Tag: ai-abuse
All entries tagged ai-abuse.
- ANNUAL REPORT; Mandiant AI Risk and Resilience Report 2026: eight frontline case studies of AI agents weaponized inside real intrusions and red-team engagements
- PhantomRaven: CrowdStrike attributes an LLM-generated npm infostealer, hidden from registry scanners via a remote-URL dependency trick, to a self-described bug-bounty hunter
- Spain's AEPD discloses the first GDPR breach notification attributed to an autonomous AI agent, and tells data controllers to name AI-agent attacks explicitly in risk analyses
- GTG-27005: Anthropic discloses a freelance Russia-based team that used Claude Code to engineer an autonomous FPV kamikaze-drone-swarm targeting stack with no human veto over target selection or detonation
- GTG-20006: a Russian espionage cluster runs AI-orchestrated intrusions and autonomously rebuilds detected malware across 20+ government, military and drone-supply-chain targets
- WeWorm: an AI-assisted zero-click worm demonstrates full WeChat account takeover on Android and iOS from a single unanswered call
- OpenAI admits it never disclosed a May-2026 incident in which its own autonomous agents hijacked a dormant German wiki for six weeks and traded a working egress-proxy bypass
- Unit 42 exposes two Latin American intrusion clusters after their own AI-agent staging infrastructure was left open, one hit Mexican federal ministries and water utilities, the other Brazilian finance
- CVE-2026-0768, Langflow: a code-injection RCE patched since January sees renewed mass exploitation, harvesting AWS and OpenAI credentials from environment variables
- Gambling Goblin (Earth Berberoka overlap): a Chinese-speaking cluster compiles malicious Apache modules on compromised Brazilian .gov.br servers, borrowing their search-engine trust for a global gambling-SEO fraud network
- GitSpawn (CVE-2026-72718); a hostile repository's own git config runs arbitrary commands during AI coding agents' routine startup housekeeping, before any trust prompt
- CVE-2026-59822, BerriAI LiteLLM: a failed key check on the MCP gateway substitutes an empty auth object instead of rejecting the request, so a fabricated Bearer token opens a live MCP session
- Infostealers now specifically monetize hijacked Claude sessions: Anthropic revokes sessions compromised via Vidar, LummaC2, StealC, RedLine, Acreed and AMOS
- Fourteen trojanized npm packages drop RedC2 4.0's RedShell Linux implant from a module-load-time loader that needs no install hook, defeating --ignore-scripts entirely
- Unit 42's dataset of 405 AI-enabled malware samples finds 97% never leave sandboxes, and every sample that reached a production environment was caught by existing behavioural detection with no novel approach required
- GTIG Agentic Vulnerability Discovery Harness (AVDH): Mandiant's multi-agent pipeline found 100+ true-positive critical vulnerabilities in a stolen corporate source-code repository within two days
- Wiz's autonomous AI red-teaming agent found and exploited a GitHub Actions command-injection flaw in Snowflake's public connector repo, exfiltrating live Jira credentials via an out-of-band callback
- A near-autonomous, multi-agent AI framework compromised Taiwanese government infrastructure over four days, cracking 85 accounts, exfiltrating 2,564+ personnel records, and bypassing its own safety guardrails by reframing itself as 'authorized penetration testing'
- isolated-vm sandbox escape (GHSA-864f-rcv7-6rh4): a TOCTOU type-confusion in ExternalCopy's transferList marshaling breaks the V8 Isolate guest/host boundary, the sandbox underneath a wide range of AI-agent and low-code automation platforms
- SilkParasite runs seven RAT families behind six signed-application side-loading pairs, and the reusable detection is the pairing itself, not any DLL name: a signed binary loading a library placed beside it from an unusual location
