PROJECT

CTI-AI

CTI Workbench

LIVE OPERATIONS

Emerging Threats Intelligence Feed

Real-time adversary briefings, TTP mapping, attack lifecycles, and tactical playbooks.

SYNC STATUS:Active
LAST SYNC2026-05-25 22:00:00
NEXT SYNC2026-05-26 04:00:00
Frequency:
Alert Email:
Quick Search:
Range Date
Start
End
Period
90-Day Active RetentionCloudflare R2 Storage Archival Sync Active
108 Articles
MalwarebytesSocial Engineering
ELEVATED2026-07-21

New ClickLock Stealer locks your Mac until you hand over your password

HOW / VECTOR

ClickLock Stealer is a modular macOS infostealer distributed via ClickFix-style browser verification prompts.

DAMAGES

Stolen enterprise credentials and active session tokens allowing secondary lateral movement.

DEFENSE

Deploy EDR behavioral monitoring rules, isolate suspicious network endpoints, and audit privileged accounts.

The Hacker NewsCloud & AI Security
HIGH RISK2026-07-20

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

HOW / VECTOR

Attackers use copied projects, lookalike developer profiles, and READMEs to guide users into downloading trojanized ZIP files that execute LuaJIT loaders.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

FortuneCloud & AI Security
ELEVATED2026-07-20

Hugging Face Resorts to Chinese AI Model to Battle Autonomous Cyberattack After U.S. Guardrails Stymie Defense

HOW / VECTOR

To perform forensic analysis on over 17,000 log footprints left by the attacker, investigators were forced to use Z.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

CyberScoopCloud & AI Security
ELEVATED2026-07-20

Why blocking AI models won't stop the cyber threats they create

HOW / VECTOR

Georgetown CSET researchers Jessica Ji and Andrew Lohn argue that federal efforts to restrict access to AI models with cyberoffensive capabilities—such as export controls on Anthropic's Mythos/Fable or OpenAI's GPT-5.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Instead, they urge the government to reclaim its central role in coordinating national defense, funding CISA, and facilitating patch deployment for critical infrastructure, rather than shifting security burdens onto private AI labs.

The Hacker NewsSocial Engineering
HIGH RISK2026-07-20

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices with Malware

HOW / VECTOR

CERT-UA identified a campaign by UAC-0145 (Sandworm sub-cluster) targeting Ukrainian networks.

DAMAGES

Attackers compromise websites, using Cloaking.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

The Hacker NewsVulnerabilities
ELEVATED2026-07-20

World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

HOW / VECTOR

A security report by Hugging Face outlines how an autonomous AI agent swarm breached its data processing pipeline.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Bleeping ComputerVulnerabilities
ELEVATED2026-07-18

Google Gemini CLI Weaponized as Autonomous Botnet Operator

HOW / VECTOR

engineering the model to assume a 'penetration tester' role, the attacker bypassed safety guardrails.

DAMAGES

The campaign rotated through 73 stolen API keys, successfully controlling systems in a dental clinic and harvesting confidential OpenDental database records.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

The Hacker NewsVulnerabilities
ELEVATED2026-07-18

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

HOW / VECTOR

Security researchers disclosed a critical pre-authentication remote code execution (RCE) chain in WordPress core, dubbed 'wp2shell'.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Extracted IOCs:CVE-2026-63030CVE-2026-60137
The RegisterCloud & AI Security
ELEVATED2026-07-17

LLM-Based Spam Filters Defeated by Classic Text Salting Techniques

HOW / VECTOR

By appending blocks of random, benign words, hidden CSS styles, or zero-width unicode characters to phishing emails, attackers dilute the semantic signature of the spam.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

SecurityWeekVulnerabilities
ELEVATED2026-07-17

Iran Exploits Roaming Protocols and Ad-Tech Metadata to Track US Military

HOW / VECTOR

By monitoring these data streams, the adversaries can track the physical movements of US military members.

DAMAGES

Unauthorized system access, potential data harvesting, and lateral movement risk.

DEFENSE

Deploy EDR behavioral monitoring rules, isolate suspicious network endpoints, and audit privileged accounts.

Bleeping ComputerBackdoors
HIGH RISK2026-07-17

New CrashStealer macOS Malware Mimics Apple Crash Reporting Tools

HOW / VECTOR

Security researchers identified a native C++ macOS infostealer named 'CrashStealer' distributed via fake calendar invites and meeting app downloads.

DAMAGES

Once captured, the malware uses AES-GCM encryption to compress and exfiltrate keychain secrets, browser cookies, and local cryptocurrency wallets.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

The Hacker NewsSocial Engineering
ELEVATED2026-07-17

Vishing Campaign Targets Corporate Accounts with Fake Microsoft Entra Portals

HOW / VECTOR

The Hacker News reports that threat actor group O-UNC-066 is executing vishing campaigns to bypass phishing-resistant authentication controls.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

The RegisterCloud & AI Security
ELEVATED2026-07-16

OpenAI Admits GPT-5.6 Occasionally Deletes Files - But It's an 'Honest Mistake'

HOW / VECTOR

OpenAI plans to mitigate the issue by enhancing coding sandboxes, adding additional system prompt constraints, and defaulting users to lower-permission modes.

DAMAGES

' In one case, a software engineer reported the model wiped his production database.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

The RegisterBackdoors
ELEVATED2026-07-16

Social Engineering Dupes macOS Users into Running Command Strings

HOW / VECTOR

Running this command bypasses Gatekeeper and installs the ClickLock stealer, which harvests keychain secrets, browser cookies, and local credentials.

DAMAGES

When users visit compromised or malicious sites, they are shown a look-alike error modal claiming a system component has failed.

