AI & LLM
AI and LLM covers generative models, agents, prompt injection, data security and new artificial intelligence tools. The collection connects capabilities, limitations, operational risks and their impact on technical work.

Threat Actors Use AI to Attack Siemens PLCs in Critical Infrastructure
U.S. federal agencies warn that AI-generated exploit scripts are actively targeting internet-exposed Siemens S7 PLCs. No OT expertise…

Five US Agencies: Generative AI Is Accelerating Attacks on Siemens S7 PLCs
NSA, CISA, FBI, DOE, and EPA issued a joint advisory on August 19, 2026, warning that unidentified threat actors are using generative…

Google Mandiant Unveils AVDH Architecture: AI Agents vs. Vulnerabilities
Google's Threat Intelligence Group has disclosed the Agentic Vulnerability Discovery Harness (AVDH), a multi-agent system built on lar…

North Korea’s Famous Chollima Behind 47% of State-Backed Tech Attacks
The North Korean group Famous Chollima carried out 47% of all state-sponsored attacks against the technology sector in one year, using…

Exposed Directory Reveals Autonomous AI Fleet for Industrial-Scale Crypto Theft
A Chinese-speaking operator orchestrated entire offensive campaigns using multi-vendor AI agents in full-auto mode. A misconfiguration…

NGINX DAV: Pre-Auth RCE Discovered by Calif.io in Collaboration with
CVE-2026-27654 in the NGINX HTTP DAV module: an integer underflow triggered by an alias in a prefix location enables unauthenticated r…

TeamPCP/UNC6780: Six Enterprise Breaches From Trivy to LiteLLM
The TeamPCP/UNC6780 campaign compromised Trivy to poison LiteLLM on PyPI. According to Hudson Rock, six enterprise breaches resulted w…

Underground Markets Sell AI Tools to Orchestrate Ransomware Without Expertise
Trellix researchers have uncovered LLM-powered hacking tools for sale on underground forums that dramatically lower the technical barr…

Copilot Autofix Introduces Vulnerability in Snowflake CI/CD, Then an AI Agent Finds It
GitHub Copilot Autofix introduced a script injection flaw into a Snowflake GitHub Actions workflow. Five days later, Wiz's autonomous…

Ransomware Q2 2026: 2,139 Victims and Payment Rate Crashes to 23%
Ransomware isn't slowing down — it's fragmenting. Q2 2026 saw 93 active groups, up from 71 at the start of the year. The top-10 share…

Rubrik Zero Labs Unveils RPE: From Word Document to Shell on Copilot
Remote Prompt Execution turns prompt injection into full enterprise identity compromise on Microsoft 365 Copilot. The five-stage chain…

Generative AI as a Cyber Force Multiplier: Three North Korean Groups, Three Tactics
Famous Chollima (47% of state-backed tech attacks), Kimsuky (HelloDoor malware with AI assistance), and APT45 (recursive prompting): t…