Machine Speed
AI-Cyber Intel
The Board
Watchlist
Briefs
Newsletter
About
RSS
☀
Light
Lanes
Capability
86
Policy
56
Defense
82
Attacks
92
Markets
29
AI in real attacks
Attackers using AI models and agents in actual operations.
Back to the Watchlist
33
Items
Jul 1
First
Sep 25
Latest
Threads in this topic
Agent-abuse attack surface
33
Sep 25
Sep 25
Attacks
Microsoft tracks the first documented agentic ransomware crew into an Azure tenant's service principals
Microsoft Security Research ↗
Sep 23
Attacks
A Docker botnet installs an off-the-shelf AI agent and tells it to take AI API keys first
ThreatDown ↗
Sep 22
Attacks
One operator ran three open-source AI harnesses against online retailers at about $25 a company
Gambit Security ↗
Sep 22
Attacks
Cisco Talos documents a Windows implant that lets four AI models vote on its next move
Cisco Talos ↗
Sep 22
Defense
Microsoft disrupts EvilTokens, a phishing service that sold an AI assistant with the kit
Microsoft Threat Intelligence ↗
Sep 22
Defense
Talos open-sources a framework for hunting AI-integrated malware
Cisco Talos ↗
Sep 15
Attacks
Researchers find an uncensored AI service sold by subscription on a criminal forum as an alternative to jailbreaking
Sophos Counter Threat Unit (via Help Net Security) ↗
Sep 14
Attacks
Spain's data protection agency records its first notified personal-data breach executed by an AI agent
Agencia Española de Protección de Datos (AEPD) ↗
Sep 10
Attacks
Anthropic says a majority of the misuse operations it disrupted were executed or orchestrated by AI
Anthropic ↗
Sep 10
Attacks
An espionage group ran its own autonomous vulnerability research program against a major security product
Anthropic ↗
Sep 9
Attacks
Hundreds of AI agents drive a PaperCut campaign reaching 440 instances in 48 countries
GreyNoise ↗
Sep 9
Policy
A bipartisan House bill would have NIST write standards for finding, verifying and cutting off AI agents
Office of Rep. Josh Gottheimer ↗
Sep 8
Attacks
Google says a PRC-nexus actor runs open-weight models on victim compute to escape API monitoring, and that AI models and prompts are now extortion targets
Google Threat Intelligence Group / Mandiant ↗
Sep 8
Attacks
Google records an attacker planning, building and running a mass credential-harvesting campaign with an autonomous multi-agent framework in under six hours
Google Threat Intelligence Group / Mandiant ↗
Sep 3
Attacks
Unit 42 finds two criminal clusters in Latin America running intrusions with commercial chatbots
Palo Alto Networks Unit 42 ↗
Sep 2
Attacks
Unit 42 investigates an intrusion that ran more than 50 ATT&CK techniques in under ten hours
Unit 42 (Palo Alto Networks) ↗
Sep 2
Defense
Booz Allen launches a counter-AI product and reports playbooks that cut autonomous-attacker success by more than 95%
Booz Allen Hamilton ↗
Aug 27
Attacks
Ransomware operators ran Cursor Agent inside victim networks to carry out hands-on intrusion steps
Gambit Security ↗
Aug 27
Defense
NIST says organisations are repeating decades-old identity mistakes with AI agents
NIST ↗
Aug 26
Attacks
FBI, NSA and Cyber National Mission Force say a China-linked group has been integrating AI into its operations
FBI / NSA / Cyber National Mission Force ↗
Aug 25
Attacks
Joe Security analyses ToxNetV2, a Linux botnet that queries a jailbroken hosted LLM to propose attack commands
Joe Security (via Cyber Security News) ↗
Aug 20
Attacks
Cisco Talos finds a Chinese-speaking crew running agentic-AI tools in live post-compromise operations
Cisco Talos ↗
Aug 20
Defense
UK NCSC issues interim guidance on securing agentic AI, including keeping the ability to “pull the plug”
UK NCSC ↗
Aug 17
Attacks
Rapid7 finds a crypto-fraud crew used Claude Code to build and run a vishing pipeline against wallet users
Rapid7 ↗
Aug 13
Attacks
Israeli firm Dream reports China-linked operators ran a near-autonomous AI-agent intrusion of Taiwan's government
Dream / Taiwan Administration for Cyber Security ↗
Aug 13
Attacks
Trellix reports purpose-built offensive AI tools are being sold on criminal forums
Trellix (via Cybersecurity Dive) ↗
Aug 10
Attacks
A personal AI agent told only to book a gym class autonomously exploited the booking API to cancel another member's reservation
ABC News (via The Next Web) ↗
Aug 3
Attacks
CrowdStrike's 2026 Threat Hunting Report says AI is now embedded across adversary operations
CrowdStrike ↗
Jul 30
Attacks
Unit 42 reports Chinese-speaking actor running autonomous attacks with DeepSeek and the Hermes Agent framework
Palo Alto Networks Unit 42 ↗
Jul 24
Attacks
Open-source Hermes agent run in "YOLO mode" automated an intrusion at Thailand's finance ministry
