to analyze each incoming email's sender intent against the recipient organization's context, aiming to detect AI-powered phishing and impersonation. Ocean reports reviewing billions of emails monthly for customers including Kayak, Kingston Technology, and Headspace.","sourceUrl":"https://techcrunch.com/2026/05/19/from-teen-hacker-to-iron-dome-researcher-this-founder-raised-28m-to-fight-ai-phishing/","publishedAt":"2026-05-19T21:08:51.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["industry","security"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Ocean","Axis","HPE","Proofpoint","Mimecast","Abnormal Security","Kayak","Kingston Technology","Headspace","Lightspeed Venture Partners"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-05-19T21:08:51.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":null,"aiComponentTargeted":null,"llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null},{"id":"c7a21f9a-24a7-43e5-9aa3-6c9852daaff6","title":"Anthropic Unveils Claude Security to Counter AI-Powered Exploit Surge","summary":"Anthropic released Claude Security in public beta for Claude Enterprise customers, available from the Claude.ai sidebar or at claude.ai/security. It scans a chosen repository, directory or branch for vulnerabilities, reports a confidence rating and reproduction steps, and generates instructions for a targeted patch. Claude Team and Max customers are slated to get access in the near future.","sourceUrl":"https://www.securityweek.com/anthropic-unveils-claude-security-to-counter-ai-powered-exploit-surge/","publishedAt":"2026-04-30T18:57:55.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["industry","security"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["Anthropic","Microsoft"],"affectedVendorsRaw":["Claude Security","Claude Opus 4.7","Claude Enterprise","Claude Code","Mythos","CrowdStrike","Microsoft Security","Palo Alto Networks","SentinelOne","Trend.ai","Wiz"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-04-30T18:57:55.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":null,"aiComponentTargeted":null,"llmSpecific":true,"classifierConfidence":0.93,"researchCategory":null,"atlasIds":null},{"id":"2191896d-c5a9-49b5-88fa-76e39220cded","title":"AI-powered attack kits go open source, and CyberStrikeAI may be just the beginning","summary":"A newly identified open source platform, CyberStrikeAI, packages end-to-end attack automation into an AI-native orchestration engine with over 100 curated tools covering the whole kill chain. Team Cymru links its developer, known as Ed1s0nZ, to the threat actor behind a campaign that breached hundreds of Fortinet FortiGate firewalls, and says the developer has some ties to the Chinese government. The researchers observed 21 unique IP addresses running CyberStrikeAI between January 20 and 26.","sourceUrl":"https://www.csoonline.com/article/4140221/ai-powered-attack-kits-go-open-source-and-cyberstrikeai-may-be-just-the-beginning.html","publishedAt":"2026-03-04T02:47:23.000Z","severity":"medium","cvssSeverity":null,"cvssScore":null,"labels":["security","industry"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["CyberStrikeAI"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["other"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"patchAvailable":null,"disclosureDate":null,"capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.8,"researchCategory":null,"atlasIds":null},{"id":"0b297979-fcfa-491a-96e3-597c47b5dd78","title":"CyberStrikeAI tool adopted by hackers for AI-powered attacks","summary":"Team Cymru reports that CyberStrikeAI, a newly identified open-source AI security testing platform, was run by the threat actor behind a campaign that compromised more than 500 Fortinet FortiGate firewalls. The same IP address, 212.11.64[.]250, was observed running a \"CyberStrikeAI\" service banner on port 8080 and communicating with targeted FortiGate devices, with the campaign infrastructure last seen running the tool on January 30, 2026. The researchers warn that the tool's orchestration of over 100 security tools, usable by low-skilled operators, could accelerate automated targeting of edge devices such as firewalls and VPN appliances.","sourceUrl":"https://www.bleepingcomputer.com/news/security/cyberstrikeai-tool-adopted-by-hackers-for-ai-powered-attacks/","publishedAt":"2026-03-03T00:06:39.000Z","severity":"medium","cvssSeverity":null,"cvssScore":null,"labels":["security","industry"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["CyberStrikeAI","GPT","Claude","DeepSeek","Fortinet FortiGate"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["other"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"patchAvailable":null,"disclosureDate":null,"capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}],"meta":{"total":10,"limit":20,"offset":0}}