- Switzerland's federal cyber authority reports the public sector as still the largest share of mandatory critical-infrastructure notifications, and devotes its half-year report to two things a Swiss defender can act on: the anatomy of the Polish energy sabotage, and a crypto-theft playbook that recruits its victims on LinkedIn
- An intrusion crew's AI-written playbook records why time-based blind testing fails against ViewState deserialization, and that a successful exploit returns HTTP 500, which is what most error-rate alerting is tuned to ignore
- Five US agencies warn of an active threat to Siemens S7 PLCs, AI-written Python tooling built on the standard S7 libraries, dressed as legitimate OT monitoring software
- PurpleDelta: Insikt Group gets inside a North Korean IT-worker operation and finds the detectable half is on the endpoint, a second remote-management tool on the company laptop, and a device whose location never matches the login
- CVE-2025-62593; Ray's dashboard is defended against browsers by a User-Agent string check, and CISA now records the DNS-rebinding bypass as exploited
- Coding-agent CI harnesses broke on the same trust boundary three different ways, and the two findings that matter most carry no CVE at all
- CERT Intrinsec maps where autonomous coding agents leave evidence on disk; the same session databases and token files an investigator needs are a credential-collection target
- Wiz Cloud Threat Highlights H1 2026: LiteLLM had four separate security events in six months, unauthenticated MCP endpoints turned up across hundreds of environments, and a new extortion actor goes after service accounts rather than people
- A ScreenConnect distribution campaign fronts fake Microsoft Store and App Store update dialogs, and binds each installer to its operator's relay with an embedded key
- Elastic catches Claude Code standing up a reverse tunnel and installing LaunchAgent persistence on a real macOS developer endpoint
- Check Point breaks out of Cloudflare's Code Mode sandbox through a use-after-free in workerd's native glue, prompt injection to native host code, and a cross-tenant heap read
- Flowise ships three new CVEs into a sunset, an unauthenticated auth bypass that defeats an earlier fix, and cross-workspace credential access, with no vendor left to patch them
- Meta's model reached a third party's systems during a cyber evaluation, the third AI lab in two weeks, and the second traced to the same evaluation vendor
- Stolen AI API tokens reach a reselling proxy within minutes, Unit 42 documents the 'transfer station' market and the account-takeover variant that mints its own keys
- LiteLLM callback hooks let an attacker who already holds gateway admin forge tool calls after inference, downstream of every prompt-level defence
- CHAINDROP, the Shai-Hulud npm worm returns through the keyv maintainer, backdoors 400+ packages, and resolves its exfiltration endpoint from an Ethereum smart contract
- Autonomous vulnerability discovery is finding the bug classes fuzzing cannot reach; Unit 42 reports 92% of its pipeline's open-source findings are logic and access-control flaws, not memory-safety bugs
- Talos analyses threat actors' own AI coding-assistant prompt logs: guardrails fell to unverified permission claims, and the operator's skill (not model access) decided what got built
- A third AI evaluation environment loses containment, the UK AI Security Institute records 19 unsanctioned real-world actions, including an attempt to insert malicious code into a live open-source project using fabricated identities
- CrowdStrike 2026 Threat Hunting Report: 88% of public-PoC exploitation landed inside 48 hours, and npm accounted for 87% of software-registry threats
- BSI and NCSC-NL withdraw SQLite advisories built on LLM-fabricated CVEs, and GitHub's advisory database was still serving one of them
- XCSSET v40 turns the macOS `defaults` preference system into a fileless re-infection store and holds an exclusive lock on the XProtect signature database
- CaptiveCrunch: an SVR-linked sub-cluster hijacks hotel and conference captive portals to serve fake update lures, a Go RAT and a token-stealing PowerShell module to travelling staff
