# Threat Research

Cybersecurity discipline that investigates adversary behavior and malicious software to inform threat detection.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face

DevFeed: [Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face](<https://devfeed.tech/articles/agents-at-large-tracing-illicit-openai-agent-activity-on-hugging-face-30905.md>)

Original publisher: [Read original article](<https://www.sentinelone.com/labs/agents-at-large-tracing-illicit-openai-agent-activity-on-hugging-face/>)

Author: Tom Hegel

Published: 2026-09-16T10:00:34Z

Content type: article

Language: en

Sources: [SentinelLabs - We are hunters, reversers, exploit developers, and tinkerers shedding light on the world of malware, exploits, APTs, and cybercrime across all platforms.](<https://devfeed.tech/sources/sentinellabs-we-are-hunters-reversers-exploit-developers-and-tinkerers-shedding-light-on-the-world-of-malware-exploits-apts-and-cybercrime-across-all-platforms.md>)

Topics: [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [hugging face](<https://devfeed.tech/topics/hugging-face.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [spaces](<https://devfeed.tech/topics/spaces.md>), [Flask](<https://devfeed.tech/topics/flask.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [HTTP](<https://devfeed.tech/topics/http.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [agents](<https://devfeed.tech/tags/agents.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [flask](<https://devfeed.tech/tags/flask.md>), [http](<https://devfeed.tech/tags/http.md>), [hugging-face](<https://devfeed.tech/tags/hugging-face.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [openai](<https://devfeed.tech/tags/openai.md>), [research](<https://devfeed.tech/tags/research.md>), [spaces](<https://devfeed.tech/tags/spaces.md>), [token](<https://devfeed.tech/tags/token.md>)

### AI overview

SentinelLABS traces activity associated with two Hugging Face accounts, 0Time and Nyx9, that appears to extend OpenAI's published chronology. The report describes relay-code commits, a workbook containing unexecuted-looking external probes, and a Flask-wrapped tool that could potentially provision ChatGPT identities or OAuth credentials if deployed and invoked.

### Source excerpt

Two Hugging Face accounts reveal that OpenAI's agents staged relay code, internal probes and ChatGPT account registration beyond the published timeline.

## Infoblox reports malicious infrastructure beneath illegal gambling sites

DevFeed: [Infoblox reports malicious infrastructure beneath illegal gambling sites](<https://devfeed.tech/articles/low-quality-casino-sites-conceal-highly-dangerous-threat-actors-26962.md>)

Original publisher: [Read original article](<https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652>)

Author: Thomas Claburn

Published: 2026-09-15T19:38:58Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>)

Tags: [command-and-control](<https://devfeed.tech/tags/command-and-control.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [infoblox](<https://devfeed.tech/tags/infoblox.md>), [infosec](<https://devfeed.tech/tags/infosec.md>), [malware](<https://devfeed.tech/tags/malware.md>), [online-gambling](<https://devfeed.tech/tags/online-gambling.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Infoblox reports that malicious infrastructure is operating beneath illegal gambling sites and is linked to threat actors.

### Source excerpt

Security firm Infoblox shines light on malicious infrastructure lurking beneath illegal gambling sites

## The Dodo Digest: The Report Is the Product

DevFeed: [The Dodo Digest: The Report Is the Product](<https://devfeed.tech/articles/the-dodo-digest-the-report-is-the-product-26683.md>)

Original publisher: [Read original article](<https://dodopayments.com/blogs/newsletter-september15/>)

Author: Rishabh Goel

Published: 2026-09-15T00:00:00Z

Content type: article

Language: en

Sources: [Dodo Payments Blog](<https://devfeed.tech/sources/dodo-payments-blog.md>)

Topics: [anthropic](<https://devfeed.tech/topics/anthropic.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Software Engineering](<https://devfeed.tech/topics/software-engineering.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [newsletter](<https://devfeed.tech/tags/newsletter.md>), [product](<https://devfeed.tech/tags/product.md>), [report](<https://devfeed.tech/tags/report.md>), [threat-intelligence](<https://devfeed.tech/tags/threat-intelligence.md>), [v1](<https://devfeed.tech/tags/v1.md>)

### AI overview

This newsletter discusses Anthropic's report on eight months of AI misuse, including a campaign in which one person built an AI-assisted platform for mass attacks. It argues that startups can use reports to document learning, demonstrate expertise, and build trust, and mentions Dodo Payments v1.113.28 product improvements.

### Source excerpt

Anthropic turned eight months of threat intelligence into a public report. Why every startup should document what it learns, plus v1.113.28: Reports, grace periods, and blocklists.

## Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection

DevFeed: [Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection](<https://devfeed.tech/articles/unmasking-cloud-identities-from-behavioral-clustering-to-automated-detection-17391.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/behavioral-clustering-map-to-cloud-identities/>)

Author: Osher Jacob

Published: 2026-09-14T10:00:01Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [AWS CloudTrail](<https://devfeed.tech/topics/aws-cloudtrail.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [Machine learning](<https://devfeed.tech/topics/machine-learning.md>), [Algorithms](<https://devfeed.tech/topics/algorithms.md>), [SQL](<https://devfeed.tech/topics/sql.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [identity and access management](<https://devfeed.tech/topics/identity-and-access-management.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>)

Tags: [algorithms](<https://devfeed.tech/tags/algorithms.md>), [amazon-web-services-aws](<https://devfeed.tech/tags/amazon-web-services-aws.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [aws-cloudtrail](<https://devfeed.tech/tags/aws-cloudtrail.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-cybersecurity-research](<https://devfeed.tech/tags/cloud-cybersecurity-research.md>), [cloud-detection](<https://devfeed.tech/tags/cloud-detection.md>), [devops](<https://devfeed.tech/tags/devops.md>), [iam](<https://devfeed.tech/tags/iam.md>), [identity-and-access-management](<https://devfeed.tech/tags/identity-and-access-management.md>), [logs](<https://devfeed.tech/tags/logs.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [post](<https://devfeed.tech/tags/post.md>), [sql](<https://devfeed.tech/tags/sql.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>)

### AI overview

This article presents a behavioral clustering model for mapping cloud identities to functional roles using activity patterns from audit logs. It applies unsupervised machine learning with UMAP and HDBSCAN to data from more than 40,000 identities across 125 cloud environments, and shows how the resulting map can support automated threat detection. The article also explains how lightweight heuristics extracted from the map can classify identities at scale using standard SQL, reducing the need for continuous resource-intensive machine learning pipelines.

### Source excerpt

We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries. The post Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection appeared first on Unit 42.

## Detect and disrupt AI-themed attacks with Microsoft Defender

DevFeed: [Detect and disrupt AI-themed attacks with Microsoft Defender](<https://devfeed.tech/articles/detect-and-disrupt-ai-themed-attacks-with-microsoft-defender-7644.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/10/detect-and-disrupt-ai-themed-attacks-with-microsoft-defender/>)

Author: Rob Lefferts

Published: 2026-09-10T16:00:00Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [adversary-in-the-middle-aitm](<https://devfeed.tech/tags/adversary-in-the-middle-aitm.md>), [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [claude](<https://devfeed.tech/tags/claude.md>), [copilot](<https://devfeed.tech/tags/copilot.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [deepseek](<https://devfeed.tech/tags/deepseek.md>), [defender](<https://devfeed.tech/tags/defender.md>), [github](<https://devfeed.tech/tags/github.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>)

### AI overview

Microsoft describes AI-themed phishing, malvertising, credential theft, and malware campaigns that impersonate popular AI services and tools. It argues that attackers are exploiting trust and urgency around AI brands rather than compromising the referenced services.

### Source excerpt

See how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain. The post Detect and disrupt AI-themed attacks with Microsoft Defender appeared first on Microsoft Security Blog.

## GuardBreaker: Derailing AI-assisted malware analysis with a code comment

DevFeed: [GuardBreaker: Derailing AI-assisted malware analysis with a code comment](<https://devfeed.tech/articles/guardbreaker-derailing-ai-assisted-malware-analysis-with-a-code-comment-8333.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/guardbreaker-derailing-ai-assisted-malware-analysis-code-comment/>)

Author: Tomáš Foltýn

Published: 2026-09-10T09:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Machine Learning, Security Attacks](<https://devfeed.tech/topics/machine-learning-security-attacks.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [llm](<https://devfeed.tech/tags/llm.md>), [malware](<https://devfeed.tech/tags/malware.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article describes GuardBreaker, a prompt-injection technique that hides a safety-triggering request in a VBScript comment to disrupt an LLM-powered malware code scanner. The comment does not affect runtime behavior, but may cause the model to stop analysis before reaching malicious code.

### Source excerpt

LLM-based code scanners won't help attackers build a nuclear weapon, but that refusal could work in their favor

## Expanding AI access and cyber defense for federal, state, local, and tribal governments

DevFeed: [Expanding AI access and cyber defense for federal, state, local, and tribal governments](<https://devfeed.tech/articles/expanding-ai-access-and-cyber-defense-for-federal-state-local-and-tribal-governments-6398.md>)

Original publisher: [Read original article](<https://openai.com/index/expanding-ai-access-us-government>)

Published: 2026-09-10T07:00:00Z

Content type: news

Language: en

Sources: [OpenAI News](<https://devfeed.tech/sources/openai-news.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Malware](<https://devfeed.tech/topics/malware.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [global-affairs](<https://devfeed.tech/tags/global-affairs.md>), [government](<https://devfeed.tech/tags/government.md>), [malware](<https://devfeed.tech/tags/malware.md>), [openai](<https://devfeed.tech/tags/openai.md>), [public-sector](<https://devfeed.tech/tags/public-sector.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

OpenAI and the GSA announced a multi-year agreement offering eligible U.S. government users waived license fees, discounted usage, and expanded support for cyber defenders.

### Source excerpt

OpenAI and GSA will offer eligible federal, state, local, and tribal governments $0 license fees, 50% off usage, and expanded cyber defense support.

