AI-powered ransomware toolkit automates Active Directory discovery and EDR evasion
The framework's code and payloads were developed using AI agents powered by Cursor and Claude Opus.
The framework's code and payloads were developed using AI agents powered by Cursor and Claude Opus.
The malware spreads through fake Minecraft mods, cheats, clients, and other tools.
The attackers tricked the AI into linking their own email addresses to targeted accounts.
CISA didn’t provide any details on the nature of the exploitation of the vulnerabilities.
An unknown threat actor attempted to bypass two-factor authentication and add new devices to existing user accounts.
The campaign begins with weaponized xHTML files that deliver a malicious RAR archive exploiting a WinRAR vulnerability (CVE-2025-8088).
The attack is designed to steal developer credentials and CI/CD secrets during package installation.
The campaign mainly targets organizations in government, research, education, technology, and financial services.
The Marimo flaw was exploited for the initial compromise and AWS credential theft.
The botnet relied on more than 200 servers hosted in the Netherlands.
Showing elements 31 - 40