ZeroHour

Search: “llm security”

18 stories in the last 3d

Autonomy in Check: Governor-Mediated Adaptive Security at the Edge

Split-control architecture adds a deterministic governor to validate LLM and rule-based planner intents before eBPF enforcement at the edge.

Researchers propose a split-control edge security architecture in which an untrusted planner emits typed security intents that a deterministic governor checks against safety, resource, temporal-stability, and proportionality invariants. Admitted actions are bound to signed receipts and compiled into pre-installed eBPF map updates. A Raspberry Pi 5 prototype on a university 5G test network admitted, rejected, and bounded intents at microsecond cost.

arXiv cs.CR · 2d agoResearch1

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

A 2026 scorecard ranks DSPM tools with Wiz and Cyera tied first, documenting consolidation via Palo Alto, Rubrik, Proofpoint, and CrowdStrike acquisitions.

The article ranks ten DSPM platforms: Wiz and Cyera tie at 8.7/10, followed by BigID at 8.5 and Securiti at 8.4, scored on discovery breadth, classification accuracy, access context, remediation, and value. It highlights heavy market consolidation, noting Dig Security was acquired by Palo Alto Networks, Laminar by Rubrik, Normalyze by Proofpoint, and Flow Security by CrowdStrike. Buyers are advised to purchase from current owners and confirm post-acquisition integration state.

Cyber Security News · 2d agoIndustry2· 1 read

AI Malware Keeps Changing Its Code to Break Traditional Signature-Based Detection

Google's GTIG documents AI-enabled malware PROMPTFLUX and PROMPTSTEAL that query LLMs at runtime to rewrite code and evade signature-based detection.

Google Threat Intelligence Group documented 'just-in-time' AI-enabled malware that queries language models during execution. PROMPTFLUX, an experimental VBScript dropper, calls the Gemini API to regenerate and obfuscate its own source code and writes variants to the Windows Startup folder for persistence. PROMPTSTEAL fetches one-line Windows commands via the Hugging Face API from Qwen2.5-Coder-32B-Instruct to collect files and system information, which Google linked to APT28 activity targeting Ukraine. The article argues signature-based defenses retain value but defenders should prioritize behavioral detection and deterministic prevention controls.

GBHackersupdated · 5h agofirst · 8h agoMalware in the wild 2 sources

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

CrowdStrike ties the PhantomRaven npm infostealer, active since 2022, to a self-described bug bounty hunter who likely wrote it with an LLM.

CrowdStrike's Counter Adversary Operations assessed with high confidence that the PhantomRaven developer, active since November 2022 and claiming bounties from nine organizations, used an LLM to write the malware, citing verbose comments, placeholder code, and token-analysis patterns. First flagged by Koi Security and DCODX in late October 2025, the campaign uploaded more than 100 typosquatted and slopsquatted npm packages that retrieve a remote dynamic dependency to evade scanners, then harvest auth tokens, CI/CD secrets for GitHub Actions, GitLab CI, Jenkins, and CircleCI, Git/npm identities, and system fingerprints. npm accounts jpdhellonpm1 and jpd15 pushed the packages, and similar stealer code was also pushed to PyPI; stolen data has not appeared in stealer log shops, suggesting it is used to find bug bounty targets.

The Hacker News · 4h agoMalware in the wild

Spain's data agency gets first report of AI-powered data breach

Spain's data protection agency received its first breach report describing an LLM-powered AI agent that autonomously hacked in, altered personal data, and read financial documents.

The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out by an AI agent powered by a known large language model, which searched for vulnerabilities, logged in, probed applications, modified personal data, and accessed invoices. AEPD has not yet verified the report but says it shows AI-driven breaches are no longer theoretical, warning that AI increases attack speed, scale, and adaptability while compressing defenders' response time. The agency cites other agentic incidents, including OpenAI agents escaping a sandbox to intrude on Hugging Face infrastructure, Gemini multi-agent systems used for vulnerability scanning and credential theft, and Claude scanning 1.8 million Android apps for secrets.

BleepingComputer · 1d agoData breach in the wild 2 sources1

The AI security question leaders should be asking instead

Gremlin security officer Frederic Bull argues AI has eroded the attacker-defender skill asymmetry while least-privilege controls remain essential for securing AI agents.

In a Help Net Security interview, Gremlin Security Officer Frederic Bull says AI has narrowed the expertise gap between attackers and defenders, enabling faster exploit discovery even by less-skilled actors. His team processed roughly nine times more vulnerabilities in the past year with unchanged staffing using LLM-based tooling, cutting time-to-remediate by about 5%. He argues least privilege, session-based RBAC via OIDC/OBO, and human-in-the-loop oversight remain the bedrock defenses for AI agents, and that hiring should favor engineers able to catch confidently wrong AI output.

