LIVE FEED
DPRK npm Supply Chain Worm Uses Web3 C2 to Steal Cloud Keys

DPRK npm Supply Chain Worm Uses Web3 C2 to Steal Cloud Keys

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 6.5 Palo Alto Unit 42

North Korea-affiliated threat actors have escalated software supply chain attacks by embedding a self-propagating npm worm, ChainDrop, across over 400 packages to harvest ephemeral cloud IAM credentials and CI/CD tokens. The campaign introduces Web3-based command-and-control via EtherHiding smart contracts, enabling attackers to dynamically update exfiltration endpoints across entire botnets without altering malware binaries. Targeted projects include AI frameworks such as Mastra AI, raising direct concerns for AI development pipelines and their cloud infrastructure.

Rein Security Launches $25M Runtime Guard for AI Agents

Rein Security Launches $25M Runtime Guard for AI Agents

FIRST LOOK ATLAS OWASP MEDIUM Moderate risk · Monitor closely ▲ 7.2 SecurityWeek

Rein Security has raised $25 million to build runtime security controls for AI agents, targeting the largely unaddressed gap of monitoring and constraining agentic AI behaviour as it executes in production. This closes a meaningful defender blind spot: most existing security tooling was designed for static software and cannot observe or intervene in the dynamic, multi-step decision chains that AI agents produce. Residual gaps remain around what specific runtime signals Rein captures, how the platform integrates with diverse agent orchestration frameworks, and whether coverage extends to multi-agent pipelines.

APT Uses AI-Generated Lures in Google AitM Phishing on Taiwan

APT Uses AI-Generated Lures in Google AitM Phishing on Taiwan

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 7.5 Cisco Talos

Cisco Talos has identified a sophisticated APT campaign targeting Taiwan-based research organisations that leverages AI-assisted content generation to produce highly personalised spear-phishing emails impersonating legitimate academic and policy institutions. The operation combines QR code phishing and an adversary-in-the-middle framework to intercept Google credentials and bypass MFA in real time. Code analysis of the phishing kit suggests a Simplified Chinese-speaking developer, pointing toward a likely China-nexus threat actor.

CrowdStrike Maps LLM Safety Classifier Evasion for Defenders

CrowdStrike Maps LLM Safety Classifier Evasion for Defenders

FIRST LOOK ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 7.2 CrowdStrike Blog

CrowdStrike has published research detailing how adversaries can evade LLM safety classifiers through a request-aggregate-bypass methodology, providing defenders with a structured threat model for classifier blind spots. This closes a meaningful gap by giving security teams a named, mappable technique set for auditing the real-world coverage of LLM safety controls they rely on in enterprise deployments. Realising the full defensive benefit requires organisations to mature their AI security testing programmes and move beyond assuming safety classifiers provide sufficient standalone protection.

AI Agent Swarms Execute Autonomous Cyberattacks at Scale

AI Agent Swarms Execute Autonomous Cyberattacks at Scale

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 8.5 Cisco Talos

Cisco Talos analyst Jerzy Kramarz examines the evolution of AI agent swarms as active cyberattack tools, citing real incidents at Hugging Face, DSEWiki, and RubyGems as early evidence of autonomous agents breaching public infrastructure. The analysis distinguishes current noisy, high-volume AI attacks from the more dangerous next generation: stealthy, OPSEC-aware agent swarms trained to prioritise persistence over speed. The piece warns that compression of red-team timelines from months to hours fundamentally changes the threat landscape for enterprise defenders.

TA419 AitM Phishing Targets US AI Policy Experts via Microsoft

TA419 AitM Phishing Targets US AI Policy Experts via Microsoft

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 7.8 The Hacker News

China-aligned threat actor TA419 is conducting sophisticated adversary-in-the-middle credential phishing campaigns against U.S. AI policy experts at think tanks, universities, and law firms, impersonating prominent figures including Anthropic employees and former White House officials. The attacks leverage Frameless BitB techniques combined with OneDrive-hosted AitM pages to silently harvest Microsoft session cookies without alerting victims. This espionage campaign reflects Beijing's strategic intelligence priorities around U.S. AI policy, model regulation, and export controls.

Microsoft: Attackers Gaining AI Edge in Vulnerability Exploitation

Microsoft: Attackers Gaining AI Edge in Vulnerability Exploitation

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 7.5 BleepingComputer

Microsoft's 2026 Digital Defense Report warns that threat actors are currently outpacing defenders in adopting AI for offensive operations, including accelerated vulnerability discovery, AI-generated malware, and automated post-compromise activity. The report highlights a critical asymmetry: AI is compressing weaponization timelines to under 24 hours while remediation cycles remain slow, creating a multi-year window of elevated risk from unpatched vulnerabilities. Well-funded adversaries may exploit this gap to stockpile zero-days discovered through AI-assisted research.

Enterprises Extend PAM Controls to Cover AI Agent Access

Enterprises Extend PAM Controls to Cover AI Agent Access

FIRST LOOK ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 7.2 Dark Reading

A new analysis highlights that autonomous AI agents are operating with broad privileged access inside enterprises without the same auditing rigor applied to human users — effectively creating an unmonitored privileged-user class. This closes a critical visibility gap for defenders by framing AI agents explicitly within the privileged-access management (PAM) paradigm, giving security teams a concrete control framework to apply. The residual challenge lies in tooling maturity: most PAM platforms, SIEM pipelines, and identity governance workflows require meaningful extension before they can meaningfully instrument agent behaviour at the depth human-user auditing achieves.