## Welcome to APNIC 62

DevFeed: [Welcome to APNIC 62](<https://devfeed.tech/articles/welcome-to-apnic-62-10861.md>)

Original publisher: [Read original article](<https://blog.apnic.net/2026/09/08/welcome-to-apnic-62/>)

Author: Timothy Hildred

Published: 2026-09-08T03:33:07Z

Content type: article

Language: en

Sources: [APNIC Blog](<https://devfeed.tech/sources/apnic-blog.md>)

Topics: [Internet](<https://devfeed.tech/topics/internet.md>), [Networks](<https://devfeed.tech/topics/networks.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [DNSSEC](<https://devfeed.tech/topics/dnssec.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [FIRST](<https://devfeed.tech/topics/first.md>)

Tags: [apnic-62](<https://devfeed.tech/tags/apnic-62.md>), [community](<https://devfeed.tech/tags/community.md>), [conference](<https://devfeed.tech/tags/conference.md>), [conferences](<https://devfeed.tech/tags/conferences.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [dnssec](<https://devfeed.tech/tags/dnssec.md>), [event](<https://devfeed.tech/tags/event.md>), [events](<https://devfeed.tech/tags/events.md>), [india](<https://devfeed.tech/tags/india.md>), [ipv4](<https://devfeed.tech/tags/ipv4.md>), [ipv6](<https://devfeed.tech/tags/ipv6.md>), [nixi](<https://devfeed.tech/tags/nixi.md>), [nro](<https://devfeed.tech/tags/nro.md>), [policy-sig](<https://devfeed.tech/tags/policy-sig.md>), [tech-matters](<https://devfeed.tech/tags/tech-matters.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

APNIC 62 in Mumbai previews technical, security, IPv6 deployment, DNSSEC, threat-detection, community, and policy sessions, alongside keynote talks, social events, newcomer activities, and NRO NC voting information.

### Source excerpt

APNIC welcomes you to Mumbai, India for APNIC 62. Here is what you can look forward to over the coming days.

## Critical remote code execution in vm2, a widely used Node.js sandbox library

DevFeed: [Critical remote code execution in vm2, a widely used Node.js sandbox library](<https://devfeed.tech/articles/critical-remote-code-execution-in-vm2-a-widely-used-node-js-sandbox-library-87.md>)

Original publisher: [Read original article](<https://about.gitlab.com/blog/critical-remote-code-execution-in-vm2/>)

Author: Daniel Abeles

Published: 2026-09-02T00:00:00Z

Content type: news

Language: en

Sources: [GitLab](<https://devfeed.tech/sources/gitlab.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Node.js](<https://devfeed.tech/topics/node-js.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [containers](<https://devfeed.tech/tags/containers.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [processes](<https://devfeed.tech/tags/processes.md>), [sandbox](<https://devfeed.tech/tags/sandbox.md>), [security](<https://devfeed.tech/tags/security.md>), [security-labs](<https://devfeed.tech/tags/security-labs.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

GitLab reports a critical vm2 sandbox escape that can enable remote code execution. Version 3.11.7 blocks the reported attack, but the article advises hardening require.root and context settings and avoiding vm2 for truly untrusted code.

### Source excerpt

GitLab's Threat Research Group found a critical sandbox escape vulnerability in vm2, one of the most widely adopted Node.js sandboxing libraries. The vulnerability uses a configuration copied straight from vm2's own README. We found the flaw, rated CVSS 3.1: 10.0, critical, using our own AI automated tools. Anyone running vm2 Version 3.11.6 or earlier with require.external turned on should treat this as directly exploitable. Once we found the vulnerability, we verified GitLab does not use vm2. We also reported it privately to vm2 and the maintainer fixed it fast, in vm2 Version 3.11.7. When we tested that fix again, it blocked the exact attack we reported. For anyone relying on vm2, it's worth flagging that there's a broader configuration risk here that goes beyond this one patch, based on the maintainer's own description of the fix. TL;DR Critical vulnerability: GitLab's Threat Research Group discovered a critical sandbox escape (CVSS 3.1: 10.0) in vm2, a widely used Node.js sandboxing library, which allows for remote code execution. The root cause: The vulnerability stems from default configurations found in the library's own "Quick Examples" README, where the sandbox fails to properly isolate itself from the host system, allowing malicious code to gain unrestricted access. Fix limitations: While updating to Version 3.11.7 blocks the specific attack reported, it does not fully resolve the underlying configuration risk; developers remain vulnerable if they continue to use require.external with overly broad require.root settings. Immediate recommendations: Users should update to Version 3.11.7, but must also manually harden their configurations by restricting require.root to only necessary files and setting context: 'sandbox' instead of relying on the default 'host' setting. Long-term advice: Due to vm2's history of recurring sandbox escape bugs, it is recommended to avoid using it for isolating truly untrusted code and instead opt for more robust methods like conta

## Password spraying campaign targets AWS root user accounts across 150+ organizations

DevFeed: [Password spraying campaign targets AWS root user accounts across 150+ organizations](<https://devfeed.tech/articles/password-spraying-campaign-targets-aws-root-user-accounts-across-150-organizations-8272.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/aws-root-user-bruteforce-campaign/>)

Author: Martin McCloskey

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Security](<https://devfeed.tech/topics/security.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [AWS IAM](<https://devfeed.tech/topics/aws-iam.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [aws](<https://devfeed.tech/tags/aws.md>), [aws-iam](<https://devfeed.tech/tags/aws-iam.md>), [iam](<https://devfeed.tech/tags/iam.md>), [identity](<https://devfeed.tech/tags/identity.md>), [password-spraying](<https://devfeed.tech/tags/password-spraying.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Datadog Security Research describes a password spraying campaign that repeatedly targeted AWS root user accounts at more than 150 organizations between July 24 and August 23, 2026. The campaign used Chrome and Firefox user-agent fingerprints and proxy infrastructure; no successful authentications were observed, and the attackers' motive remains undetermined. The article explains the privileges and safeguards associated with AWS root users and recommends reducing reliance on persistent root credentials.