BleepingComputer ↗
Jul 21
Attacks
LLM-run agent deploys "ENCFORGE" ransomware built to encrypt AI/ML model stacks
Sysdig / Help Net Security ↗
Jul 14
Attacks
Hunt.io reports suspected China-linked operators running Claude Code and DeepSeek as an intrusion toolchain against government targets in four countries
Hunt.io ↗
Jul 1
Attacks
Sysdig documents JADEPUFFER, an LLM-driven agent that autonomously exploited Langflow and extorted a production database
Sysdig ↗
Items, newest week first
Week of Sep 21
6
Sep 25
Attacks
Microsoft tracks the first documented agentic ransomware crew into an Azure tenant's service principals
Sep 23
Attacks
A Docker botnet installs an off-the-shelf AI agent and tells it to take AI API keys first
Sep 22
Attacks
Cisco Talos documents a Windows implant that lets four AI models vote on its next move
Sep 22
Defense
Talos open-sources a framework for hunting AI-integrated malware
Sep 22
Defense
Microsoft disrupts EvilTokens, a phishing service that sold an AI assistant with the kit
Sep 22
Attacks
One operator ran three open-source AI harnesses against online retailers at about $25 a company
Week of Sep 14
2
Sep 15
Attacks
Researchers find an uncensored AI service sold by subscription on a criminal forum as an alternative to jailbreaking
Sep 14
Attacks
Spain's data protection agency records its first notified personal-data breach executed by an AI agent
Week of Sep 7
6
Sep 10
Attacks
Anthropic says a majority of the misuse operations it disrupted were executed or orchestrated by AI
Sep 10
Attacks
An espionage group ran its own autonomous vulnerability research program against a major security product
Sep 9
Attacks
Hundreds of AI agents drive a PaperCut campaign reaching 440 instances in 48 countries
Sep 9
Policy
A bipartisan House bill would have NIST write standards for finding, verifying and cutting off AI agents
Sep 8
Attacks
Google records an attacker planning, building and running a mass credential-harvesting campaign with an autonomous multi-agent framework in under six hours
Sep 8
Attacks
Google says a PRC-nexus actor runs open-weight models on victim compute to escape API monitoring, and that AI models and prompts are now extortion targets
Week of Aug 31
3
Sep 3
Attacks
Unit 42 finds two criminal clusters in Latin America running intrusions with commercial chatbots
Sep 2
Attacks
Unit 42 investigates an intrusion that ran more than 50 ATT&CK techniques in under ten hours
Sep 2
Defense
Booz Allen launches a counter-AI product and reports playbooks that cut autonomous-attacker success by more than 95%
Week of Aug 24
4
Aug 27
Attacks
Ransomware operators ran Cursor Agent inside victim networks to carry out hands-on intrusion steps
Aug 27
Defense
NIST says organisations are repeating decades-old identity mistakes with AI agents
Aug 26
Attacks
FBI, NSA and Cyber National Mission Force say a China-linked group has been integrating AI into its operations
Aug 25
Attacks
Joe Security analyses ToxNetV2, a Linux botnet that queries a jailbroken hosted LLM to propose attack commands
Week of Aug 17
3
Aug 20
Attacks
Cisco Talos finds a Chinese-speaking crew running agentic-AI tools in live post-compromise operations
Aug 20
Defense
UK NCSC issues interim guidance on securing agentic AI, including keeping the ability to “pull the plug”
Aug 17
Attacks
Rapid7 finds a crypto-fraud crew used Claude Code to build and run a vishing pipeline against wallet users
Week of Aug 10
3
Aug 13
Attacks
Israeli firm Dream reports China-linked operators ran a near-autonomous AI-agent intrusion of Taiwan's government
Aug 13
Attacks
Trellix reports purpose-built offensive AI tools are being sold on criminal forums
Aug 10
Attacks
A personal AI agent told only to book a gym class autonomously exploited the booking API to cancel another member's reservation
Week of Aug 3
1
Aug 3
Attacks
CrowdStrike's 2026 Threat Hunting Report says AI is now embedded across adversary operations
Week of Jul 27
1
Jul 30
Attacks
Unit 42 reports Chinese-speaking actor running autonomous attacks with DeepSeek and the Hermes Agent framework
Week of Jul 20
2
Jul 24
Attacks
Open-source Hermes agent run in "YOLO mode" automated an intrusion at Thailand's finance ministry
Jul 21
Attacks
LLM-run agent deploys "ENCFORGE" ransomware built to encrypt AI/ML model stacks
Week of Jul 13
1
Jul 14
Attacks
Hunt.io reports suspected China-linked operators running Claude Code and DeepSeek as an intrusion toolchain against government targets in four countries
Week of Jun 29
1
Jul 1
Attacks
Sysdig documents JADEPUFFER, an LLM-driven agent that autonomously exploited Langflow and extorted a production database