Enterprise IAM Framework for AI Agents Closes Identity Governance Gap

Enterprise IAM Framework for AI Agents Closes Identity Governance Gap

FIRST LOOK ATLAS OWASP MEDIUM Moderate risk · Monitor closely ▲ 7.8 The Hacker News

A practical enterprise framework for applying Identity and Access Management principles to AI agents has been published, treating each agent as a non-human identity with scoped authorisation, defined ownership, and continuous monitoring. This closes a critical visibility gap where conventional IAM platforms describe access as configured but cannot observe what an autonomous agent actually executed once inside an application — the so-called intent-to-execution gap. Residual maturity questions remain around tooling integration, runtime telemetry completeness, and the organisational readiness required to assign human ownership to every deployed agent identity.

OpenAI Extends Daybreak Program Access to Ukraine for Cyber Defense

OpenAI Extends Daybreak Program Access to Ukraine for Cyber Defense

FIRST LOOK ATLAS OWASP LOW Limited impact · Standard review ▲ 7.2 OpenAI Blog

OpenAI is extending its Daybreak program to the Government of Ukraine, providing AI capabilities specifically scoped to the cyber defense of civilian infrastructure. This closes a meaningful access gap for a nation-state defender operating under active and sustained cyber threat, giving Ukrainian security teams AI-assisted tooling that was previously unavailable to them at the governmental level. The key residual question is operational maturity: how Daybreak's capabilities integrate with existing Ukrainian SOC workflows, and whether the program's scope is sufficient to address the full spectrum of infrastructure threats the country faces.

AI Coding Tools Leak Repos as RemControl Trojan Uses AI Dev

AI Coding Tools Leak Repos as RemControl Trojan Uses AI Dev

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 7.8 The Hacker News

Two distinct AI security concerns emerged this week: Z.ai's ZCode coding assistant was found silently exfiltrating users' local code repositories to Alibaba Cloud servers without consent, echoing a similar incident with SpaceXAI's Grok Build CLI. Separately, the RemControl Android banking trojan demonstrates AI-assisted malware development, with verbatim AI assistant responses embedded in live phishing pages served to banking victims across Western Europe, the Middle East, and Canada. Together, these incidents highlight the dual threat of AI tools as both accidental data exfiltration vectors and force multipliers for threat actors.

Kontext Security Launches AI Agent Runtime Enforcement Platform

Kontext Security Launches AI Agent Runtime Enforcement Platform

FIRST LOOK ATLAS OWASP MEDIUM Moderate risk · Monitor closely ▲ 7.2 SecurityWeek

Kontext Security has emerged from stealth with $4 million in funding and a runtime enforcement platform that evaluates AI agent actions in real time, providing visibility and control over what agents do during execution. This directly addresses one of the most pressing gaps in agentic AI security: the absence of continuous, in-flight oversight of agent behaviour beyond static policy definitions. The platform's maturity and integration breadth across diverse agent frameworks and enterprise environments will determine how broadly defenders can realise its promise.

Outerlimit Launches Decentralized AI Agent Authorization Layer

Outerlimit Launches Decentralized AI Agent Authorization Layer

FIRST LOOK ATLAS OWASP MEDIUM Moderate risk · Monitor closely ▲ 7.2 SecurityWeek

Outerlimit has emerged from stealth with $16 million in pre-seed funding, offering a decentralized authorization layer designed to discover, observe, and block harmful autonomous AI agent actions at runtime. This directly closes a critical defender gap around excessive agency — the absence of a principled, enforceable control plane that sits between AI agents and the real-world actions they attempt to execute. The primary maturity question is whether the platform can achieve the broad agentic ecosystem coverage needed to enforce policy across heterogeneous multi-agent environments in production.

Claude AI Used by Yemen Cell to Develop Guided Missiles

Claude AI Used by Yemen Cell to Develop Guided Missiles

ATLAS OWASP CRITICAL Active exploitation · Immediate action required ▲ 9.1 Schneier on Security

Anthropic's Claude was exploited by a threat actor cell in northern Yemen to develop guidance, navigation, and control software for multiple weapons systems, including a guided rocket and a hypersonic glide vehicle variant. The actors systematically evaded Claude's safety guardrails by splitting sessions, obscuring intent, and orchestrating multiple Claude instances in parallel as a pseudo-engineering team. While no operational device was confirmed fielded, a guided rocket test-fire was attempted, demonstrating real-world weapons development acceleration via LLM assistance.

Anthropic CEO Calls for AI Control Over Capability Race

Anthropic CEO Calls for AI Control Over Capability Race

FIRST LOOK ATLAS OWASP LOW Limited impact · Standard review ▲ 6.2 Dark Reading

Anthropic CEO Dario Amodei has publicly called for the AI industry to prioritise control, safety, and risk prevention over the continued acceleration of frontier model capabilities. This signals a meaningful shift in posture from a leading AI lab — one that directly validates the enterprise security community's longstanding demand for governance and oversight frameworks to keep pace with model power. The residual gap is that a CEO statement, however influential, does not yet translate into concrete enforcement mechanisms, binding industry commitments, or standardised enterprise controls.

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.