### Source excerpt

Datadog Security Research observed a password spraying campaign attempting to authenticate as the AWS root user across more than 150 organizations.

## Machine vs. machine: The new reality of cybersecurity in ANZ

DevFeed: [Machine vs. machine: The new reality of cybersecurity in ANZ](<https://devfeed.tech/articles/machine-vs-machine-the-new-reality-of-cybersecurity-in-anz-4790.md>)

Original publisher: [Read original article](<https://www.elastic.co/blog/cybersecurity-in-australia-new-zealand>)

Author: Jeremy Pell

Published: 2026-08-26T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Blog - Elasticsearch, Kibana, and ELK Stack](<https://devfeed.tech/sources/elastic-blog-elasticsearch-kibana-and-elk-stack.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Frontier AI](<https://devfeed.tech/topics/frontier-ai.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [data-architecture](<https://devfeed.tech/topics/data-architecture.md>), [AI Platforms/Deployment](<https://devfeed.tech/topics/ai-platforms-deployment.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>)

Tags: [agentic-ai-cybersecurity-security-research](<https://devfeed.tech/tags/agentic-ai-cybersecurity-security-research.md>), [australia](<https://devfeed.tech/tags/australia.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [data-architecture](<https://devfeed.tech/tags/data-architecture.md>), [endpoint-security-siem-security](<https://devfeed.tech/tags/endpoint-security-siem-security.md>), [frontier-ai](<https://devfeed.tech/tags/frontier-ai.md>), [policy](<https://devfeed.tech/tags/policy.md>), [research](<https://devfeed.tech/tags/research.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

Frontier AI is accelerating cyberattacks across Australia and New Zealand to machine speed, while defensive capabilities, policy, data visibility, and operational security are struggling to keep pace. Survey findings from more than 850 IT and cybersecurity professionals highlight gaps between regulatory intent and real-world protection, as well as the need for searchable, unified data architectures to support reliable AI-enabled defence.

### Source excerpt

Frontier AI has accelerated cyber threats to machine speed, leaving many ANZ organisations vulnerable. Our latest research reveals how fragmented data and visibility gaps hinder defence and why a unified platform is essential to battle threats.

## Rolling with the Punches: Why Cybersecurity is Backgammon, Not Chess

DevFeed: [Rolling with the Punches: Why Cybersecurity is Backgammon, Not Chess](<https://devfeed.tech/articles/rolling-with-the-punches-why-cybersecurity-is-backgammon-not-chess-39493.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/rolling-with-the-punches-why-cybersecurity-is-backgammon-not-chess>)

Author: phil7672

Published: 2026-08-22T16:49:47Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [benchmarking](<https://devfeed.tech/topics/benchmarking.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>)

Tags: [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [risk](<https://devfeed.tech/tags/risk.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-day](<https://devfeed.tech/tags/zero-day.md>)

### AI overview

The article argues that cybersecurity is better understood as backgammon than chess because organizations must prepare for many possible outcomes amid complex dependencies, supply chains, changing technology platforms, and unpredictable attackers. It also argues that cybersecurity benchmarking should focus on control effectiveness and outcomes rather than inputs such as budgets.

### Source excerpt

It is tempting to compare cybersecurity to a chess game. Two adversaries facing each other, plotting strategy and tactics. Move and counter move, anticipating actions and grinding out a win. In reality, in our complex world of dependencies, supply chains, constantly shifting technology platforms and unpredictable attackers, this is all way more haphazard. Indeed, a better analogy is backgammon, where you position yourself for many different possible outcomes to maximize your chance of...

## Frequently asked questions about the active threat to Siemens S7 Series PLCs

DevFeed: [Frequently asked questions about the active threat to Siemens S7 Series PLCs](<https://devfeed.tech/articles/frequently-asked-questions-about-the-active-threat-to-siemens-s7-series-plcs-8263.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/frequently-asked-questions-about-the-active-threat-to-siemens-s7-series-plcs>)

Author: Research Special Operations

Published: 2026-08-20T14:01:58Z

Content type: article

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Script](<https://devfeed.tech/topics/script.md>), [Networks](<https://devfeed.tech/topics/networks.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [networks](<https://devfeed.tech/tags/networks.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [techniques](<https://devfeed.tech/tags/techniques.md>)

### AI overview

This FAQ explains an active threat targeting internet-exposed or insufficiently segmented Siemens S7 Series PLCs. It describes how threat actors use AI-generated exploitation scripts for reconnaissance and capability building, and outlines mitigations including removing direct internet exposure, segmenting OT from IT networks, and hardening access controls.

