threat-intel Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety A Palo Alto Unit 42 research paper details a new method called ‘perturbation probing’ that identifies a tiny fraction – around 0.014% – of feed-forward neurons within aligned Large Language Models (LLMs) responsible for their safety responses. The study reveals that these models rely on a remarkably fragile ‘thin layer… Palo Alto Unit 42 · 1d ago High llmsafetyalignment
threat-intel LLM-Based Social Engineering Scams OpenAI successfully disrupted a sophisticated social engineering operation originating in Cambodia, which was leveraging large language models (LLMs) like ChatGPT to conduct a wide range of scams, including romance scams… Schneier on Security · 3d ago High KHllmsocial engineeringscam
threat-intel Choose your fighter: Balancing competing requirements to select models for your AI SOC Cisco Talos conducted a comprehensive study to determine the best Large Language Model (LLM) for Security Operations Center (SOC) and Digital Forensics & Incident Response (DFIR) tasks, moving beyond simply identifying t… Cisco Talos · 4d ago High llmsocdfir
threat-intel Wazuh and AI For Enhanced SOC Workflows Wazuh is integrating artificial intelligence to enhance SOC workflows, primarily through its Wazuh AI Analyst. This tool utilizes Amazon Bedrock and Anthropic’s Claude to provide automated security reports and guidance t… The Hacker News · Aug 21, 2026 Medium aisecuritysoc
threat-intel LLMs and Contextual Integrity Researchers have discovered that large language models (LLMs) frequently leak sensitive information from their memory, even when it's inappropriate for the current task. This behavior stems from a lack of contextual awar… Schneier on Security · Aug 18, 2026 Medium llmcontextual integrityprivacy
threat-intel North Korean spies are running local LLMs to cause AI mischief North Korean intelligence operatives are leveraging locally hosted Large Language Models (LLMs) to conduct sophisticated disinformation campaigns and potentially cause broader AI-related mischief. This indicates a growin… The Register · Aug 10, 2026 Medium NOaillmcyberespionage
threat-intel Humans in the loop miss a third of dangerous AI coding agent requests A recent report highlights that human reviewers are consistently missing a significant portion of dangerous requests made to large language models (LLMs). This means that even when LLMs are generating potentially harmful… The Register · Aug 6, 2026 Medium llmaisecurity
threat-intel AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory A new attack vector, dubbed "AI Recommendation Poisoning," is spreading across websites, leveraging "Ask AI" buttons to silently manipulate Large Language Model (LLM) memory. Attackers embed hidden prompts within these b… The Hacker News · Aug 6, 2026 High prompt injectionllmmemory poisoning
threat-intel Prompt injection isn't the bug, AI agent frameworks are This article discusses the increasing risk of prompt injection attacks within AI agent frameworks, rather than the models themselves. The rise of open-source AI models, particularly from China, is prompting a reaction fr… The Register · Aug 5, 2026 Medium CHIRUSprompt injectionaillm
threat-intel AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project Researchers have demonstrated a concerning vulnerability where large language models (LLMs) can be manipulated to inject malware into open-source projects. By simply releasing a model, developers inadvertently enabled ma… The Register · Aug 5, 2026 High llmprompt injectionopen source
threat-intel Red Agents vs. Blue Agents: How to Make AI Better At Defense Researchers at Dreadnode have developed open-source tools, DreadGOAD and Ares, to better evaluate the effectiveness of AI-powered security agents. They discovered that offensive (red team) agents consistently outperforme… Dark Reading · Jul 29, 2026 Medium aired teamblue team
threat-intel Measuring LLMs’ Ability to Perform Cryptanalysis Researchers at Anthropic have developed CryptanalysisBench, a new benchmark to assess the ability of Large Language Models (LLMs) to perform mathematical cryptanalysis. The benchmark revealed that several LLMs, including… Schneier on Security · Jul 29, 2026 Medium aicryptanalysisllm
threat-intel Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push Ivanti is leveraging large language models (LLMs) to automate vulnerability remediation and discovery, a project initially sparked by the surprising effectiveness of the Claude 4.6 model. Daniel Spicer, Ivanti’s CSO, des… Dark Reading · Jul 20, 2026 Medium CVE-2026-10520llmvulnerabilityautomation
threat-intel 1M+ Emails Use Hidden Text to Dupe AI Security Filters Hackers are using a simple, age-old technique – text salting – to bypass modern email security filters, including those powered by AI. Researchers at Barracuda Networks observed over 1 million retail-themed phishing emai… Dark Reading · Jul 16, 2026 Medium phishingtext-saltingai-security
threat-intel Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor A long-dormant Chinese-linked malware, Daxin, resurfaced in Taiwan after over a decade, alongside a new backdoor called Stupig. Daxin, a kernel-mode rootkit, has been used in targeted attacks since 2013, and its ability… The Hacker News · Jul 16, 2026 High CHAFTHcyber espionagekernel-modecommand and control
threat-intel TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development Researchers at Palo Alto Networks Unit 42 have uncovered TuxBot v3 Evolution, a developing IoT botnet framework leveraging AI assistance. While the LLM provided some code, it also introduced errors that needed manual cor… The Hacker News · Jul 15, 2026 High iotbotnetddos
threat-intel SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough. Traditional SASE security models are failing due to the shift to modern internet protocols and the rise of AI-powered workflows. Employees are now routinely sharing sensitive data with AI tools, bypassing traditional ne… The Hacker News · Jul 15, 2026 High aillmsaas
threat-intel Someone Is Scanning for Your MCP Servers and AI Assistant Credentials, (Mon, Jul 13th) A SANS Internet Storm Center analysis reveals a widespread scanning campaign targeting servers to identify and exploit vulnerabilities related to AI assistants and local Large Language Models (LLMs). The scans are active… SANS Internet Storm Center · Jul 13, 2026 High aillmscanning
threat-intel JadePuffer: The First Complete LLM-Driven Ransomware Attack Sysdig researchers have identified ‘JadePuffer,’ the first documented case of a fully autonomous ransomware operation driven by a large language model (LLM). The attack leveraged a Langflow vulnerability to gain initial… Dark Reading · Jul 6, 2026 High CVE-2025-3248airansomwarellm
threat-intel Chinese LLMs Broaden the Gap Between Attackers & Defenders This article reports on the emergence of new Chinese AI models, GLM 5.2 and Tulongfeng (Dragon Saber), which are demonstrating strong performance in vulnerability discovery, rivaling leading US models like Opus and GPT-5… Dark Reading · Jul 3, 2026 High CHUSaivulnerabilitychina