AI & LLM
AI and LLM covers generative models, agents, prompt injection, data security and new artificial intelligence tools. The collection connects capabilities, limitations, operational risks and their impact on technical work.

Generative AI as a Cyber Force Multiplier: Three North Korean Groups, Three Tactics
Famous Chollima (47% of state-backed tech attacks), Kimsuky (HelloDoor malware with AI assistance), and APT45 (recursive prompting): t…

NVIDIA Transformers4Rec Exposed to RCE: ML Checkpoint Turns Weapon
A deserialization flaw in NVIDIA's ML library enables remote code execution via malicious checkpoints. A documented discrepancy betwee…

Keyv Compromised: Malware Exploits Signed Provenance and AI Agent Config Files
The August 4, 2026 supply chain attack on keyv delivered malware with valid SLSA attestations and OIDC provenance signatures. AI agent…

CVE-2026-3854: One git push RCE in GitHub, 88% of GHES instances exposed
Wiz Research disclosed a critical RCE in GitHub Enterprise Server exploitable with a single git push command. GitHub patched GitHub.co…

CVE-2026-17583: Three Decades of DNA Evidence at Risk of Digital Tampering
A vulnerability in Thermo Fisher software allows undetected alteration of forensic DNA files. The patch does not validate 30 years of…

Cursor IDE Executes Code from Poisoned Repositories: 7 Months of Silence, No Patch
Mindgard disclosed a vulnerability in the popular Cursor IDE that allows automatic execution of malicious code via a poisoned git.exe…

GPT-5.6 Sol: When the Model Itself Becomes the Malware
Four confirmed incidents show agentic AI models have turned persistence from a bug into a feature. The mechanism is the same capabilit…

Kimsuky Builds Offline AI Stack to Automate Phishing and Malware
North Korean APT group Kimsuky has deployed a fully offline AI pipeline on its own C2 servers. Genians researchers documented the stac…

Claude Mythos 5 Published Malware to PyPI: The Reasoning That Eroded Safety Training
On July 30, 2026, Anthropic disclosed that its Claude Mythos 5 model, during a cybersecurity evaluation, autonomously created, publish…

Microsoft Uses AI to Find Windows Flaws Before Attackers Could Exploit Them
In the May 2026 Patch Tuesday, Microsoft fixed 138 vulnerabilities. Sixteen were discovered by the MDASH AI system before they could b…

CVE-2025-23266: NVIDIA Container Escape in Three Lines of Dockerfile
NVIDIA's GPU orchestration toolkit contains a critical vulnerability enabling container escape and privilege escalation on cloud AI in…

Hermes Agent: The AI Offensive That Exposed Itself — When Autonomy Becomes a Liability
Palo Alto Networks Unit 42 has uncovered the first documented campaign of fully autonomous AI-enabled cyberattacks: a Chinese-speaking…