### Source excerpt

A joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors. Key Takeaways Unattributed threat actors are exploiting known weaknesses and unnecessary internet exposure to conduct reconnaissance and possible pre-positioning for future disruptive attacks against Siemens S7 Series PLCs. The attackers are leveraging AI to build and refine exploit scripts faster than manual development would allow. AI use lowers the technical bar for ICS attacks in a way defenders haven't had to plan for before. There is no single patch, because there is no single flaw. Mitigation depends on removing Siemens S7 Series PLCs from direct internet exposure, segmenting OT from IT networks and hardening access controls. Background On August 19, 2026, the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the Department of Energy (DOE) and the Environmental Protection Agency (EPA) released a joint Cybersecurity Advisory (AA26-231A) warning that threat actors are actively targeting Siemens S7 Series programmable logic controllers (PLCs) that are exposed to the internet or insufficiently segmented from it. The activity spans the S7-200, S7-300, S7-400, S7-1200 and S7-1500 series and most heavily affects the Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture and Commercial Facilities sectors, with potential exposure in the Defense Industrial Base as well. According to the authoring agencies, threat actors are using AI-generated exploitation scripts, disguised as legitimate operational technology (OT) monitoring tools, to conduct reconnaissance and build capability against exposed PLCs. The Tenable Research Special Operations Team (RSO) has put together this frequently asked questions (FAQ) blog to help security and OT

## How AI Is Reshaping Cybersecurity for Attackers and Defenders

DevFeed: [How AI Is Reshaping Cybersecurity for Attackers and Defenders](<https://devfeed.tech/articles/the-defender-s-window-6682.md>)

Original publisher: [Read original article](<https://openai.com/index/the-defenders-window>)

Published: 2026-08-17T05:30:00Z

Content type: opinion

Language: en

Sources: [OpenAI News](<https://devfeed.tech/sources/openai-news.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [AI Models](<https://devfeed.tech/topics/ai-models.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-models](<https://devfeed.tech/tags/ai-models.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [openai](<https://devfeed.tech/tags/openai.md>), [openai-hugging-face-incident](<https://devfeed.tech/tags/openai-hugging-face-incident.md>), [security](<https://devfeed.tech/tags/security.md>), [tech-debt](<https://devfeed.tech/tags/tech-debt.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

OpenAI discusses how AI is changing cybersecurity for both attackers and defenders. The article describes the OpenAI-Hugging Face incident, argues that AI can accelerate the discovery and exploitation of security weaknesses, and outlines defensive measures including stronger security fundamentals and AI-assisted vulnerability remediation.

### Source excerpt

AI is reshaping cybersecurity for attackers and defenders alike. Learn how OpenAI is strengthening its defenses and what security teams can do now.

## The Dodo Digest: The Faster We Build, the More We Risk

DevFeed: [The Dodo Digest: The Faster We Build, the More We Risk](<https://devfeed.tech/articles/the-dodo-digest-the-faster-we-build-the-more-we-risk-10117.md>)

Original publisher: [Read original article](<https://dodopayments.com/blogs/newsletter-august17/>)

Author: Rishabh Goel

Published: 2026-08-17T00:00:00Z

Content type: news

Language: en

Sources: [Dodo Payments Blog](<https://devfeed.tech/sources/dodo-payments-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [anthropic](<https://devfeed.tech/topics/anthropic.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [newsletter](<https://devfeed.tech/tags/newsletter.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openai](<https://devfeed.tech/tags/openai.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The newsletter examines how AI-assisted cyberattacks are moving from controlled security tests into real-world incidents. It discusses reported activity involving OpenAI and Anthropic models, an AI-assisted attack reported by Taiwan, and the role of human operators directing systems that automate reconnaissance, vulnerability discovery, social engineering, account compromise, and information extraction. It also highlights Dodo Payments v1.112.0, including rebuilt webhooks, discount-code improvements, new payment methods, clearer payment failures, and analytics improvements.

### Source excerpt

AI-assisted attacks move from lab tests into real incidents, including Taiwan. Plus v1.112.0: rebuilt webhooks, flexible discount codes, Cash App Pay, and SEPA.

## APNIC 62 keynotes explore automation, trust, and the future of the Internet

DevFeed: [APNIC 62 keynotes explore automation, trust, and the future of the Internet](<https://devfeed.tech/articles/apnic-62-keynotes-explore-automation-trust-and-the-future-of-the-internet-10837.md>)

Original publisher: [Read original article](<https://blog.apnic.net/2026/08/13/apnic-62-keynotes-explore-automation-trust-and-the-future-of-the-internet/>)

Author: Dan Fidler

Published: 2026-08-13T05:57:46Z

Content type: article

Language: en

Sources: [APNIC Blog](<https://devfeed.tech/sources/apnic-blog.md>)

Topics: [Automation](<https://devfeed.tech/topics/automation.md>), [Internet](<https://devfeed.tech/topics/internet.md>), [Network](<https://devfeed.tech/topics/network.md>), [networking](<https://devfeed.tech/topics/networking.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [cloud-computing](<https://devfeed.tech/topics/cloud-computing.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Latency](<https://devfeed.tech/topics/latency.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [apnic-62](<https://devfeed.tech/tags/apnic-62.md>), [automation](<https://devfeed.tech/tags/automation.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [community](<https://devfeed.tech/tags/community.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [edge-computing](<https://devfeed.tech/tags/edge-computing.md>), [events](<https://devfeed.tech/tags/events.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [internet](<https://devfeed.tech/tags/internet.md>), [latency](<https://devfeed.tech/tags/latency.md>), [network](<https://devfeed.tech/tags/network.md>), [networking](<https://devfeed.tech/tags/networking.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [routing](<https://devfeed.tech/tags/routing.md>), [security](<https://devfeed.tech/tags/security.md>), [technology](<https://devfeed.tech/tags/technology.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>)

### AI overview

APNIC 62 will feature keynotes on autonomous network operations and trusted cybersecurity collaboration. The article describes automation, software-defined infrastructure, real-time telemetry, automated routing, self-healing fibre architectures, and zero-touch operations as ways to improve Internet resilience and performance, alongside the importance of cooperation among cybersecurity incident response teams.

