AI-enabled attacks
Attackers using AI to find vulnerabilities, write malware, phish or run intrusions with less human effort.
- All items
- 11
- Last 90 days
- 5
- Change
- +67%vs 3 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 0 |
| Jul 2025 | 0 |
| Aug 2025 | 0 |
| Sep 2025 | 0 |
| Oct 2025 | 0 |
| Nov 2025 | 0 |
| Dec 2025 | 0 |
| Jan 2026 | 0 |
| Feb 2026 | 1 |
| Mar 2026 | 2 |
| Apr 2026 | 1 |
| May 2026 | 2 |
| Jun 2026 | 0 |
| Jul 2026 | 1 |
| Aug 2026 | 2 |
| Sep 2026 | 2 |
| Oct 2026 | 0 |
11 items
AI malware just removed the human from the attack loop
Sep 22, 2026MediumNewsSecurityResearchCisco Talos researchers describe CLOSEDQUORUM, a malware binary they call the first "LLM-as-C2" architecture, which uses a panel of large language model judges to automate command-and-control and steal credentials. It targets LSASS credential dumping and browser saved passwords in Chrome, Edge and Firefox, plus crypto wallets such as MetaMask, Ethereum and Exodus. Cisco Talos states there is not yet any confirmation of its deployment in the wild.
CSO OnlineAI-powered attack exploited PaperCut flaws to hack 395 organizations
Sep 10, 2026MediumNewsSecurityIndustryA likely Russian-speaking threat actor used hundreds of AI agents, built on OpenAI's Codex and DeepSeek models with commodity offensive tools, to exploit CVE-2026-81578 and CVE-2026-82078 in PaperCut NG/MF servers starting August 31, according to GreyNoise. GreyNoise says the campaign compromised at least 440 PaperCut instances tied to 395 organizations in 48 countries, with administrator privileges obtained at 12 organizations, mostly in education.
Fix: System administrators are advised to apply PaperCut's emergency security updates addressing CVE-2026-81578 and CVE-2026-82078 immediately, and follow the vendor's recommendations in this bulletin.
BleepingComputerAI agents wage near-autonomous cyberattack on Asian government networks
Aug 13, 2026MediumNewsSecurityIndustryDream, a cybersecurity firm, reported that multiple AI agents built on Hermes and OpenClaw ran a near-autonomous intrusion campaign against government networks in Asia over four days in early July. The agents produced 1,395 files, cracked 85 credentials, and exfiltrated thousands of personnel records. Taiwan's Ministry of Digital Affairs separately reported an AI agent-assisted attack on government agencies in the same period, though neither party has confirmed a link between the two.
CSO OnlineOpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns
Aug 10, 2026InfoNewsSecuritySafetyOpenAI has flagged its unreleased model Astra as potentially reaching the 'critical' tier of its Preparedness Framework, which covers models that can autonomously build zero-day exploits or design and execute end-to-end cyberattacks from a high-level goal. In response, the company has paused internal Astra projects that lack new security controls, including isolated testing, network restrictions and improved model weight protections. OpenAI has also clarified that Astra was not responsible for the recent Hugging Face hack.
Fix: Isolated testing setups, strict network restrictions, improved model weight protections, and universal monitoring of Astra's actions across agentic applications, with internal chain-of-thought evaluation to intercept high-risk or misaligned behavior. Internal projects that do not meet these requirements are paused.
SecurityWeekChinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Jul 30, 2026MediumNewsSecurityIndustryUnit 42 identified an AI-enabled autonomous hacking campaign by a Chinese-speaking threat actor, using the aliases knaithe and KnYuan. The actor used DeepSeek through the Hermes Agent framework, controlled via Telegram, to enumerate targets with FOFA, download exploit code and attempt exploits against infrastructure using seven vulnerabilities. When initial exploitation failed, the agent autonomously searched for critical-severity CVEs and pivoted to higher-value targets.
Palo Alto Unit 42CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks
May 26, 2026InfoNewsSecurityPolicyCERT-In, the Indian Computer Emergency Response Team, has issued guidelines requiring organizations to patch critical vulnerabilities in internet-exposed systems within 12 hours of being flagged, where feasible. The guidance responds to threat actors using AI tools and large language models to automate vulnerability discovery and exploitation. CERT-In published the 38-page blueprint on Monday.
Fix: Patch critical security vulnerabilities in internet-exposed systems within 12 hours of being flagged where feasible, and adopt continuous, risk-based vulnerability and patch management practices.
The Hacker NewsFrom teen hacker to Iron Dome researcher, this founder raised $28M to fight AI phishing
May 19, 2026InfoNewsIndustrySecurityOcean, an agentic email security startup founded by Shay Shwartz, emerged from stealth with $28 million in total funding, led by Lightspeed Venture Partners. The platform uses a small language model to analyze each incoming email's sender intent against the recipient organization's context, aiming to detect AI-powered phishing and impersonation. Ocean reports reviewing billions of emails monthly for customers including Kayak, Kingston Technology, and Headspace.
TechCrunch (Security)Anthropic Unveils Claude Security to Counter AI-Powered Exploit Surge
Apr 30, 2026InfoNewsIndustrySecurityAnthropic released Claude Security in public beta for Claude Enterprise customers, available from the Claude.ai sidebar or at claude.ai/security. It scans a chosen repository, directory or branch for vulnerabilities, reports a confidence rating and reproduction steps, and generates instructions for a targeted patch. Claude Team and Max customers are slated to get access in the near future.
SecurityWeekAI-powered attack kits go open source, and CyberStrikeAI may be just the beginning
Mar 3, 2026MediumNewsSecurityIndustryA newly identified open source platform, CyberStrikeAI, packages end-to-end attack automation into an AI-native orchestration engine with over 100 curated tools covering the whole kill chain. Team Cymru links its developer, known as Ed1s0nZ, to the threat actor behind a campaign that breached hundreds of Fortinet FortiGate firewalls, and says the developer has some ties to the Chinese government. The researchers observed 21 unique IP addresses running CyberStrikeAI between January 20 and 26.
CSO OnlineCyberStrikeAI tool adopted by hackers for AI-powered attacks
Mar 2, 2026MediumNewsSecurityIndustryTeam Cymru reports that CyberStrikeAI, a newly identified open-source AI security testing platform, was run by the threat actor behind a campaign that compromised more than 500 Fortinet FortiGate firewalls. The same IP address, 212.11.64[.]250, was observed running a "CyberStrikeAI" service banner on port 8080 and communicating with targeted FortiGate devices, with the campaign infrastructure last seen running the tool on January 30, 2026. The researchers warn that the tool's orchestration of over 100 security tools, usable by low-skilled operators, could accelerate automated targeting of edge devices such as firewalls and VPN appliances.
BleepingComputer13 ways attackers use generative AI to exploit your systems
Feb 23, 2026InfoNewsSecurityIndustryCybercriminals are using generative AI to make attacks more productive and scalable, according to Dr. Peter Garraghan of Mindgard and Crystal Morin of Sysdig. The article describes AI-generated phishing emails that are more personalized and convincing, and AI-assisted malware development, including an XWorm HTML smuggling attack and the FunkSec ransomware group, which Check Point Research says uses AI to build tools. It also notes that agentic AI is beginning to automate entire attack chains.
CSO Online
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.