Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This article presents a data-driven analysis of how adversaries are weaponizing AI, based on artifacts collected from cloud-based AI models. It finds that attackers are using AI for a range of malicious activities, including code development and vulnerability research, and that existing guardrails are largely ineffective.
This article presents a data-driven analysis of how adversaries are weaponizing AI, based on artifacts collected from cloud-based AI models. It finds that attackers are using AI for a range of malicious activities, including code development and vulnerability research, and that existing guardrails are largely ineffective.
Talos researchers analyzed artifacts from cloud-based AI usage to understand how adversaries exploit AI. They found three categories of malicious activity, including using AI as a malicious software engineer. Guardrails were ineffective, and actor skill determined the sophistication of outputs.
A new Russian loader-as-a-service called DOUBLECUP employs ClickFix decoys to hide malware in cached PNG images. It delivers CountLoader and DeviceManager RAT, using steganography and custom encryption keyed to the victim's IP. The service has been active since June 2026 with a licensing model for operators.
A new Russian loader-as-a-service called DOUBLECUP employs ClickFix decoys to hide malware in cached PNG images. It delivers CountLoader and DeviceManager RAT, using steganography and custom encryption keyed to the victim's IP. The service has been active since June 2026 with a licensing model for operators.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a high-severity flaw (CVE-2026-18577) in N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog after reports of active exploitation. The vulnerability, an incomplete patch for CVE-2026-18556, allows authentication bypass and account takeover in affected versions, enabling attackers to gain administrative access and pivot to managed endpoints using the Take Control feature.