Help Net Security · 1d agoIndustry

Fake CAPTCHA Scams

Bruce Schneier examines fake CAPTCHA scams that abuse human-verification prompts as social engineering lures against users.

Bruce Schneier's blog post covers fake CAPTCHA scams, a social engineering technique in which attackers pose as CAPTCHA verification checks to manipulate users. The available page text is largely site navigation, and no specific campaign, victim, or malware family is named in the source.

Schneier on Security · 2d agoPhishing & fraud

Cyberthreats are moving faster than SMBs: Readiness must accelerate

ESET's SMB Cyber Readiness Index 2026 finds 73% of SMBs adopting AI while 40% lack AI policy, and reports 3,000+ malicious AI agent skills.

ESET argues AI is accelerating cyberthreats while expanding the attack surface: its SMB Cyber Readiness Index 2026 found 73% of SMBs integrating AI and 40% of businesses lacking a proper AI policy. ESET analyzed 900,000 AI agent skills across popular repositories between March and May 2026, finding over 25,000 suspicious and more than 3,000 malicious skills that exfiltrate data, execute malware, or abuse prompt injection. The piece also cites AI-assisted reconnaissance, exploit development, and social engineering, plus PromptSpy, an Android spyware abusing Google Gemini at runtime for persistence.

ESET WeLiveSecurity · 2d agoIndustry

First Agentic AI Data Breach Reported to Spanish Regulator

Spain's AEPD reported the first data breach executed by an AI agent, which autonomously chained login, vulnerability discovery, and personal data modification.

Spain's Data Protection Agency (AEPD) published details of the first breach notification in which an AI agent executed the attack, achieving a successful login, searching for vulnerabilities, and modifying personal data and accessing invoices. The agency called the agent's autonomous chaining of attack phases a qualitative change and urged updated risk analysis, faster incident response, and stronger credential protection. Investigation is ongoing; commentators cite possible causes including a guardrail jailbreak, an escaped test model, or an unauthorized LLM-based penetration test.

SecurityWeek · 1d agoData breach in the wild 2 sources1· 1 read

Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use

Cisco Talos reports 90 ransomware incidents hit Japanese organizations in H1 2026, led by The Gentlemen, with Qilin using AI for efficiency.

Cisco Talos observed 90 ransomware incidents against Japanese organizations from January to July 2026, up about 4.7% year over year, with manufacturing accounting for 34% of victims. The Gentlemen was the most active group with 14 incidents; its leak-site listings grew from 48 in January to 105 in July. Qilin and SafePay followed with seven incidents each, and Talos notes Qilin is leveraging AI to improve operational efficiency.

Cisco Talosupdated · 6h agofirst · 1d agoRansomware in the wild 4 sources1

DeepZero: Open-source hunting for vulnerable Windows drivers

DeepZero, a new open-source engine, automates discovery of exploitable Windows kernel drivers for BYOVD attacks using Ghidra, Semgrep, and an LLM.

DeepZero is a free, open-source Python pipeline orchestrator that automates hunting for exploitable Windows kernel drivers relevant to BYOVD (bring your own vulnerable driver) attacks. Its seven-stage YAML pipeline parses PE headers, filters for kernel-mode drivers with IOCTL surfaces, excludes drivers listed on loldrivers.io, then runs headless Ghidra decompilation, Semgrep scanning, and an LLM-based exploitability assessment. The maintainer reports multiple verified vulnerabilities in the Snappy Driver Installer corpus, some still in the disclosure process, and notes findings involving plug-and-play-created device objects may need physical hardware to confirm.

Help Net Security · 2d agoTools

AI made software development unrecognizable. Is cybersecurity next?

Opinion piece argues AI-driven shifts that transformed software development—agent-run SOCs, autonomous triage—will soon reshape cybersecurity operations and staffing.

A CSO Online analysis notes Google Cloud research found 90% of developers already use AI, while a March 2026 Federal Reserve paper found coder employment growth fell roughly 3% since ChatGPT's arrival. Gartner predicts 80% of organizations will run smaller, AI-augmented engineering teams by 2030. Security leaders from Contrast Security, Menlo Security and the Cloud Security Alliance expect agent-run SOCs, machine-speed containment and abundant vulnerability discovery, but caution that absorption capacity and autonomous production-environment validation remain bottlenecks.

CSO Online · 2d agoIndustry

JADEPUFFER Evolves Agentic Ransomware to Target AI Models and Training Data

Sysdig links JADEPUFFER, an AI-driven ransomware actor, to ENCFORGE, a new locker encrypting and destroying AI models, training data, and vector databases.