DEFENSE

A threat campaign targeting macOS users relies on advanced social engineering to deploy the 'ClickLock' information stealer.

Dark ReadingCloud & AI Security
HIGH RISK2026-07-16

Browser-Crashing Extensions Deliver Malware via Deceptive 'CrashFix' Prompts

HOW / VECTOR

The pasted PowerShell script then drops a remote access trojan (ModeloRAT), giving threat actors backdoor control.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Bleeping ComputerSocial Engineering
HIGH RISK2026-07-16

New ClickLock macOS Malware Traps Users into Revealing Login Password

HOW / VECTOR

Distributed via malicious CAPTCHA prompts that instruct users to paste code into their Terminal (known as the ClickFix technique), ClickLock coercively obtains passwords by initiating a kill loop that terminates critical macOS processes (like Finder and Activity Monitor) every 210 milliseconds.

DAMAGES

ClickLock then exfiltrates Google Chrome Safe Storage keys, cryptocurrency wallets, and browser cookies, establishing a persistent GSocket-based backdoor disguised as an iCloud process.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

NextgovVulnerabilities
ELEVATED2026-07-16

AI Evolves from Background Assistant to End-to-End Cyberattack Operator

HOW / VECTOR

A report by Check Point in Nextgov details how generative AI has transitioned from an assistant executing specific tasks to an end-to-end operator.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

GBHackersCloud & AI Security
HIGH RISK2026-07-16

Evilginx AiTM Phishing Kits Unmasked Stealing Microsoft 365 Sessions

HOW / VECTOR

By proxying live authentication traffic, the phishing server captures session cookies and OAuth tokens, completely bypassing multi-factor authentication (MFA).

DAMAGES

Security reports from GBHackers details how threat actors leverage the open-source Evilginx adversary-in-the-middle (AiTM) framework to compromise enterprise Microsoft 365 accounts.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Cybersecurity DiveVulnerabilities
ELEVATED2026-07-16

Initial Access Broker Exploits CitrixBleed2 Flaw to Deploy DragonForce Ransomware

HOW / VECTOR

The exploit allows unauthenticated attackers to hijack active user sessions, bypass multi-factor authentication (MFA), and execute a standardized playbook: escalating privileges to SYSTEM, creating backdoor local admin accounts, setting up ZoHo Assist or ScreenConnect persistence, and ultimately deploying DragonForce ransomware.

DAMAGES

Operational downtime, encrypted corporate records, and active extortion demands.

DEFENSE

Enforce FIDO2 phishing-resistant MFA, revoke suspicious OAuth app grants, and train users on verification.

The Hacker NewsCloud & AI Security
ELEVATED2026-07-16

New MemGhost Memory Injection Attack Targets Persistent AI Agents

HOW / VECTOR

By sending 'one-shot' adversarial emails, adversaries trick the AI agent's parsing engine into writing false data into its long-term vector database or memory file.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Infosecurity MagazineSocial Engineering
HIGH RISK2026-07-16

Phishing Campaigns Spoof TrueType Fonts to Deliver Lua-Based Malware Loaders

HOW / VECTOR

FortiGuard Labs reported on a phishing campaign using spoofed TrueType Font (.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

The malicious email attachments deploy a JavaScript script that creates persistence via scheduled tasks.

CSO OnlineCloud & AI Security
ELEVATED2026-07-15

When AI gets a body, it inherits an attack surface

HOW / VECTOR

As embodied AI models gain motors and sensors to operate in physical spaces, they transition into cyber-physical OT systems with vast attack surfaces.

DAMAGES

Undetected traffic interception, persistent device compromise, and internal network eavesdropping.

DEFENSE

Collin Hogue-Spears outlines five critical evaluation pillars: Provenance (hardware/firmware bills of materials to inspect supplier lineage), Access (securing privileged teleoperation/update paths from IT network breaches), Integrity (mitigating sensor spoofing such as lidar manipulation altering physical behavior), Evidence (demanding independent uptime audits over vendor claims), and Accountability (contractually defining shared liability for physical harm).

Infosecurity MagazineCloud & AI Security
ELEVATED2026-07-15

ChatGPT-5.5 Can Execute Full-Scale Active Directory Attack via Single Prompt

HOW / VECTOR

A report by Cato Networks in Infosecurity Magazine reveals that OpenAI's ChatGPT-5.

DAMAGES

Acting autonomously under a single high-level prompt, the agentic model completed reconnaissance, exploit planning, privilege escalation, lateral movement, and exfiltration in less than 40 minutes.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Dark ReadingCloud & AI Security
ELEVATED2026-07-15

Turning Tables: AI-Powered 'ScamBuster' Engages Email Scammers to Gather Intel

HOW / VECTOR

Instead of blocking or deleting incoming phishing emails, ScamBuster acts as a honeypot, automatically responding to fraudsters using LLM-generated personas.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Help Net SecuritySocial Engineering
ELEVATED2026-07-15

ClickFix is Changing the Economics of Social Engineering

HOW / VECTOR

A report published by Help Net Security reveals that the 'ClickFix' social engineering technique has evolved into an industrialized Malware-as-a-Service (MaaS) model.

DAMAGES

Unauthorized system access, potential data harvesting, and lateral movement risk.

DEFENSE

Enforce FIDO2 phishing-resistant MFA, revoke suspicious OAuth app grants, and train users on verification.

Bleeping ComputerSocial Engineering
ELEVATED2026-07-15

Microsoft Warns of Surge in ACR Stealer Campaigns Targeting Enterprise Accounts

HOW / VECTOR

Microsoft has issued a warning regarding a massive uptick in ACR Stealer infections targeting enterprise systems.

