The activity is separate from an earlier campaign involving Chinese-speaking operators, but shows a similar pattern: commercial AI models were used as operational tools...
Threat actors are increasingly targeting exposed AI infrastructure to steal model-provider API keys, abuse cloud-connected services, and deploy Monero cryptominers, according to new research...
TITAN, a ransomware-as-a-service (RaaS) operation active since May 2026, is promoting an on-premises artificial intelligence platform designed to analyze stolen corporate data and increase...
An exposed open directory has revealed months of activity linked to a Russian-speaking affiliate of the Aurora ransomware operation.
CloudSEK said the operator targeted...
ToxNetV2, an AArch64 Linux peer-to-peer botnet, has integrated an LLM into its controller workflow, allowing host and botnet telemetry to be converted into structured...