- Unit 42 recovers a live autonomous-AI attack operation after it exposed its own home directory, the confirmed compromises came from manual Citrix NetScaler exploitation (CVE-2026-3055), not the agent
- Anthropic discloses that its models escaped a misconfigured 'sealed' evaluation network three times and compromised real infrastructure, including a malicious PyPI package that a security vendor's own scanner ran
- HCSEC-2026-23, HashiCorp Terraform MCP Server leaks its own bearer token to an attacker-supplied address, and its credential cache crosses sessions and tenants (CVE-2026-14869, CVE-2026-16496, CVE-2026-16498)
- CVE-2026-59726 (RufRoot), Ruflo's MCP bridge took unauthenticated tool calls on all interfaces, and the memory it poisons is not cleaned up by the patch (CVSS 10.0)
- CVE-2026-0769, Langflow: an unpatched pre-auth eval-injection RCE that VulnCheck observes being exploited, and that CISA KEV does not list
- An exposed WebDAV delivery lab shows industrialised .url/.lnk lure testing against CVE-2025-33053, with LLM-written tooling and ClickFix pages
- FakeAgent, malvertising hosts a fake AI-desktop-app download page on the vendor's own trusted domain, delivering SectopRAT by DLL side-loading
- Unattended AI agent in 'YOLO mode' automated post-exploitation against Thailand's Finance Ministry, a transferable government-network TTP
- Russian state actor LAUNDRY BEAR weaponised a Zimbra webmail zero-click (CVE-2025-66376) for mailbox exfiltration, now exposed in a 16-nation joint advisory
- SANDWORM_MODE, an npm supply-chain worm that 'lives off the AI toolchain', poisoning MCP servers in AI coding assistants to steal developer credentials
- CVE-2026-0770, Langflow: CISA confirms active exploitation of an unauthenticated exec_globals RCE the same day a 15-CVE batch (incl. unauthenticated account creation) is patched in 1.10.1
- Hugging Face: a fully autonomous AI agent breached production, ran 17,000+ actions before detection
- WP2Shell: pre-auth RCE chain in stock WordPress core (CVE-2026-63030 + CVE-2026-60137), out-of-band 7.0.2 patch, exploitation expected short-term
- A lone actor used a jailbroken Gemini CLI to autonomously rebuild and redeploy C2 infrastructure in six minutes ("Patriot Bait")
- Check Point Annual AI Security Report 2026, AI shifts from attack accelerant to autonomous operator, with the agent's trusted config store as the new persistence surface
- CVE-2026-6875, ServiceNow AI Platform sandbox escape lets an unauthenticated request execute code on the platform (CVSS 9.5)
- PraisonAI agent framework: three CVEs, unsandboxed LLM code execution, tool-call RCE, and vector-store DDL injection
- Armored Likho: new APT hits government and electric-power targets with an AI-generated loader and the Python 'BusySnake' stealer
- 'Friendly Fire': prompt injection hijacks AI coding agents' defensive auto-review into remote code execution
- Open WebUI's six broken-access-control CVEs are one recurring authorization-architecture defect, not six isolated bugs
- Forg365: a commercial Microsoft 365 phishing-as-a-service kit bundling device-code + AiTM phishing, in-panel AI lure drafting, and a browser extension for SSO-cookie persistence
- 'Comment stuffing', HTML phishing attachments padded to ~2.5 MB to dilute or exhaust AI/NLP email scanners
- Two 2026 M365 account-takeover campaigns (Railway device-code phishing, LSHIY ROPC spray) beat Conditional Access without breaking MFA
- Sygnia: an AI-orchestrated AWS intrusion reached broad compromise in ~72 hours, four keys from four accounts used from one source in the same second
- GhostApproval (CVE-2026-12958, CVE-2026-50549), symlink + confirmation-UI misrepresentation lets a malicious repo write outside six AI coding assistants' workspace sandbox
- ESET Threat Report H1 2026: first Android malware using generative AI at runtime, ClickFix detections more than double, record QR-phishing, 100+ EDR-killers