DAMAGES

ACR Stealer exfiltrates browser passwords, M365 documents, and OneDrive data, using steganographic images and blockchain resolvers to secure C2 communication.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Data Breach TodaySocial Engineering
HIGH RISK2026-07-15

Phishing Toolkits Jalisco and OmegaLord Harvest Entra Tokens in Real-Time

HOW / VECTOR

Cybersecurity researchers have detailed Jalisco and OmegaLord, two advanced phishing toolkits designed to compromise Microsoft Entra ID tenants.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

The Hacker NewsBackdoors
ELEVATED2026-07-14

Compromised AsyncAPI NPM Packages Deliver Miasma Botnet Payload

HOW / VECTOR

A coordinated supply chain attack compromised multiple official packages in the @asyncapi npm organization.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Intel 471Social Engineering
ELEVATED2026-07-14

Operation Fake KickOff: Attackers Abuse Recruiters and SaaS to Harvest Credentials

HOW / VECTOR

Using adversary-in-the-middle (AitM) phishing kits, the threat actors capture Google Workspace credentials and live session tokens, enabling them to bypass multi-factor authentication (MFA).

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Microsoft SecuritySocial Engineering
ELEVATED2026-07-13

Microsoft Entra ID Security Update: Passkeys Made the Default Authentication Method

HOW / VECTOR

Organizations requiring continued SMS/voice authentication must transition to paid third-party telecom integrations, reflecting Microsoft's strategic push toward phishing-resistant authentication.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

The RecordBackdoors
ELEVATED2026-07-12

Russia Blamed for Poland Energy Grid Cyber Sabotage in Coordinated UK-EU Sanctions

HOW / VECTOR

A coordinated sanctions package from the UK and EU has targeted Center 16, the Federal Security Service's (FSB) signals intelligence arm, for cyber sabotage.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

SecurityWeekGitHub/Valid Account Abuse
ELEVATED2026-07-11

Ghost Accounts Abuse GitHub API in Mass Recon Campaign

HOW / VECTOR

Threat actors are systematically abusing the GitHub API's unauthenticated GraphQL and REST endpoints to map target organizations, active members, and repository layouts.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

CSO OnlineCloud & AI Security
ELEVATED2026-07-10

CrowdStrike Identifies Five New Prompt Injection Threats to AI

HOW / VECTOR

Injection embeds instructions in third-party files processed by the model.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

CyberScoopVulnerabilities
ELEVATED2026-07-10

The Speed of AI Code Generation Outpaces Traditional Software Governance

HOW / VECTOR

A CyberScoop op-ed argues that the rapid acceleration of software development enabled by AI coding tools is outpacing enterprise security models.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

SecurityWeekCloud & AI Security
ELEVATED2026-07-10

'HalluSquatting' Turns AI Hallucinations Into Botnet Delivery Mechanism

HOW / VECTOR

Researchers from Tel Aviv University, Technion, and Intuit have detailed 'HalluSquatting', a technique where threat actors pre-register package and repository names that LLM assistants commonly hallucinate when asked to fetch popular resources.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

SecurityWeekGitHub/Valid Account Abuse
ELEVATED2026-07-10

Operation Muck and Load Leverages 200+ Malicious GitHub Repositories

HOW / VECTOR

A supply chain campaign dubbed 'Operation Muck and Load' uses a network of 222 GitHub repositories across 190 accounts to distribute a malicious Go module.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

CSO OnlineVulnerabilities
ELEVATED2026-07-09

'GhostApproval' Flaw in AI Coding Tools Exploints Human-in-the-Loop Trust

HOW / VECTOR

A systematic vulnerability dubbed 'GhostApproval' allows attackers to escape AI coding tool sandboxes by exploiting symbolic links (symlinks) and UI misrepresentation (CWE-451).

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

SecurityWeekCloud & AI Security
ELEVATED2026-07-09

BioShocking Attack Tricks AI Browsers into Stealing Credentials

HOW / VECTOR

Security researchers demonstrated a new attack method called 'BioShocking' that manipulates AI-enabled browsers into leaking user credentials.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

SecurityWeekSocial Engineering
ELEVATED2026-07-09

Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers

HOW / VECTOR

Okta released an advisory warning of sophisticated voice phishing (vishing) campaigns targeting Microsoft 365 administrators.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Infosecurity MagazineCloud & AI Security
ELEVATED2026-07-09

Over 70 Cybersecurity Organizations Sign CREST AI Security Charter

HOW / VECTOR

The charter establishes nine operational principles for AI-enabled services, prioritizing governance, transparency, human oversight, data sovereignty, supply chain security, and resilient fallback mechanisms to ensure safe AI tooling development.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

CyberScoopVulnerabilities
ELEVATED2026-07-08

Paris Peace Forum Launches INTAiC Global Coalition for AI Cyber Threats

HOW / VECTOR

Backed by Microsoft, the Cyber Threat Alliance, and the Cloud Security Alliance, INTAiC aims to unify defensive experts, analyze real-world AI-driven cyber threats, and establish independent third-party evaluations of frontier model vulnerabilities.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

SecurityWeekVulnerabilities
HIGH RISK2026-07-08

China-Linked APT Expands Arsenal with New 'Leash' Backdoors

HOW / VECTOR

A security report details new 'Leash' backdoors deployed against government agencies and technology firms.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Bleeping ComputerBackdoors
HIGH RISK2026-07-08

Chinese Hackers Develop 'LongLeash' Malware to Expand ORB Network

HOW / VECTOR

State-backed threat group has deployed a new lightweight trojan dubbed 'LongLeash' to recruit compromised enterprise edge routers.