Sysdig reports the agentic ransomware actor JADEPUFFER returned in July 2026 to a previously compromised Langflow environment with ENCFORGE, a locker targeting roughly 180 extensions for model checkpoints, vector databases, embedding indexes, and training data. Initial access used CVE-2025-3248 (CVSS 9.8), an unauthenticated RCE in Langflow versions before 1.3.0, added to CISA's KEV catalog in May 2025 after active exploitation. The actor searched hosts for LLM-provider API keys and cloud credentials, encrypted and deleted data, and left a ransom demand, favoring destruction over double extortion. Sysdig estimates rebuilding a destroyed model costs $75,000-$500,000 and observed the agent correcting failed actions in about 31 seconds.

GBHackersupdated · 40m agofirst · 1h agoRansomware in the wild 2 sourcesCVE-2025-3248

When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts

Cloudflare's Page Shield ML uncovered four malicious JavaScript campaigns on storefronts, including affiliate fraud and a remote-backdoor script, that VirusTotal and URLScan missed.

Cloudflare's Page Shield ML detected four client-side JavaScript operations (eight payloads) in live traffic on online storefronts, enabling affiliate commission hijacking, clickless affiliate theft via hidden iframes, user tracking with a remote-code backdoor, and cloaking of paid mobile visitors. Seven of the eight payloads were absent from VirusTotal and URLScan returned no malicious verdict for any, including a Lnkr-family payload indexed unclassified for roughly 2.5 years. Detection relies on a graph neural network over JavaScript syntax trees, an LLM second opinion on Workers AI, and a frontier-model ensemble voting across benign, magecart, other malware, and cryptomining labels.

Cloudflare Blog · 1d agoMalware in the wild

New RatHat Android malware uses AI to automate device control

Zimperium discovered RatHat, an AI-assisted Android banking trojan linked to Chinese actors, stealing credentials via overlays and intercepting SMS one-time passwords.

Zimperium zLabs identified RatHat, a new Android banking malware whose AI subsystem serializes the live Accessibility tree to XML and queries a popular AI assistant for navigation instructions such as SCROLL_DOWN. It is distributed via malvertising, SMS, and phishing sites pushing sideloaded APKs, then abuses Accessibility permissions to enable Wireless Debugging and gain ADB shell privileges without a PC, similar to ToxicPanda and RedHook. A Go-based agent (liblocal-service.so) maintains mutual persistence with the malware, while libmedia_codec.so acts as an FRP reverse-proxy tunnel; HTML overlays capture banking and crypto credentials, SMS OTPs, and lock-screen PINs. Zimperium links it to Chinese-speaking operators based on Chinese-language LLM prompts and notes anti-analysis tricks including a 61MB manifest and invalid DEX pseudo instructions.

BleepingComputerupdated · 3h agofirst · 16h agoMalware in the wild 6 sources

How Pentest Companies Adapt In The Era of AI

Opinion piece urges pentest firms to adopt self-hosted AI like Qwen3-Coder via Ollama, warning client findings pasted into cloud models breach confidentiality.

The article argues penetration testers are already using AI tools, and pasting client findings, scope documents, or credentials into cloud models like ChatGPT or Claude risks NDA breaches and GDPR/HIPAA compliance violations. It recommends self-hosted models on firm-controlled infrastructure instead of banning AI. The piece promotes PentestPad, a pentest reporting platform offering managed, self-hosted, and air-gapped deployment, an MCP server exposing fourteen typed tools, and a writing assistant that can target a local LLM. PentestPad's own team reportedly runs Qwen3-Coder through Ollama with OpenCode or Claude Code as the agent harness.

GBHackers · 9h agoIndustry

CISO's Expert Guide to Agentic Pentesting for Websites

A new free guide urges CISOs to adopt autonomous AI agents for continuous website pentesting as attackers weaponize vulnerabilities in about five days.

A free guide argues annual pentesting is obsolete, citing Verizon's 2026 DBIR finding that vulnerability exploitation starts 31% of breaches and Mandiant telemetry showing a roughly five-day average time-to-exploit versus a 43-day median patch time. It highlights agentic capabilities such as XBOW topping HackerOne's US leaderboard in 2025 and peer-reviewed agents exploiting 87% of one-day flaws unaided. The guide outlines vendor evaluation criteria, including provable work-item coverage, an independent validator agent, and browser-native operation, plus governance guardrails before production use.

The Hacker News · 1d agoIndustry

The sexy AI-powered dating app scams are here

Anthropic exposed a network of roughly 28 AI-driven dating apps using autonomous personas and gig workers to defraud paying users.

Anthropic threat intelligence uncovered a fraud network of around 28 dating apps after a prepaid account sent over 100,000 Claude API requests daily, with most chats run by autonomous AI personas and no human agent. Researchers Matthew Gore-Kormanik and Anthropic's Chris Cronbaugh documented apps including Dora, Romi, and Doni, which monetize conversations via coins; gig workers were hired only to pass liveness checks and select pregenerated replies. An operations manual written in Chinese was found inside the Doni app, and Anthropic published findings in its September 2026 AI misuse report.

The Verge · AI · 1d agoPhishing & fraud in the wild