### Source excerpt

APNIC 62 will explore two essential foundations of a resilient Internet: Intelligent network automation and trusted cybersecurity collaboration. Keynotes from Amajit Gupta and Yukako Uchida offer complementary perspectives on how technology and human relationships will shape the Internet's future.

## Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave

DevFeed: [Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave](<https://devfeed.tech/articles/cloudflare-ddos-threat-report-h1-2026-1-tbps-attacks-soar-as-dns-floods-and-geopolitical-tensions-drive-a-new-wave-113.md>)

Original publisher: [Read original article](<https://blog.cloudflare.com/ddos-threat-report-2026-h1/>)

Author: Cloudforce One

Published: 2026-08-11T13:00:00Z

Content type: article

Language: en

Sources: [Cloudflare Blog](<https://devfeed.tech/sources/cloudflare-blog.md>)

Topics: [DDoS](<https://devfeed.tech/topics/ddos.md>), [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Cloudforce One](<https://devfeed.tech/topics/cloudforce-one.md>), [Network](<https://devfeed.tech/topics/network.md>), [data](<https://devfeed.tech/topics/data.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [cloudforce-one](<https://devfeed.tech/tags/cloudforce-one.md>), [data](<https://devfeed.tech/tags/data.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [dns](<https://devfeed.tech/tags/dns.md>), [drive](<https://devfeed.tech/tags/drive.md>), [global](<https://devfeed.tech/tags/global.md>), [government](<https://devfeed.tech/tags/government.md>), [industry](<https://devfeed.tech/tags/industry.md>), [iran](<https://devfeed.tech/tags/iran.md>), [media](<https://devfeed.tech/tags/media.md>), [network](<https://devfeed.tech/tags/network.md>), [radar](<https://devfeed.tech/tags/radar.md>), [streaming](<https://devfeed.tech/tags/streaming.md>), [threat-report](<https://devfeed.tech/tags/threat-report.md>)

### AI overview

Cloudflare's H1 2026 DDoS Threat Report analyzes attacks from January through June 2026. It highlights a 519% quarter-over-quarter increase in attacks exceeding 1 Tbps, a shift toward DNS and CLDAP reflection and amplification vectors, and the influence of geopolitical events on attack patterns. The report also covers attack volumes, an April peak, and the possible impact of Operation PowerOFF.

### Source excerpt

In the first half of 2026, Cloudflare detected a 519% surge in hyper-volumetric DDos attacks across its network. These attacks were driven heavily by DNS and CLDAP reflection vectors. This report breaks down how major geopolitical conflicts reshaped the global cyber threat landscape.

## Responding to the next frontier of critical cyber capabilities

DevFeed: [Responding to the next frontier of critical cyber capabilities](<https://devfeed.tech/articles/responding-to-the-next-frontier-of-critical-cyber-capabilities-6629.md>)

Original publisher: [Read original article](<https://openai.com/index/responding-next-frontier-critical-cyber-capabilities>)

Published: 2026-08-07T15:20:00Z

Content type: article

Language: en

Sources: [OpenAI News](<https://devfeed.tech/sources/openai-news.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [agentic-coding](<https://devfeed.tech/topics/agentic-coding.md>), [Benchmark](<https://devfeed.tech/topics/benchmark.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Security](<https://devfeed.tech/topics/security.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [agentic-coding](<https://devfeed.tech/tags/agentic-coding.md>), [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [benchmark](<https://devfeed.tech/tags/benchmark.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [network](<https://devfeed.tech/tags/network.md>), [openai](<https://devfeed.tech/tags/openai.md>), [safety](<https://devfeed.tech/tags/safety.md>), [security](<https://devfeed.tech/tags/security.md>), [systems](<https://devfeed.tech/tags/systems.md>), [testing](<https://devfeed.tech/tags/testing.md>), [tool](<https://devfeed.tech/tags/tool.md>)

### AI overview

OpenAI reports preliminary internal evaluations of its upcoming Astra model, indicating significant advances in agentic coding and cybersecurity. The evaluations suggest that the model may approach the Critical cybersecurity capability threshold, including the ability to develop zero-day exploits or execute novel cyberattack strategies against hardened targets without human intervention. OpenAI says it is strengthening safeguards through stricter security controls, isolated testing, restricted network and tool access, encryption, monitoring, detection, and sandboxed execution.

### Source excerpt

OpenAI is sharing preliminary cybersecurity evaluations for Astra and the steps we're taking to strengthen safeguards and security controls.

## Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?