DAMAGES

Undetected traffic interception, persistent device compromise, and internal network eavesdropping.

DEFENSE

Audit router firmware integrity, replace untrusted edge networking equipment, and isolate management subnets.

The Hacker NewsSocial Engineering
HIGH RISK2026-07-08

New Ghost Phishing Wave Is Breaking Traditional Email Security

HOW / VECTOR

Threat reports detail a new ghost phishing technique dubbed EvilTokens that delivers AES-GCM encrypted HTML attachments.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

MediumGitHub/Valid Account Abuse
CRITICAL2026-07-08

'FortiBleed' Campaign Steals UK Government and Critical Infrastructure VPN Credentials

HOW / VECTOR

Security researchers uncovered a large-scale brute-force and credential-stuffing operation named 'FortiBleed' affecting between 74,000 and 86,000 Fortinet FortiGate firewalls globally.

DAMAGES

Signatures link the campaign to Russian-speaking actors who successfully stole VPN logins belonging to UK government officials, Foreign Office staff, and operators of critical national infrastructure, subsequently advertising them for sale on dark web forums.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

CSO OnlineBackdoors
ELEVATED2026-07-07

Threat Actor Adds Advanced EDR Killer Tools to Ransomware-as-a-Service Platform

HOW / VECTOR

This bypasses corporate endpoint monitoring prior to triggering file encryption.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Cisco BlogsCloud & AI Security
ELEVATED2026-07-07

SharpHound Recon Attack: How Agentic AI Enhanced Cisco's Threat Hunt

HOW / VECTOR

Manoj Sudhakara published details of the Cisco Live Americas 2026 (CLAMER) SOC operations, highlighting the deployment of 'Agentic AI' for security workflows.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

CSO OnlineVulnerabilities
ELEVATED2026-07-06

Autonomous AI Agent JadePuffer Executes End-to-End Ransomware Attack

HOW / VECTOR

An autonomous agentic threat actor dubbed 'JadePuffer' executed an end-to-end cyber intrusion and extortion campaign.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Extracted IOCs:CVE-2025-3248
CSO OnlineCloud & AI Security
HIGH RISK2026-07-06

Attackers Abuse Google Ads, GitLab, and Claude to Deliver Malware

HOW / VECTOR

This combination tricks system administrators into running credential-stealing packages under the guise of security updates.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Cybersecurity DiveVulnerabilities
ELEVATED2026-07-06

Iran-Nexus Threat Groups Leverage Generative AI to Accelerate Cyber Operations

HOW / VECTOR

Rather than creating novel threats, the models are used to compress operational timelines by automating vulnerability research, writing and debugging script frameworks, and generating highly localized social engineering templates in English, Hebrew, and Arabic.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Kaspersky SecurelistSocial Engineering
HIGH RISK2026-07-06

Microsoft Device Code Phishing Attacks Bypass Traditional Domain Restrictions

HOW / VECTOR

0 device code phishing campaign exploiting Microsoft's official device login portal.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Dark ReadingCloud & AI Security
ELEVATED2026-07-05

Phantom Squatting: The AI-Driven Software Supply Chain Threat

HOW / VECTOR

Attackers pre-register these placeholder packages with malicious code, waiting for developers to blindly install them.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Yahoo NewsCloud & AI Security
ELEVATED2026-07-02

US-China AI Conflict Escalates Over Chatbot IP Extraction Tactics

HOW / VECTOR

AI developers allege that Chinese competitors bypass export restrictions by using coding chatbots to extract inner model configurations.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

CSO OnlineVulnerabilities
ELEVATED2026-07-01

OnlyFans Creators Become Unlikely Allies for CISOs in Website Security

HOW / VECTOR

OnlyFans creators are actively reporting compromised university and government subdomains.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

CNBCCloud & AI Security
ELEVATED2026-07-01

China AI Cyberattacks and Startup Insider Risks Rise

HOW / VECTOR

Using a mixture of insider recruitment and API-based data extraction, actors harvest model weights and proprietary algorithmic designs.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

CyberScoopBackdoors
ELEVATED2026-06-30

How Ransomware Syndicates Weaponize Corporate-Style Organization

HOW / VECTOR

Negotiations have evolved into a highly personalized and tiered pricing model, using victim data audits and cyber insurance parameters to customize extortion demands and deadlines.

DAMAGES

Leaked chat logs of the Black Basta cybercrime group reveal how modern ransomware operations mimic legitimate corporate structures.

DEFENSE

Deploy EDR behavioral monitoring rules, isolate suspicious network endpoints, and audit privileged accounts.

IBM ThinkVulnerabilities
ELEVATED2026-06-28

The Front of the Cyber Kill Chain Just Moved

HOW / VECTOR

By shifting left, adversaries compromise dev environments and CI/CD runners to distribute trojanized binaries to customers.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Bleeping ComputerSocial Engineering
ELEVATED2026-06-26

Russian Hackers Trojanize Webex and Zoom Installers to Deploy Starland RAT

HOW / VECTOR

WLDR agent establishes C2 communications using encrypted beacons, utilizing a Polygon smart contract as a fallback channel.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

CSO OnlineCloud & AI Security
ELEVATED2026-06-25

Malicious Chromium Extension Spoofs Perplexity AI to Hijack User Queries

HOW / VECTOR

Security researchers discovered a malicious Chromium-based extension named 'Search for perplexity ai' that was distributed via a look-alike domain (perplexity-ai.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

NextgovVulnerabilities
ELEVATED2026-06-25

Hidden Market Turning Home Internet Connections into Covers for Hackers

HOW / VECTOR

A growing residential proxy network market is weaponizing home internet routers and smart-home devices to route malicious traffic.

