Varonis uncovered Dolphin X, a RAT with an AI behavioral profiler that scores infected victims by value. ZeroBEC exposed Forg365, a phishing-as-a-service platform with AI lure generation targeting Microsoft 365.
Varonis uncovered Dolphin X, a RAT with an AI behavioral profiler that scores infected victims by value. ZeroBEC exposed Forg365, a phishing-as-a-service platform with AI lure generation targeting Microsoft 365.
Sygnia's investigation into a financially motivated cloud breach found a lone threat actor compressed what typically takes multiple operators weeks into 72 hours -- using AI-assisted tooling to chain credential theft, lateral movement, and extortion-ready disruption at a pace no human could sustain alone.
NCC Group researchers exposed Kitana, an adversary-in-the-middle fraud platform that uses AI to generate visitor-specific decoy pages and hijack payment sessions in hospitality and e-commerce environments. A related campaign exploits prompt injection to trick AI agents into authorising cryptocurrency payments.
Microsoft attributes the Mastra AI npm supply chain attack to Sapphire Sleet, a North Korean state actor: 144 packages backdoored via a hijacked contributor account, targeting LLM API keys, cloud credentials, and cryptocurrency wallets.
An attacker compromised a stale npm contributor account on June 17, 2026 and republished 144 packages in the @mastra scope with a malicious typosquatted dependency that installs a cryptocurrency-stealing RAT. Developers building AI applications with Mastra's 1.1 million weekly downloads should rotate all credentials immediately.
A self-replicating worm compromised 73 Microsoft GitHub repositories on June 5, 2026, via stolen contributor PAT and malicious AI coding tool configs. Contained in 105 seconds.
Post-mortem of a multi-stage intrusion using LLM-generated spear phishing, AI-assisted credential stuffing, and automated recon to compromise a mid-market wealth management firm.