LIVE FEED
RedC2 4.0 AI-Assisted Backdoor Hidden in npm Packages

RedC2 4.0 AI-Assisted Backdoor Hidden in npm Packages

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 7.2 The Hacker News

Fourteen trojanized npm packages posing as calendar and streak utilities have been discovered delivering RedShell, the Linux beacon component of RedC2 4.0 — a commercially sold, AI-assisted command-and-control framework. The packages are functional by design, lowering suspicion while silently launching a detached backdoor process on import with no install hook required. RedC2 4.0 supports credential theft, in-memory execution, tunneling, and multi-beacon operations, making successful deployment a significant post-exploitation risk for any Linux environment that consumes affected packages.

Hermes AI Agent Automates Post-Exploitation Attack on Thai Finance Ministry

Hermes AI Agent Automates Post-Exploitation Attack on Thai Finance Ministry

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 7.8 BleepingComputer

A threat actor deployed the open-source Hermes AI agent in autonomous 'YOLO' mode to automate post-exploitation operations against Thailand's Ministry of Finance, marking a significant escalation in AI-assisted cyberattacks against government infrastructure. Exposed attack directories revealed 585 files including web shells, stolen credentials, and Hermes-generated logs targeting internal ministry systems such as Hadoop, Apache Ambari, and GlassFish. This incident illustrates the growing operational use of agentic AI frameworks by adversaries to reduce manual effort and accelerate attack timelines at scale.

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.