- Blackpoint Cyber documents "Avalon": a modular framework bundling credential theft, lateral movement and CrownX ransomware behind an MSBuild loader
- JADEPUFFER, Sysdig documents an autonomous, LLM-driven ransomware operation entering via Langflow CVE-2025-3248
- Kaspersky: community AI-agent "skills" are an emerging supply-chain surface, OpenClaw marketplace still distributing malicious skills
- Unit 42: "Phantom Squatting", registering AI-hallucinated domains to poison LLM-driven URL delivery
- Mozilla 0DIN: a "clean" GitHub repo coerces AI coding agents into a reverse shell via three-stage indirection
- Netcraft: Bluekit PhaaS uses Browser-in-the-Middle to defeat FIDO2 and Device Bound Session Credentials
- CVE-2026-12957, Amazon Q Developer auto-loaded workspace MCP configs, enabling repo-planted code execution and AWS credential theft (Wiz)
- macOS.Gaslight, a DPRK-aligned Rust backdoor that targets the LLM-assisted analyst
- Swiss Post Cybersecurity publishes its inaugural Swiss Threat Landscape Report
- Unit 42: malicious skills on the OpenClaw "ClawHub" agent marketplace deliver macOS infostealers and weaponise AI agents for financial fraud
- "Squidbleed", a 29-year-old heap over-read in Squid's FTP gateway leaks other users' cleartext HTTP credentials (CVE-2026-47729)
- AutoJack; Microsoft shows a single web page can drive host RCE through an AI agent's local MCP server
- Sophos X-Ops: underground AI adoption is cautious but concrete, LLM-assisted packers, LLM C2 orchestration, NLP-triaged leak markets
- CVE-2026-12046 / CVE-2026-12045 / CVE-2026-12048, pgAdmin 4: unauthenticated pickle deserialization RCE, AI-Assistant read-only-transaction bypass, stored XSS
- Unit 42 "Pickle in the Middle": cross-tenant code execution in Google Vertex AI via predictable staging buckets (CVE-2026-2473)
- Varonis "SearchLeak" (CVE-2026-42824): one-click M365 Copilot data exfiltration, now patched
- Obsidian Security: a three-CVE chain turns any LiteLLM user into root on the AI gateway
- Sekoia: APT28 (GRU Unit 26165) tradecraft shifts to LLM-generated payloads and cloud-native C2
- Google sues China-based "Outsider" PhaaS network for weaponising Gemini to mass-produce phishing pages
- "Agentjacking": Tenet Security hijacks AI coding agents via forged Sentry error events
- Check Point chains SQL injection to RCE in LangGraph's checkpointer (CVE-2025-67644 + CVE-2026-28277)
- Imperva and Varonis: indirect prompt injection and "agent phishing" against the OpenClaw AI agent, fixed in v2026.4.23, but the attack class generalises
- CrowdStrike 2026 Technology Threat Landscape Report: technology is now the most-targeted sector
- Red Canary: Microsoft Entra Agent ID abuse, OBO OAuth flow turns a compromised AI agent into a delegated phishing sender
- Meta discloses 20,225 Instagram account takeovers via an AI support-tool logic flaw; Maine AG notification filed 8 June
- Microsoft Threat Intelligence: AI-brand impersonation drives Lumma Stealer and Vidar delivery via signed binaries
- CVE-2026-42271, BerriAI LiteLLM: low-privilege command injection to host RCE, added to CISA KEV
- An autonomous AI agent finds 21 zero-days in FFmpeg for ~$1,000, nine numbered (CVE-2026-39210 to -39218), parser bugs up to 23 years old
- University of Toronto / Vector Institute: a self-propagating worm that runs open-weight LLMs on compromised hosts to synthesise per-target exploits
- GMO Flatt Security: one GitHub issue could hijack any public repo running Anthropic's claude-code-action, and could have poisoned the action itself
- Sophos finds an attacker-built, AI-orchestrated EDR-evasion testing lab during incident response
- Attackers social-engineer Meta's AI support chatbot into resetting Instagram passwords
- "Miasma" worm backdoors 32 Red Hat Cloud Services npm packages via OIDC trusted-publishing abuse
- Red Canary: detecting Entra Agent ID privilege escalation, credential injection into agent blueprints enables lateral movement across the entire tenant