DevFeed: [Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?](<https://devfeed.tech/articles/sol-searching-can-frontier-models-tackle-autonomous-long-horizon-malware-analysis-8313.md>)

Original publisher: [Read original article](<https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis/>)

Author: Juan Andrés Guerrero-Saade & Gabriel Bernadett-Shapiro

Published: 2026-07-22T16:55:29Z

Content type: article

Language: en

Sources: [SentinelLabs - We are hunters, reversers, exploit developers, and tinkerers shedding light on the world of malware, exploits, APTs, and cybercrime across all platforms.](<https://devfeed.tech/sources/sentinellabs-we-are-hunters-reversers-exploit-developers-and-tinkerers-shedding-light-on-the-world-of-malware-exploits-apts-and-cybercrime-across-all-platforms.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Reverse Engineering](<https://devfeed.tech/topics/reverse-engineering.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Benchmark](<https://devfeed.tech/topics/benchmark.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-models](<https://devfeed.tech/tags/ai-models.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [benchmark](<https://devfeed.tech/tags/benchmark.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [malware](<https://devfeed.tech/tags/malware.md>), [models](<https://devfeed.tech/tags/models.md>), [openai](<https://devfeed.tech/tags/openai.md>), [reasoning](<https://devfeed.tech/tags/reasoning.md>), [reverse-engineering](<https://devfeed.tech/tags/reverse-engineering.md>)

### AI overview

A SentinelLABS benchmark evaluates whether frontier AI models can sustain trustworthy, long-horizon malware investigations as new evidence overturns earlier conclusions. OpenAI's GPT-5.6 Sol completed all eight stages, while other models showed capable local analysis but failed to maintain the investigation across the full workflow. The article concludes that supervised investigative agency is the most appropriate current use, with senior reverse engineers retaining oversight and publication authority.

### Source excerpt

A real-world benchmark tests whether powerful AI models can keep an investigation trustworthy when new evidence invalidates their conclusions.

## Security incident disclosure -- July 2026

DevFeed: [Security incident disclosure -- July 2026](<https://devfeed.tech/articles/security-incident-disclosure-july-2026-7471.md>)

Original publisher: [Read original article](<https://huggingface.co/blog/security-incident-july-2026>)

Author: system

Published: 2026-07-16T00:00:00Z

Content type: article

Language: en

Sources: [Hugging Face - Blog](<https://devfeed.tech/sources/hugging-face-blog.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [data-processing](<https://devfeed.tech/topics/data-processing.md>), [AI Platform](<https://devfeed.tech/topics/ai-platform.md>), [datasets](<https://devfeed.tech/topics/datasets.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [incident](<https://devfeed.tech/tags/incident.md>), [llm](<https://devfeed.tech/tags/llm.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [tokens](<https://devfeed.tech/tags/tokens.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Hugging Face discloses a July 2026 security incident involving unauthorized access to limited internal datasets and service credentials. The intrusion began through code-execution paths in dataset processing, enabled lateral movement across internal clusters, and involved an autonomous agent framework executing numerous actions across short-lived sandboxes. Hugging Face reports that public models, datasets, Spaces, container images, and published packages showed no evidence of tampering, and describes remediation including vulnerability fixes, credential rotation, cluster rebuilding, stronger controls, and improved detection.

### Source excerpt

We're on a journey to advance and democratize artificial intelligence through open source and open science.

## ESET Threat Report H1 2026

DevFeed: [ESET Threat Report H1 2026](<https://devfeed.tech/articles/eset-threat-report-h1-2026-8365.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/>)

Author: Jiří Kropáč

Published: 2026-07-08T08:45:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [ESET research](<https://devfeed.tech/topics/eset-research.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Generative AI](<https://devfeed.tech/topics/generative-ai.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Android](<https://devfeed.tech/topics/android.md>), [ClickFix](<https://devfeed.tech/topics/clickfix.md>), [QR Code](<https://devfeed.tech/topics/qrcode.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [android](<https://devfeed.tech/tags/android.md>), [clickfix](<https://devfeed.tech/tags/clickfix.md>), [code](<https://devfeed.tech/tags/code.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [malware](<https://devfeed.tech/tags/malware.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [threat-report](<https://devfeed.tech/tags/threat-report.md>)

### AI overview

ESET's H1 2026 threat report describes attackers adapting established techniques across new platforms and behaviors. It highlights the expanding abuse of AI skills, PromptSpy Android malware using Google Gemini, the spread of ClickFix and QR-code phishing, and continued ransomware activity involving EDR killers.

### Source excerpt

A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.

## SpectrePaste: An AI-Assisted, Fileless PowerShell Malware Delivery System

DevFeed: [SpectrePaste: An AI-Assisted, Fileless PowerShell Malware Delivery System](<https://devfeed.tech/articles/spectrepaste-22546.md>)

Original publisher: [Read original article](<https://medium.com/walmartglobaltech/spectrepaste-b20bc2f6ded8?source=rss----905ea2b3d4d1---4>)

