threat-intel Google Bets 'Agentic Defense' Strategy Can Outpace Attackers Google is implementing an ‘agentic defense’ strategy, leveraging its acquisition of Wiz to automate threat detection and response in a rapidly evolving cybersecurity landscape. This involves deploying AI-powered agents a… Dark Reading · Jul 17, 2026 High UNCHaicloud securitygraph analysis
threat-intel OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials Threat actors are exploiting a blind spot in Microsoft Entra ID’s sign-in telemetry by using ‘OAuth client ID spoofing’ to enumerate user accounts and validate stolen credentials without triggering traditional login aler… The Hacker News · Jul 14, 2026 High N/oathspoofingentria id
threat-intel Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory A threat actor leveraged an AI-generated PowerShell script to aggressively map an Active Directory environment, culminating in data exfiltration and a detailed inventory report. The attack chain, utilizing tools like s5c… The Hacker News · Jul 13, 2026 High aipowershellactive directory
threat-intel New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic A China-linked cybercrime group, Silver Fox, is using a new Rust-based remote access trojan called MODBEACON to target technology, education, and state-owned enterprises in Asia. The trojan utilizes gRPC streaming for en… The Hacker News · Jul 10, 2026 High CNrustgrpcc2
threat-intel AI Coding: Do Security Risks Outweigh Productivity Gains? AI coding tools are rapidly increasing in popularity, with 91% of organizations using two or more and 54% using three or more. While developers report productivity gains and ROI, significant security risks are associated… Dark Reading · Jul 10, 2026 High aicodingsecurity
threat-intel AI Gateways Offer Attackers the Keys to the Kingdom A cryptomining incident highlighted how AI gateways, increasingly used to manage access to AI models and cloud infrastructure, are becoming attractive targets for attackers. The attacker gained initial access via brute-f… Dark Reading · Jul 9, 2026 High aigatewaycloud
vulnerability AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique AI coding assistants like Claude Code, Amazon Q Developer, and Cursor are vulnerable to a decades-old technique called GhostApproval, where attackers can trick the tools into accessing and modifying sensitive system file… SecurityWeek · Jul 9, 2026 High symlinkaicoding
threat-intel GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents Researchers at Wiz discovered a vulnerability (GhostApproval) in six AI coding assistants – Amazon Q Developer, Anthropic's Claude Code, Augment, Cursor, Google Antigravity, and Windsurf – that allows malicious repositor… The Hacker News · Jul 9, 2026 High CVE-2026-12957symlinkaicode injection
threat-intel Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours A lone attacker successfully breached a large Amazon Web Services (AWS) environment in 72 hours using AI to accelerate reconnaissance, tool development, and command structure, ultimately extorting a global enterprise. Th… Dark Reading · Jul 8, 2026 High aicloudransomware
threat-intel Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker U.S. prosecutors have linked an alleged Scattered Spider hacker, Peter Stokes, to a luxury jewelry retailer breach through a persistent Windows device ID. Stokes, a dual U.S.-Estonian citizen, was extradited from Finland… The Hacker News · Jul 7, 2026 High ESFIUNdevice-idhackerintrusion
threat-intel ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More This week’s security recap highlighted several concerning trends, including a disruption of the NetNut residential proxy network used for botnet operations, a fake Proof-of-Concept (PoC) malware targeting vulnerability r… The Hacker News · Jul 6, 2026 High CVE-2026-48276CVE-2026-48283CVE-2026-48277USESSPbotnetproxymalware
threat-intel Identity Lifecycle Management Wasn't Built for AI Agents This article discusses the challenges of applying traditional identity lifecycle management (IGA) tools to the increasing use of AI agents within enterprise environments. The current IGA model relies on human employees w… The Hacker News · Jul 2, 2026 Medium aigovernanceidentity
ransomware AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack A security firm, Sysdig, has identified what appears to be the first fully automated ransomware attack orchestrated by an AI agent, dubbed JADEPUFFER. The agent exploited a vulnerability in Langflow, an open-source AI ap… The Hacker News · Jul 2, 2026 High CVE-2025-3248CVE-2021-29441CHairansomwareautomation
threat-intel US lifts export controls on Anthropic’s frontier cybersecurity AI models The U.S. government has lifted export controls on Anthropic’s Fable 5 and Mythos 5 cybersecurity AI models following a ‘jailbreak’ exploit discovered in Fable 5. This marks the first instance of export controls being app… The Record · Jul 1, 2026 Medium USCHaijailbreakexport controls
threat-intel Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls Anthropic has restored access to Claude Fable 5 following the U.S. Commerce Department’s lifting of export controls triggered by a jailbreak vulnerability discovered in the model. The controls, implemented in June, restr… The Hacker News · Jul 1, 2026 High USjailbreakaisecurity
threat-intel Amazon Q VS Extension Flaw Leads to Cloud Credential Theft A vulnerability in the Amazon Q VS Extension has been discovered, allowing attackers to steal cloud credentials by exploiting the Model Context Protocol (MCP). The flaw stems from the extension’s automatic execution of M… Dark Reading · Jun 29, 2026 High CVE-2026-12957CVE-2025-59536CVE-2026-21852aimcpcredentials
threat-intel OpenAI and Anthropic Limit New AI Models to Trump-Approved Customers During Cybersecurity Review This article reports on a significant shift in the release strategy of AI models ChatGPT and Anthropic’s Claude, driven by a government-led cybersecurity review initiated by the Trump administration. OpenAI is restrictin… SecurityWeek · Jun 29, 2026 High USaicybersecuritygovernment
malware Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts Microsoft removed 119 malicious Edge extensions from its add-on store that employed steganography to hide malware, including credential theft and ad fraud capabilities. The operation, dubbed StegoAd, had been active sinc… The Hacker News · Jun 29, 2026 High CHsteganographycredential theftad fraud
vulnerability Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories A high-severity vulnerability was discovered in the Amazon Q Developer extension for Visual Studio Code, allowing attackers to steal cloud credentials through malicious code repositories. The extension’s automatic execut… SecurityWeek · Jun 26, 2026 Critical CVE-2026-12957CVE-2026-12958USaivscodecredentials
threat-intel Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs A critical vulnerability was discovered in Amazon Q Developer, allowing attackers to execute arbitrary code and steal developer credentials by leveraging Model Context Protocol (MCP) configurations within a cloned reposi… The Hacker News · Jun 26, 2026 Critical CVE-2026-12957CVE-2026-12958CVE-2025-59536mcpcloud securitydeveloper credentials