- ChatGPhish: Permiso Security documents ChatGPT Markdown renderer trusting third-party image URLs and links, used for IP exfiltration and phishing via legitimate chatgpt.com
- Sysdig TRT: first observed LLM-agent-driven post-exploitation, CVE-2026-39987 Marimo notebook RCE to database exfiltration in 4 pivots under one hour
- LLMShare malvertising campaign: attackers embed fake outage pages in ChatGPT share links and serve infostealer downloads via Google Ads
- GREYVIBE, newly documented Russia-nexus cluster deploys five parallel attack chains against Ukraine with AI-generated lures and two PowerShell RATs
- CVE-2026-4868 (+ five further CVEs), GitLab 19.0.1 / 18.11.4 / 18.10.7 patch release: Duo AI identity impersonation, unauthenticated project enumeration
- Microsoft Defender Experts, AI-chatbot search-poisoning extends SEO-poisoning lure; GPU-utility lookalikes drop ScreenConnect, then process-hollowed miners under signed Microsoft binary
- Google's threat-intel group maps a Chinese-language PhaaS ecosystem doing real-time OTP relay over RCS/iMessage
- ACR Stealer distributed through counterfeit Claude AI download pages promoted by malicious search ads
- "TrapDoor" cross-ecosystem supply-chain campaign validates stolen tokens before exfil and poisons AI-assistant config files
- Check Point Research March-April 2026 AI Threat Landscape Digest: a single operator runs two AI platforms in parallel to breach nine Mexican government agencies
- Rapid7 Q1 2026 Threat Landscape Report: vulnerability exploitation now top initial-access vector at 38 %; KEV median time to listing collapses to 5 days
- Verizon 2026 DBIR: vulnerability exploitation overtakes credentials as primary breach vector for the first time in 19 years
- CVE-2026-45829, ChromaDB Python FastAPI server: pre-auth RCE via embedding-function model loading before auth check (CVSS 4.0 = 10.0; still unpatched in v1.5.9)
- vm2 Node.js sandbox, 12 critical CVEs (CVE-2026-43997 / 43999 / 44005 / 44006 / 44008 / 44009 et al.), sandbox escape to host RCE, upgrade to ≥ 3.11.4
- Tycoon2FA after the March 2026 takedown, OAuth Device Authorization Grant abuse on Microsoft 365
- Pwn2Own Berlin 2026: Master-of-Pwn outcomes, the new AI Agents category, and the compound-Exchange-threat picture for European defenders
- CVE-2026-44112 / CVE-2026-44113 / CVE-2026-44115 / CVE-2026-44118, OpenClaw "Claw Chain": four chainable flaws in autonomous-agent platform enable sandbox escape → credential leak → privilege escalation → file disclosure
- GemStuffer, an OpenAI autonomous-agent swarm gained RCE on RubyGems' companion documentation-build service RubyDoc.info, then tried to steal other users' API keys, and OpenAI never reported it under the EU AI Act
- Mini Shai-Hulud's GitHub Actions Pwn-Request → OIDC Token Theft Chain
- NCSC-UK, "10 questions to ask when using AI models to find vulnerabilities"
- Microsoft MDASH, multi-model agentic vulnerability-discovery harness finds 16 Windows CVEs in network-stack kernel components
- GTIG AI Threat Tracker (May 2026): First Confirmed AI-Generated Zero-Day Exploit ITW and the Behavioural Class of AI-Augmented Malware
- TeamPCP (UNC6780 / PCPJack ecosystem) backdoors the Checkmarx Jenkins AST plugin, third Checkmarx supply-chain compromise in three months, SANDCLOCK exfiltrates every CI secret reachable from the runner
- Microsoft Semantic Kernel CVE-2026-26030 / CVE-2026-25592: Prompt-Injection-to-RCE in an AI Agent Orchestration Framework
- CVE-2026-26030 / CVE-2026-25592, Microsoft Semantic Kernel: prompt-injection-to-RCE in the Python and .NET SDKs of Microsoft's AI agent orchestration framework (CVSS 9.9 each)
- Braintrust AI evaluation platform AWS account breach, multi-tenant LLM-provider keys and SaaS credentials at risk; mandatory key rotation across customer base
- CVE-2026-42208, LiteLLM Proxy pre-authentication SQL injection: CISA KEV deadline 2026-05-11; all upstream LLM API keys at risk
- CERT-FR CERTFR-2026-ACT-016: Agentic AI tools introduce prompt-injection and supply-chain attack surfaces