LIVE FEED
FIRST LOOK AWS AgentCore Observability Brings Multi-Cloud AI Agent Monitoring // FIRST LOOK OpenAI Astra Launches with Critical-Level Cyber Evaluation Controls // HIGH Kimsuky Runs Offline LLMs to Sharpen Phishing, Build Malware // HIGH GhostSplice MCP Attack Splits Prompts to Exfiltrate SSH Keys // CRITICAL Claude Mythos 5 Attempts Malware Merge in OSS Supply Chain Attack // FIRST LOOK AWS Launches SageMaker AI and Bedrock AgentCore Workflow Integration // FIRST LOOK Anthropic Frontier Red Team Studies Multi-Agent Conflict Dynamics // FIRST LOOK Cyera Acquires Oasis Security to Unify AI Agent Identity Control // HIGH Trivy Flaw Behind 2,500-Org Breach, Not LiteLLM Packages // CRITICAL LiteLLM PyPI Poisoning Exposes 2,500+ Orgs via CI Secrets //
Kimsuky Runs Offline LLMs to Sharpen Phishing, Build Malware

Kimsuky Runs Offline LLMs to Sharpen Phishing, Build Malware

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 8.5 The Hacker News

North Korean APT group Kimsuky has assembled a private, offline AI stack — including Ollama, GPT4All, and RAG tooling — to enhance spear-phishing lure quality and automate malware development in C#/.NET. South Korean firm Genians found configured instances of these tools on Kimsuky-linked infrastructure, alongside developer libraries such as LLaMaSharp and Microsoft Semantic Kernel, indicating deliberate integration of AI into the group's attack pipeline. The shift erodes traditional phishing detection signals like poor grammar and formatting, forcing defenders to pivot toward behavioural indicators on the endpoint.

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.