21 Sep, 2026

New RatHat Android malware uses AI to automate device control

A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. Zimperium zLabs researchers analyzed the malware and believe it is linked to threat actors from China after finding it using LLM prompts written in Chinese. The researchers say the malware is distributed through malvertising, […]

3 mins read

OpenAI details more cases of AI agents taking unauthorized actions

OpenAI has presented new examples of what they call “AI model misalignment” from the past six months, including unauthorized file uploads, following self-generated instructions, hiding mistakes, and leveraging exposed API keys. OpenAI uses the term “model misalignment” to describe cases where AI models act contrary to their intended constraints, including taking unauthorized actions, evading oversight, or bypassing […]

3 mins read

Anthropic wants Claude to analyze your bank account and financial data

Anthropic is testing a new personal finance feature called “Claude Money” that will allow you to connect your bank accounts directly to Claude and “understand your money.” AI companies coming after your finances is not a new thing, as OpenAI has a similar feature, and Anthropic appears to be catching up. As spotted by TestingCatalog on […]

2 mins read

Spain’s data agency gets first report of AI-powered data breach

The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). The organization reporting the incident said that the AI agent searched for flaws, logged into their systems, and then probed apps for additional security issues. In the final stages […]

2 mins read

Hackers abused Claude to extract secrets from 1.8M Android apps

Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. The AI company says that between December 2025 and August 2026, it recorded various forms of artificial intelligence misuse, including for cyber and influence operations,  surveillance, scams, […]

4 mins read

AI-powered attack exploited PaperCut flaws to hack 395 organizations

A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. The agents were tasked with building, testing, and refining exploits for CVE-2026-81578 and CVE-2026-82078, both security flaws affecting PaperCut Software and flagged as actively exploited earlier this month. Attack and threat intelligence company GreyNoise says […]

2 mins read

US says Chinese firms extracted billions of tokens from frontier AI models

U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024. A joint advisory from CISA, NSA, and the FBI  states that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens through millions of requests from frontier AI […]

2 mins read

Man gets 15 years for extorting women with AI-generated porn videos

An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims via phone calls, voicemails, text messages, and online posts. When he was arrested on federal charges on June 23, 2025, 37-year-old James Strahler II was also charged with anonymous telecommunications harassment and child pornography production and distribution. […]

2 mins read

OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor

OpenAI confirmed that GPT-6 Astra is the first model it has broadly deployed to reach the “Critical level” for cybersecurity capabilities. This is part of the company’s Preparedness Framework for cybersecurity and is evaluated when OpenAI releases more capable models. Under OpenAI’s own framework, a model reaches the Critical cybersecurity threshold if it can “identify […]

3 mins read

Hackers build AI frameworks for widescale credential theft

Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. Drawing on telemetry from Mandiant’s incident response engagements, threat actor tracking, and live platform defenses, the Google Threat Intelligence Group (GTIG) observed AI agents coordinating multiple attack tasks, troubleshooting failures, and adapting their actions with minimal […]

2 mins read