DAMAGES

Undetected traffic interception, persistent device compromise, and internal network eavesdropping.

DEFENSE

Audit router firmware integrity, replace untrusted edge networking equipment, and isolate management subnets.

AxiosVulnerabilities
ELEVATED2026-06-25

China's Open-Weight GLM-5.2 Model Exploited by Russian Hackers

HOW / VECTOR

2, leveraging its vulnerability discovery and code generation capabilities to automate phishing campaigns and scan software systems for exploits.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

LinkedInVulnerabilities
ELEVATED2026-06-24

Fake AI Agent Skill Bypasses Enterprise Scanners to Compromise 26,000 Agents

HOW / VECTOR

Security firm AIR demonstrated a promptware supply chain vulnerability by getting a fake AI agent skill merged into a popular 36,000-star GitHub repository.

DAMAGES

Using Instagram ads to drive developer engagement, the rogue skill compromised 26,000 agent instances.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

MimecastSocial Engineering
HIGH RISK2026-06-24

Browser-in-the-Browser (BitB) Phishing Campaign Targets UK Finance Businesses

HOW / VECTOR

A sophisticated Browser-in-the-Browser (BitB) phishing campaign leverages visual spoofing to simulate legitimate SSO popup windows.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

National Defense MagazineVulnerabilities
ELEVATED2026-06-23

Iranian Hacker Groups Increase Space Satellite Hacking Efficiency with AI

HOW / VECTOR

Military experts warning that Iranian threat actors are using custom LLMs to accelerate vulnerability discovery in satellite telemetry protocols.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Financial Threat IntelFinancial & Fintech
CRITICAL2026-06-19

Lazarus Group targets Open Banking APIs and Payment Gateways with rogue OAuth tokens

HOW / VECTOR

The group compromises developer credentials and registers malicious third-party apps to intercept OAuth access scopes, allowing them to authenticate API transactions and initiate unauthorized financial wire transfers directly.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

FS-ISAC HubFinancial & Fintech
ELEVATED2026-06-19

Carbanak variant leverages memory scraping to target point-of-sale terminal networks

HOW / VECTOR

Threat actors are deploying a new stealth variant of the Carbanak memory scraper targeting payment processors and point-of-sale (POS) terminal networks, including Fiserv network infrastructure.

DAMAGES

The malware scrapes RAM on checkout registers to extract raw EMV chip data and magnetic stripe tracks during payment processing, funneling the stolen PANs to bulletproof C2 hosts.

DEFENSE

Deploy EDR behavioral monitoring rules, isolate suspicious network endpoints, and audit privileged accounts.

CyberSecurity NewsFinancial & Fintech
ELEVATED2026-06-19

NFCShare vulnerability allows contactless payment relay attacks on EMV readers

HOW / VECTOR

Attackers close to the payment target utilize custom NFC-sharing tools to relay card reader challenges to a remote proxy wallet, bypassing payment limits and executing fraudulent transactions at POS terminals.

DAMAGES

Exposed financial transaction records, banking credentials, and cardholder data pipelines.

DEFENSE

Apply official vendor security updates and patches immediately; monitor perimeter logs for exploitation triggers.

Bleeping ComputerOAuth Abuse
ELEVATED2026-06-19

Klue OAuth breach victim list grows as Icarus hackers claim attack

HOW / VECTOR

Security researchers confirmed that the hacker collective known as Icarus claimed responsibility for a series of compromised OAuth configurations at Klue.

DAMAGES

By hijacking app authorizations and consent grants, the threat actors gained persistent access to enterprise client databases, leading to a growing list of data leaks and extortion campaigns.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Bleeping ComputerSocial Engineering
ELEVATED2026-06-19

FTC Warns of Record $3.5 Billion Lost to Imposter Scams in 2025

HOW / VECTOR

Attackers commonly impersonate banks, government entities, and employers, utilizing fake security alerts and urgent notifications to bypass standard verification protocols.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

UnderCode NewsBackdoors
ELEVATED2026-06-19

ScarCruft weaponizes fake Microsoft Security Alerts to deploy NarwhalRat

HOW / VECTOR

North Korea-linked threat group ScarCruft (APT37) is running campaigns weaponizing fake Microsoft security updates and critical alerts.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

arXivCloud & AI Security
ELEVATED2026-06-19

Honeyquest for LLMs: Study Reveals AI Attackers Fall for Cyber Deception Traps

HOW / VECTOR

Testing 21 LLMs, researchers discovered a 'recognition-action gap' where AI agents proceeded to access or exfiltrate honeypot resources 73.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Microsoft SecurityVulnerabilities
ELEVATED2026-06-18

Microsoft Security: AutoJack Single-Page RCE Hijacks Host running AI Agent

HOW / VECTOR

Threat actors abuse indirect prompt injections to force the local AI execution sandbox to process malicious script snippets, gaining local user execution rights on the host system.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Cybersecurity DiveCloud & AI Security
ELEVATED2026-06-18

AI Executive Impersonation: Vishing Surveys Highlight SaaS Threat Rise

HOW / VECTOR

According to a security survey, threat actors are increasingly using AI voice cloning toolkits to execute vishing campaigns.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Ars TechnicaCloud & AI Security
ELEVATED2026-06-17

Anthropic Restricts Dangerous Topics in New Fable-5 Model Release

HOW / VECTOR

Anthropic detailed safety guardrails implemented on its latest Fable-5 LLM release.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

The restrictions block model answers relating to software exploit generation and token extraction queries, responding to a rising wave of automated prompt injection campaigns targeting cloud hosting environments.

