How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
Summary
Attackers are abusing trusted features on AI platforms like Claude, ChatGPT, and Grok to deliver malware and steal data, rather than attacking the platforms directly. They exploit shareable content, public links, and search rankings to trick users into downloading malware or running malicious commands, hiding behind the platforms' legitimate branding and domains. These campaigns typically run only hours or days before removal, but that's enough time to compromise victims.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://www.bleepingcomputer.com/news/security/how-threat-actors-are-turning-trusted-ai-platforms-into-an-attack-surface/
First tracked: September 11, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 92%