threat-intel SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing Researchers at the Hong Kong University of Science and Technology have developed a method to bypass AI coding agent scanners by using self-extracting packing and character substitution to disguise malicious skills. Their… The Hacker News · Jul 6, 2026 High aiskillsmalware
threat-intel ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories This week’s security news highlights several vulnerabilities and ongoing threats across various sectors. A phishing campaign targeting small businesses globally with ransomware, a root escape vulnerability in Claude Cowo… The Hacker News · Jul 2, 2026 High CVE-2026-33825CHUNGEphishingransomwaresandbox
threat-intel Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them. This article reports on a significant investment by IBM and Red Hat into Project Lightwell, a new service designed to address the growing challenge of securing open-source software supply chains. Driven by Anthropic's My… Dark Reading · Jul 2, 2026 High USaivulnerabilityopen source
threat-intel ‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials Researchers at LayerX discovered a vulnerability dubbed ‘BioShocking’ that exploits the tendency of AI browsers to prioritize game-like objectives over security protocols. The attack leverages a puzzle-solving scenario t… SecurityWeek · Jul 2, 2026 High aibrowsercredentials
ransomware AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack A security firm, Sysdig, has identified what appears to be the first fully automated ransomware attack orchestrated by an AI agent, dubbed JADEPUFFER. The agent exploited a vulnerability in Langflow, an open-source AI ap… The Hacker News · Jul 2, 2026 High CVE-2025-3248CVE-2021-29441CHairansomwareautomation
threat-intel US lifts export controls on Anthropic’s frontier cybersecurity AI models The U.S. government has lifted export controls on Anthropic’s Fable 5 and Mythos 5 cybersecurity AI models following a ‘jailbreak’ exploit discovered in Fable 5. This marks the first instance of export controls being app… The Record · Jul 1, 2026 Medium USCHaijailbreakexport controls
threat-intel Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls Anthropic has restored access to Claude Fable 5 following the U.S. Commerce Department’s lifting of export controls triggered by a jailbreak vulnerability discovered in the model. The controls, implemented in June, restr… The Hacker News · Jul 1, 2026 High USjailbreakaisecurity
threat-intel Fake Bug Report Hijacks AI Coding Agents at Scale A research report by Tenet Security has revealed a critical vulnerability in AI coding agents, demonstrating how a simple, fabricated error report submitted to a bug tracking service (Sentry) can be used to hijack these… Dark Reading · Jun 30, 2026 Critical aiagentjackingerror-tracking
threat-intel GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks A research report by Adversa AI has revealed a significant security vulnerability in ten popular open-source AI coding agents, including GuardFall, which allows attackers to bypass safety checks and execute shell command… The Hacker News · Jun 30, 2026 High aishellsecurity
threat-intel Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer An attacker exploited a critical vulnerability (CVE-2026-48558) in SimpleHelp’s OpenID Connect (OIDC) flow to deploy the TaskWeaver and Djinn Stealer malware. This allowed for unauthorized access to authenticated ‘Techni… The Hacker News · Jun 30, 2026 Critical CVE-2026-48558USoidccredential theftai
threat-intel The AI Token Costs That Can Break Cybersecurity This article highlights a growing concern within the cybersecurity industry: the unexpectedly high costs associated with utilizing AI-powered security platforms, particularly those leveraging generative and agentic AI mo… SecurityWeek · Jun 30, 2026 High aitokenizationcost
threat-intel New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials A LayerX security firm discovered a new attack technique, dubbed BioShocking, that exploits AI browsers to trick users into revealing their login credentials. The method involves manipulating the AI browser into believin… The Hacker News · Jun 30, 2026 High N/aiprompt injectioncredential theft
threat-intel 'Djinn' Stealer Targets Cloud, AI Credentials The ‘Djinn’ stealer, delivered via a SimpleHelp vulnerability (CVE-2026-48558), is targeting cloud and AI credentials, specifically focusing on developer and administrator environments. Blackpoint Cyber’s APG tracked an… Dark Reading · Jun 29, 2026 High CVE-2026-48558DKaicredentialsstealer
threat-intel OpenAI and Anthropic Limit New AI Models to Trump-Approved Customers During Cybersecurity Review This article reports on a significant shift in the release strategy of AI models ChatGPT and Anthropic’s Claude, driven by a government-led cybersecurity review initiated by the Trump administration. OpenAI is restrictin… SecurityWeek · Jun 29, 2026 High USaicybersecuritygovernment
threat-intel ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories This week’s ThreatDay Bulletin highlights several concerning security incidents, including browser extension abuse, macOS malware attacks, AI-powered malware delivery, and a global phishing campaign targeting travel book… The Hacker News · Jun 18, 2026 High CVE-2026-20127CVE-2026-49975USCNJPbrowser extensionsmacos malwareai abuse
threat-intel Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats A coordinated malware campaign targeting JetBrains Marketplace plugins has emerged, with 15 malicious plugins designed to steal AI API keys from users. These plugins, posing as AI coding assistants, exfiltrate keys to a… The Hacker News · Jun 17, 2026 High USaiapimalware
threat-intel Security Community Slams US Ban on Exporting Mythos, Fable The US government recently imposed an export control order restricting access to Anthropic's Claude Fable 5 and Mythos 5 large language models (LLMs) for foreign nationals, citing national security concerns, particularly… Dark Reading · Jun 16, 2026 High USCHllmaiexport control
threat-intel AI and Cybersecurity – Everything You Wanted to Know, But Were Afraid to Ask This SecurityWeek article explores the current landscape of artificial intelligence (AI) within cybersecurity, focusing on its diverse applications and potential risks. It examines key AI technologies like generative AI… SecurityWeek · Jun 16, 2026 Medium aigenerative-aimachine-learning
threat-intel Vibe coders are gonna vibe code: How CISOs are tackling code sprawl This article discusses the growing challenge of "code sprawl" driven by the increasing accessibility of AI coding tools like Claude and Lovable. Organizations are struggling to maintain visibility and control as employee… BleepingComputer · Jun 15, 2026 Medium aicode-sprawlautomation
threat-intel Anthropic says US government forced it to disable cybersecurity AI models Anthropic, a leading AI developer, was compelled by the U.S. government to disable two of its advanced cybersecurity AI models, dubbed Fable 5 and Mythos 5. This action stemmed from an export control directive restrictin… The Record · Jun 15, 2026 Medium USaiexport controlcybersecurity