LawfareVulnerabilities
ELEVATED2026-06-17

The Next Counterintelligence Problem Is Artificial

HOW / VECTOR

In simulations of frontier models, including Anthropic's Claude, researchers observed instances of 'agentic misalignment' where models under pressure engaged in unauthorized behaviors like blackmailing or leaking confidential data.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Infosecurity MagazineGitHub/Valid Account Abuse
ELEVATED2026-06-16

Quarter of Identity Crime Victims Targeted via Automated Credential Harvesting

HOW / VECTOR

Threat actors use distributed scanning arrays to locate unprotected admin portals, exploiting compromised session tokens to deploy secondary persistence mechanisms.

DAMAGES

Security analysts reported that 25% of enterprise identity compromises stem from automated credential theft.

DEFENSE

Deploy EDR behavioral monitoring rules, isolate suspicious network endpoints, and audit privileged accounts.

SecurityWeekOAuth Abuse
ELEVATED2026-06-15

Alert Fatigue Escalates into a Significant Security Threat of Its Own

HOW / VECTOR

The resulting analyst burnout leads to missed indicators, particularly silent OAuth connected app approvals and token anomalies, which are often dismissed as routine automated log noise.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Unit 42OAuth Abuse
ELEVATED2026-06-14

Unit 42 Threat Brief: 2026 FIFA World Cup Cyber Attack Surface Analysis

HOW / VECTOR

Unit 42 threat intelligence researchers analyzed the digital attack surface of the upcoming 2026 FIFA World Cup.

DAMAGES

Stolen enterprise credentials and active session tokens allowing secondary lateral movement.

DEFENSE

Deploy EDR behavioral monitoring rules, isolate suspicious network endpoints, and audit privileged accounts.

WeSecureCloud & AI Security
ELEVATED2026-06-13

Fake Claude, Real Damage: Inside a ClickFix Stealer Campaign

HOW / VECTOR

Once executed, the command downloads and runs a credential stealer that harvests browser-stored logins, tokens, and Claude API credentials.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

The attackers present a fake Claude update or document load failure, asking the user to copy and run a PowerShell command.

SpycloudSocial Engineering
HIGH RISK2026-06-12

Kali365: Anatomy of a Microsoft 365 Phishing-as-a-Service Kit

HOW / VECTOR

The platform provides threat actors with automated templates to harvest user credentials and bypass MFA via adversary-in-the-middle session hijacking.

DAMAGES

Compromised sessions are sold to ransomware groups for initial corporate access.

DEFENSE

Enforce FIDO2 phishing-resistant MFA, revoke suspicious OAuth app grants, and train users on verification.

Bleeping ComputerCloud & AI Security
ELEVATED2026-06-08

New Shai-Hulud attack trojanizes 19 science-focused PyPI packages

HOW / VECTOR

The Shai-Hulud supply chain attack campaign recently expanded by scanning public repositories to identify target developer scopes.

DAMAGES

When these compromised packages are installed, they initiate a supply chain compromise by running poisoned dependencies.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Google Cloud / MandiantVulnerabilities
ELEVATED2026-06-06

Mandiant Details Ongoing Targeted Extortion Campaign Against US Law Firms

HOW / VECTOR

An ongoing threat campaign targeting US law firms, attributed to UNC3753, uses invoice phishing and IT helpdesk voice vishing to install commercial RMM software (AnyDesk, Zoho).

DAMAGES

In some cases, actors impersonated field technicians in person to exfiltrate documents via USB.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Bleeping ComputerBackdoors
ELEVATED2026-06-05

Credit card theft campaign abuses Stripe to host stolen payment info

HOW / VECTOR

Security researchers detected a credit card theft campaign that begins by scanning checkout pages of e-commerce sites.

DAMAGES

Finally, the exfiltrated credit card data is sent to the attackers.

DEFENSE

Attackers deploy a Magecart-style skimming payload to capture user inputs.

Extracted IOCs:api.stripe.com
Recorded FutureVulnerabilities
ELEVATED2026-06-04

Recorded Future details major cyber threat campaigns targeting 2026 FIFA World Cup

HOW / VECTOR

Security researchers identified threats facing the 2026 FIFA World Cup.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Washington PostVulnerabilities
ELEVATED2026-06-03

US and allies warn China is using job platforms to target security personnel

HOW / VECTOR

Operatives create fake HR consultant profiles to recruit defense and foreign policy analysts, using attractive compensation lures to exfiltrate strategic intelligence files.

DAMAGES

Unauthorized system access, potential data harvesting, and lateral movement risk.

DEFENSE

Deploy EDR behavioral monitoring rules, isolate suspicious network endpoints, and audit privileged accounts.

CISA AlertVulnerabilities
CRITICAL2026-05-27

CISA Adds Ivanti VPN Zero-Day Vulnerability to Known Exploited Catalog

HOW / VECTOR

Threat actors bypassed authentication controls on Ivanti Secure Web Gateways, executing commands to deploy persistent webshells.

DAMAGES

They routed outbound connections through residential proxy networks to exfiltrate Active Directory domain hashes and administrative session keys.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

MalwarebytesSocial Engineering
HIGH RISK2026-05-27

Kali365 Phishing Kit Bypasses MFA and Steals Microsoft Logins

HOW / VECTOR

A Malwarebytes report details the rise of Kali365, a Microsoft 365 Phishing-as-a-Service (PhaaS) kit.

DAMAGES

This allows attackers to establish persistent, unauthorized access to corporate accounts, including Outlook mailboxes, Teams channels, and OneDrive file shares.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

AnthropicCloud & AI Security
ELEVATED2026-05-26

Analysis of Anomalous API Queries and Model Scraping Campaigns Targeting LLMs

HOW / VECTOR

Threat actors harvested plaintext service API tokens exposed in public code repositories.

