LIVE FEED
HIGH AI Coding Tools Leak Repos as RemControl Trojan Uses AI Dev // HIGH Carbonato Malware Deploys AI Agents to Hijack Docker Hosts // FIRST LOOK Kontext Security Launches AI Agent Runtime Enforcement Platform // FIRST LOOK Microsoft Defender and Purview Add AI Agent Controls in September 2026 // FIRST LOOK AWS Launches AgentCore Gateway for Multi-Account AI Agents via MCP // CRITICAL Rogue AI Agents Exploit urlquery.net to Bypass Restrictions // CRITICAL OpenAI Agents Breach Australian Medicare Portal via SQLi Probes // HIGH AI Chatbots Poisoned via Web Seeding in Disinformation Campaign // FIRST LOOK Outerlimit Launches Decentralized AI Agent Authorization Layer // FIRST LOOK OWASP Flags AI Agent Unbounded Consumption as Top Enterprise Risk //
GreyVibe Deploys ChatGPT and Gemini in LLM Attack Chain

GreyVibe Deploys ChatGPT and Gemini in LLM Attack Chain

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 7.5 SecurityWeek

WithSecure has documented GreyVibe, a Russia-nexus threat actor systematically deploying ChatGPT, Google Gemini, and Ideogram AI across every phase of its attack chain — from phishing lure creation to custom malware development — against Ukrainian targets since August 2025. The group's LLM-assisted malware, LegionRelay, contained design flaws introduced during AI-generated development, which paradoxically allowed researchers to track the group over an extended period. The case illustrates both the operational leverage AI provides to moderately skilled threat actors and the novel forensic signatures that AI-assisted development can inadvertently introduce.

PromptSpy Zero-Day: AI-Generated Malware for Mass Exploitation

PromptSpy Zero-Day: AI-Generated Malware for Mass Exploitation

ATLAS OWASP CRITICAL Active exploitation · Immediate action required ▲ 9.2 Mandiant Blog

Google's Threat Intelligence Group (GTIG) has identified, for the first time, a criminal threat actor using a zero-day exploit believed to have been AI-generated, intended for mass exploitation before proactive counter-discovery intervened. The report also documents AI-augmented malware development, autonomous attack orchestration via AI-enabled malware (PROMPTSPY), and obfuscated LLM access pipelines used by adversaries to bypass usage controls. Nation-state actors from China and North Korea are actively pursuing AI-assisted vulnerability discovery, marking a significant escalation in adversarial AI capability.

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.