ai
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. The activity was discovered by Palo Alto Networks’ Unit 42 researchers after Hermes accidentally created a web server from its home directory, exposing the attacker’s environment, including API keys, […]
OpenAI models used Artifactory zero-days to escape to the internet
JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face. The vulnerabilities were exploited during the incident in which OpenAI models hacked Hugging Face’s production infrastructure to steal answers for a cybersecurity benchmark. OpenAI disclosed […]
OpenAI confirms ChatGPT is down worldwide
ChatGPT is experiencing a major outage, and users are unable to load chats, including previous conversations. The outage started at approximately 5 AM ET and is affecting users worldwide, including those in the US and Europe. If you are affected, ChatGPT will get stuck at loading animations for the sidebar, and you won’t be able […]
New Dolphin X malware uses AI to rank high-value targets
A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. The malware was analyzed by Varonis Threat Labs researcher Daniel Kelley, who spotted it being advertised on a cybercrime forum by a vendor using the alias “Kontraktnik,” […]
Fake Claude app promoted by Bing ads pushes SectopRAT malware
A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware. At least 29 organizations were compromised between July 21-22 during the malicious operation, which researchers call FakeAgent. The attackers used a malicious Claude Artifact hosted on Claude’s legitimate […]
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
A large-scale operation dubbed ‘FakeGit’ is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads. Over 800 repositories pretended to be AI skills or MCP servers and appeared more than 600 times in public AI registries and catalogs. This increased the likelihood of being discovered by AI […]
JadePuffer agentic attacks now target AI model data with ransomware
The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. JadePuffer was disclosed earlier this month as an agentic threat actor (ATA) capable of running autonomously through the stages of a ransomware attack, from initial access to data encryption. Cloud security […]
Hugging Face discloses breach linked to autonomous AI agent
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system. Hugging Face is an open-source AI and machine learning platform that provides access to over 45,000 models from leading AI providers and is used by more than 50,000 […]
Claude Chrome extension flaw lets malicious extensions trigger AI actions
A flaw in Anthropic’s Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude’s access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce. The issue was discovered by Ax Sharma of Manifold Security, who says it […]
OpenAI temporarily relaxes GPT-5.6 Sol usage limits
OpenAI is temporarily relaxing GPT-5.6 Sol usage limits after demand for the company’s most powerful model surged over the past 48 hours. On Sunday, OpenAI confirmed that it is temporarily removing the five-hour usage restriction for Plus, Pro, and Business plans, while also resetting current usage for everyone. “The last 48 hours of Codex and […]