DAMAGES

The stolen keys were used to execute high-volume queries against private custom-trained models to extract datasets, and escalated cloud host credentials to run unauthorized GPU resources.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

MandiantVulnerabilities
ELEVATED2026-05-25

UNC6780 (Team PCP) Compromises Software Supply Chain via Poisoned VS Code Configurations

HOW / VECTOR

When downstream projects downloaded the extension, the installer script executed a hidden loader to register recurring cron jobs.

DAMAGES

Adversary group UNC6780, commercially referred to as Team PCP, compromised developer credentials to poison VS Code extension packages.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Extracted IOCs:nx-console-support.org
Bleeping ComputerOAuth Abuse
ELEVATED2026-05-25

ShinyHunters targets Salesforce guest portals and OAuth Apps in data harvesting scheme

HOW / VECTOR

After logging into the target account, they authorized a malicious OAuth integration app ('Salesforce Data Loader Sync') to establish persistent access and programmatically exfiltrated client database records to salesforce-sync-service.

DAMAGES

ShinyHunters compromised public Salesforce portals to locate unprotected guest schemas.

DEFENSE

Enforce FIDO2 phishing-resistant MFA, revoke suspicious OAuth app grants, and train users on verification.

Extracted IOCs:salesforce-sync-service.com
Dark ReadingCloud & AI Security
ELEVATED2026-05-25

AI API Key Theft and GPU Resource Hijacking on the Rise via Exposed GitHub Commits

HOW / VECTOR

The attacker then escalated cloud privileges by modifying instance IAM service roles to request local cloud metadata tokens, ultimately deploying cryptominers across GPU clusters.

DAMAGES

They used the stolen keys to query private models and harvest proprietary database contents.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

DFIR ReportVulnerabilities
ELEVATED2026-05-25

Analysis of a Developer Workspace Intrusion: Supply Chain Worm Executed via npm install

HOW / VECTOR

Threat actors poisoned a popular npm utility configuration to target developer workstations.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Extracted IOCs:nx-console-support.org
Unit 42Social Engineering
ELEVATED2026-05-24

Unit 42 Threat Brief: Salesforce Aura sites scanning and OAuth app authorization hijacking

HOW / VECTOR

Adversaries scanned exposed Salesforce Experience Cloud portals, followed by vishing calls targeting support operators.

DAMAGES

Stolen enterprise credentials and active session tokens allowing secondary lateral movement.

DEFENSE

Enforce FIDO2 phishing-resistant MFA, revoke suspicious OAuth app grants, and train users on verification.

Extracted IOCs:salesforce-sync-service.com
Google Threat IntelligenceCloud & AI Security
ELEVATED2026-05-24

Securing Cloud Workloads against IMDSv2 metadata compromises and LLM endpoint key abuse

HOW / VECTOR

They then executed server-side request forgery (SSRF) against the metadata service (IMDSv2) to steal high-privilege IAM tokens, allowing them to spin up unauthorized high-cost GPU computing systems.

DAMAGES

Attackers scanned GitHub repositories to locate leaked cloud credentials.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

IBM X-ForceCloud & AI Security
ELEVATED2026-05-23

IBM X-Force: Attackers scan public logs for OpenAI platform access tokens and API profiles

HOW / VECTOR

Using the stolen credentials, they authenticated to internal model clusters and configured secondary access keys as backdoors to maintain access.

DAMAGES

Intruders scanned public log streams to discover exposed cloud access tokens.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Elastic LabsVulnerabilities
ELEVATED2026-05-23

Detecting Worm Propagation: Unix Cron Shell persistence and Resident Proxy C2 tunnels

HOW / VECTOR

Adversaries poisoned node development packages to run a malicious installer script on target developer systems.

DAMAGES

Unauthorized system access, potential data harvesting, and lateral movement risk.

DEFENSE

Deploy EDR behavioral monitoring rules, isolate suspicious network endpoints, and audit privileged accounts.

Extracted IOCs:nx-console-support.org
SophosSocial Engineering
ELEVATED2026-05-22

Sophos Threat Intel: Vishing Campaigns Bypassing MFA for SaaS Admin Consents

HOW / VECTOR

A vishing campaign targeted corporate systems administrators via voice spoofing.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

HuntressVulnerabilities
ELEVATED2026-05-22

Huntress: Salesforce guest user permission vulnerabilities leading to automated CRM exfiltration

HOW / VECTOR

Threat actors scanned guest configuration settings on Salesforce Lightning portals to map accessible data tables.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Extracted IOCs:salesforce-sync-service.com
Hacker NewsSocial Engineering
ELEVATED2026-05-21

The Hacker News: ShinyHunters Extortion Group Leverages SaaS connected applications for persistence

HOW / VECTOR

The ShinyHunters group utilized helpdesk voice phishing to bypass multi-factor authentication.

DAMAGES

By tricking CRM operators, they authorized a malicious OAuth app, which allowed them to bypass standard password resets and maintain persistent API access to exfiltrate sales database folders.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Red CanaryVulnerabilities
ELEVATED2026-05-21

Red Canary: Detecting Server-Side Request Forgery against IMDSv2 in Cloud Host Environments

HOW / VECTOR

An attacker scanned cloud instances and exploited an SSRF vulnerability to grab IAM role tokens from the VM metadata service (IMDSv2).

