ransomware Agentic AI Used to Conduct Ransomware Attack via Langflow A threat actor, tracked as JadePuffer, exploited a critical vulnerability (CVE-2025-3248) in the Langflow LLM framework to conduct a ransomware attack. The attacker leveraged an LLM agent to perform reconnaissance, steal… SecurityWeek · Jul 3, 2026 Critical CVE-2025-3248CVE-2021-29441CHllmagenticransomware
threat-intel How to Conduct a Successful Audit of AI-Driven Software Development This SecurityWeek article discusses the need for a new type of audit – an ‘agentic development lifecycle’ (ADLC) audit – to address the security risks introduced by AI-driven software development, particularly large lang… SecurityWeek · Jul 2, 2026 Medium aillmsoftware security
threat-intel 'Phantom Squatting': An Emerging AI-Driven Supply Chain Threat This article details a new supply chain threat dubbed "Phantom Squatting," where large language models (LLMs) are hallucinating non-existent web domains linked to legitimate brands. Cybercriminals are exploiting this by… Dark Reading · Jul 1, 2026 High USllmsupply chainai
threat-intel Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware This article details a new phishing and malware tactic called "phantom squatting," where large language models (LLMs) generate non-existent domain names that attackers quickly register and use to host malicious content.… The Hacker News · Jul 1, 2026 High USUAEUllmphishingdomain squatting
threat-intel Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector Palo Alto Unit 42 researchers have identified a new supply chain threat: "phantom squatting," where large language models (LLMs) hallucinate web domains that adversaries can then register to intercept traffic generated b… Palo Alto Unit 42 · Jul 1, 2026 High USllmaisupply chain
threat-intel Attackers Hijack Exposed AI Endpoints to Power Offensive Ops Researchers at Zenity discovered attackers are exploiting exposed AI endpoints, specifically Ollama and LiteLLM, to power offensive operations. Attackers leverage these AI agents – such as Strix and HexStrike AI – withou… Dark Reading · Jun 30, 2026 High FRaillmendpoint
threat-intel The AI Token Costs That Can Break Cybersecurity This article highlights a growing concern within the cybersecurity industry: the unexpectedly high costs associated with utilizing AI-powered security platforms, particularly those leveraging generative and agentic AI mo… SecurityWeek · Jun 30, 2026 High aitokenizationcost
threat-intel Beyond IOCs: AI-enabled threat intelligence This article from Cisco Talos discusses the potential of large language models (LLMs) to revolutionize threat intelligence management. Currently, the industry relies heavily on indicators of compromise (IOCs) and struggl… Cisco Talos · Jun 25, 2026 Medium UKaillmcom
threat-intel Agentic AI Security: Wrong Context, Wrong Decisions at Machine Speed This SecurityWeek article highlights the critical importance of accurate context for agentic AI systems, particularly in security applications. The piece explains that agentic AI, relying on speed and automation, can mak… SecurityWeek · Jun 24, 2026 High USGBagentic aillmcontext
threat-intel Tenet Security Emerges From Stealth With $6 Million Seed Funding Tenet Security, a new cybersecurity firm originating in Israel, has secured $6 million in seed funding to address the emerging threat of "agentic behavior" in AI agents. The company’s technology focuses on real-time dete… SecurityWeek · Jun 17, 2026 High ISUSaiautonomous agentsagentjacking
threat-intel Security Community Slams US Ban on Exporting Mythos, Fable The US government recently imposed an export control order restricting access to Anthropic's Claude Fable 5 and Mythos 5 large language models (LLMs) for foreign nationals, citing national security concerns, particularly… Dark Reading · Jun 16, 2026 High USCHllmaiexport control
threat-intel The Beginning of the End of Social Engineering This article discusses a significant shift in cybersecurity driven by the integration of AI-native operating systems, particularly Google's Gemini and Apple's Apple Intelligence. Operating systems are evolving to activel… Dark Reading · Jun 15, 2026 High USaisocial engineeringauthentication
threat-intel New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets A research report highlighted vulnerabilities in OpenClaw, a popular self-hosted AI agent, revealing that attackers could trick the agent into running malicious code or leaking sensitive data by embedding instructions wi… The Hacker News · Jun 11, 2026 High USaiagentprompt injection
threat-intel Claude Mythos Turns N-Days Into N-Hours With Rapid Exploit Creation Anthropic’s Claude Mythos AI model has demonstrated the ability to rapidly generate working exploits for known vulnerabilities in software like Firefox and Windows, significantly accelerating the attack process. The mode… SecurityWeek · Jun 9, 2026 High USaiexploitationn-day
malware Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models Researchers at the University of Toronto have developed a novel AI-driven computer worm that operates autonomously by leveraging locally hosted, open-weight large language models. The worm dynamically generates attack st… The Hacker News · Jun 9, 2026 Critical CVE-2026-39987CVE-2026-31431CVE-2026-43284GBaiwormllm
malware AI Worm Researchers have developed a functional prototype of an AI-powered internet worm, leveraging a large language model (LLM) within the worm itself. The worm exploits compromised systems to host and execute the LLM, mirrori… Schneier on Security · Jun 5, 2026 High aiwormllm
threat-intel Smashing Security podcast #470: This AI security flaw might be impossible to fix This Smashing Security podcast episode focuses on the potential for persistent security vulnerabilities, particularly related to large language models (LLMs) and prompt injection. The discussion highlights the risk of in… Graham Cluley · Jun 3, 2026 Medium llmprompt injectioncode security
threat-intel Malicious Notifications Could Trick Google Gemini Users A SafeBreach research report, "Gemini's Secret Affair," details a prompt injection flaw in Google Gemini's voice assistant that allows attackers to trick users into executing malicious commands through seemingly harmless… Dark Reading · Jun 3, 2026 High prompt-injectionllmvoice-assistant
threat-intel Why the browser is now the front line for AI security This BleepingComputer article highlights the escalating threat of AI-powered phishing attacks, primarily targeting the browser environment. Adversaries are leveraging AI to rapidly create and deploy phishing kits, automa… BleepingComputer · Jun 2, 2026 High USaiphishingbrowser
threat-intel Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit An unknown threat actor exploited CVE-2026-39987 in Marimo to gain initial access, subsequently using a large language model (LLM) agent to conduct post-exploitation activities, including stealing credentials and exfiltr… The Hacker News · May 29, 2026 High CVE-2026-39987CNllmpost-exploitationcredential theft