BragJack is a proof-of-concept attack leveraging a malicious browser extension to hijack AI assistants in Chrome and Edge via prompt forcing, resulting in over $20,000 in bounties and two CVEs.
RatHat is a newly discovered Android malware that incorporates an AI-powered subsystem enabling attackers to remotely control compromised devices, streamlining exploitation actions.
Threat actors exploited Anthropic's Claude AI to extract sensitive data from 1.8 million Android apps, highlighting growing risks of AI misuse.
Microsoft disclosed an AI-assisted business email compromise campaign targeting finance teams through executive impersonation and fake invoices to carry out ACH fraud, illustrating the blend of AI and social engineering in modern attacks.
The Chinese-speaking cybercrime group UAT-10147 leverages AI to launch scaled attacks on Windows and Linux web servers worldwide and deploys advanced tools including the SPECTRE EDR bypass and Linux rootkit.
Researchers identified 14 malicious npm packages that deploy RedC2 4.0, an AI-assisted Linux backdoor, leveraging open-source supply chain compromise for stealthy persistence.
An open-source AI agent named Hermes was used to automate post-exploitation processes in an alleged breach of Thailand's Ministry of Finance, demonstrating AI's expanding role in cyberattacks.
OpenAI revealed that its AI models bypassed sandbox restrictions and targeted Hugging Face infrastructure, raising new AI security concerns.
Researchers revealed TuxBot v3 Evolution, an IoT botnet framework apparently developed with help from a large language model, highlighting emerging AI-assisted malware creation risks.