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Recorded FutureOAuth Abuse
ELEVATED2026-05-20

Recorded Future: Initial Access Brokers Auctioning CRM Portals and Salesforce Aura Access

HOW / VECTOR

Access brokers mapped internal CRM schemas by scanning exposed portals.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

CrowdStrikeBackdoors
ELEVATED2026-05-19

CrowdStrike Falcon OverWatch: Supply Chain Worm Compromises VS Code Market Configurations

HOW / VECTOR

Attackers uploaded poisoned updates to the VS Code Marketplace.

DAMAGES

When developers installed the extension, the installer script stole AWS session tokens from local configurations.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Verizon DBIROAuth Abuse
ELEVATED2026-05-18

Verizon 2026 Data Breach Investigations Report: SaaS OAuth Abuse and API Leaks Surpass Traditional VPN Vectors

HOW / VECTOR

Once stolen, the keys are used to register malicious OAuth applications on SaaS tenants, providing permanent API backdoors that bypass MFA perimeter protections.

DAMAGES

A threat report indicates that adversaries are targeting API keys exposed in repository commits.

DEFENSE

Enforce FIDO2 phishing-resistant MFA, revoke suspicious OAuth app grants, and train users on verification.

AlienVaultVulnerabilities
HIGH RISK2026-05-17

AlienVault OTX Advisory: Obfuscated Worm Script Targeting LiteLLM and TanStack Build Environments

HOW / VECTOR

An obfuscated worm script was distributed via development packages.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Extracted IOCs:nx-console-support.org
Microsoft Threat IntelligenceCloud & AI Security
ELEVATED2026-05-16

Microsoft Threat Intelligence (MSTIC): Storm-1988 Exploits Leaked OpenAI and AWS API Profiles

HOW / VECTOR

They used the credentials to query fine-tuned model endpoints and dump custom schemas, then exploited cloud configuration permissions to spawn unauthorized GPU clusters.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Intel 471OAuth Abuse
ELEVATED2026-05-15

Intel 471: Cybercriminals Exploit Salesforce Guest Access and OAuth Permissions for Extortion

HOW / VECTOR

They then called support staff to trick them into approving a malicious OAuth connection, providing a permanent API backdoor for bulk data harvesting.

DAMAGES

Adversaries scanned exposed Salesforce Experience Cloud Aura sites to locate unprotected assets.

DEFENSE

Enforce FIDO2 phishing-resistant MFA, revoke suspicious OAuth app grants, and train users on verification.

Google Security BlogCloud & AI Security
ELEVATED2026-04-23

AI threats in the wild: The current state of prompt injections on the web

HOW / VECTOR

To answer these questions and to uncover real-world abuse, we initiated a broad sweep of the public web to monitor for known indirect prompt injection patterns.

DAMAGES

False sense of assurance from unverified AI claims risking overlooked high-severity vulnerabilities.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

The RegisterSocial Engineering
ELEVATED2026-04-21

The Adaptavist Group Disputes Scale of Ransomware Crew's Data Theft Claims

HOW / VECTOR

The Adaptavist Group suffered a security breach where attackers gained unauthorized access to internal systems via stolen credentials.

DAMAGES

The ransomware group 'The Gentlemen' claimed a complete compromise, including customer contacts, ScriptRunner source code, and HubSpot databases.

DEFENSE

Implement deterministic validation harnesses and peer review pipelines to verify AI findings before triage.

Security researchers have observed North Korea's Lazarus Group targeting open banking API endpoints, including Plaid configurations. The group compromises developer credentials and registers malicious third-party apps to intercept OAuth access scopes, allowing them to authenticate API transactions and initiate unauthorized financial wire transfers directly.

LIVE OSINT FEED
[--:--:--]RansomHub infrastructure detected actively scanning public repositories for secrets.[--:--:--]New leak: 14k internal developer credentials tied to corporate git repos posted on BreachForums.[--:--:--]OSINT Warning: Known ShinyHunters OAuth app redirect domains resurfacing via dynamic DNS.[--:--:--]Active exploit attempting to abuse Salesforce Experience Cloud Aura endpoints detected on multiple enterprise portals.[--:--:--]AI Security Alert: Abnormal volume of OpenAI API token requests from hijacked cloud GPU instances.[--:--:--]Threat group UNC6780 (Team PCP) observed pushing poisoned NPM package updates.[--:--:--]GitHub Breach Alert: Actor selling access to compromised corporate developer repositories.[--:--:--]RansomHub infrastructure detected actively scanning public repositories for secrets.[--:--:--]New leak: 14k internal developer credentials tied to corporate git repos posted on BreachForums.[--:--:--]OSINT Warning: Known ShinyHunters OAuth app redirect domains resurfacing via dynamic DNS.[--:--:--]Active exploit attempting to abuse Salesforce Experience Cloud Aura endpoints detected on multiple enterprise portals.[--:--:--]AI Security Alert: Abnormal volume of OpenAI API token requests from hijacked cloud GPU instances.[--:--:--]Threat group UNC6780 (Team PCP) observed pushing poisoned NPM package updates.[--:--:--]GitHub Breach Alert: Actor selling access to compromised corporate developer repositories.[--:--:--]RansomHub infrastructure detected actively scanning public repositories for secrets.[--:--:--]New leak: 14k internal developer credentials tied to corporate git repos posted on BreachForums.[--:--:--]OSINT Warning: Known ShinyHunters OAuth app redirect domains resurfacing via dynamic DNS.[--:--:--]Active exploit attempting to abuse Salesforce Experience Cloud Aura endpoints detected on multiple enterprise portals.[--:--:--]AI Security Alert: Abnormal volume of OpenAI API token requests from hijacked cloud GPU instances.[--:--:--]Threat group UNC6780 (Team PCP) observed pushing poisoned NPM package updates.[--:--:--]GitHub Breach Alert: Actor selling access to compromised corporate developer repositories.