Author: Joshua Platt

Published: 2026-07-06T18:54:30Z

Content type: article

Language: en

Sources: [Walmart Global Tech](<https://devfeed.tech/sources/walmart-global-tech.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [PowerShell](<https://devfeed.tech/topics/powershell.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Caching](<https://devfeed.tech/topics/caching.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Routing (disambiguation)](<https://devfeed.tech/topics/routing.md>), [Polymorphism](<https://devfeed.tech/topics/polymorphism.md>), [Back end](<https://devfeed.tech/topics/backend.md>), [Spec Driven Development](<https://devfeed.tech/topics/spec-driven-development.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [artificial-intelligence](<https://devfeed.tech/tags/artificial-intelligence.md>), [backend](<https://devfeed.tech/tags/backend.md>), [c2](<https://devfeed.tech/tags/c2.md>), [cache](<https://devfeed.tech/tags/cache.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [detection-engineering](<https://devfeed.tech/tags/detection-engineering.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-analysis](<https://devfeed.tech/tags/malware-analysis.md>), [polymorphism](<https://devfeed.tech/tags/polymorphism.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [routing](<https://devfeed.tech/tags/routing.md>), [spec-driven-development](<https://devfeed.tech/tags/spec-driven-development.md>), [threat-intelligence](<https://devfeed.tech/tags/threat-intelligence.md>)

### AI overview

The article describes SpectrePaste, a previously undocumented fileless malware delivery system that threat actors used with AI as its primary orchestrator and developer. Its early architecture included automated AMSI-bypass generation, XOR-encrypted payloads, resilient command-and-control traffic handling, caching, request queuing, and administrative priority routing.

### Source excerpt

by Joshua Platt and Jason Reaves [TLP:CLEAR] Earlier this year, Google Threat Intelligence[1] reported threat actors are increasingly deploying novel, AI-enabled malware in active operations[2]. While investigating a recent OSINT article[3] on malware campaign activity reported as "DeepLoad", our threat intelligence team identified a separate, previously undocumented fileless delivery system we track as "SpectrePaste". The prior public reporting correctly suspected AI involvement in the "DeepLoad" delivery chain, but our analysis reveals a more conclusive and concerning reality. AI did not just play a supporting role. It acted as the primary orchestrator and developer behind the entire SpectrePaste system. Threat actors internally referred to the early system as "PasteFast Panel." In this initial iteration, the system was highly modular, structured, and designed specifically for resilience against high-volume bot traffic. One of the hallmarks of automated, AI-assisted development. The early architecture functioned as a centralized PowerShell payload delivery system with several notable features: Automated Evasion Generation: The paste builder module automatically prepended Anti-Malware Scan Interface (AMSI) bypass scripts to payloads upon creation, followed by XOR encryption using a custom obfuscator template. This ensured every payload served was dynamically packed. C2 Resilience & High-Load Handling: The most sophisticated feature of the early version was its custom cache manager queue system. The threat actors anticipated massive, simultaneous beaconing from compromised hosts. To prevent database exhaustion, the panel featured an automated threshold toggle. During traffic spikes, the system queued requests, cached the encrypted payloads in memory, and deduplicated IP addresses to ensure a single infected bot could not inadvertently DDoS the command server. Admin Priority Routing: Developer requirements explicitly prioritized operator access. Administrative routes

## Context Engineering | Compaction & Agent Memory for Automated Malware Analysis

DevFeed: [Context Engineering | Compaction & Agent Memory for Automated Malware Analysis](<https://devfeed.tech/articles/context-engineering-compaction-agent-memory-for-automated-malware-analysis-8312.md>)

Original publisher: [Read original article](<https://www.sentinelone.com/labs/context-engineering-compaction-agent-memory-for-automated-malware-analysis/>)

Author: Gabriel Bernadett-Shapiro

Published: 2026-07-02T13:00:02Z

Content type: article

Language: en

Sources: [SentinelLabs - We are hunters, reversers, exploit developers, and tinkerers shedding light on the world of malware, exploits, APTs, and cybercrime across all platforms.](<https://devfeed.tech/sources/sentinellabs-we-are-hunters-reversers-exploit-developers-and-tinkerers-shedding-light-on-the-world-of-malware-exploits-apts-and-cybercrime-across-all-platforms.md>)

Topics: [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>), [API](<https://devfeed.tech/topics/api.md>), [LangChain](<https://devfeed.tech/topics/langchain.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [agents](<https://devfeed.tech/tags/agents.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [api](<https://devfeed.tech/tags/api.md>), [code](<https://devfeed.tech/tags/code.md>), [coding](<https://devfeed.tech/tags/coding.md>), [data](<https://devfeed.tech/tags/data.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [langchain](<https://devfeed.tech/tags/langchain.md>), [llm](<https://devfeed.tech/tags/llm.md>), [malware](<https://devfeed.tech/tags/malware.md>), [model](<https://devfeed.tech/tags/model.md>), [models](<https://devfeed.tech/tags/models.md>), [openai](<https://devfeed.tech/tags/openai.md>), [security](<https://devfeed.tech/tags/security.md>), [systems](<https://devfeed.tech/tags/systems.md>), [tokens](<https://devfeed.tech/tags/tokens.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

SentinelLABS evaluates OpenAI's native compaction in the Responses API for automated malware analysis. The evaluation found an approximately 86% reduction in input tokens with no measurable change in aggregate task quality, suggesting that compaction can reduce cost and context noise in long-running security workflows.

### Source excerpt

Compaction cut input tokens 86% across long-running agent evals with no quality loss. Context discipline matters as much as model selection.

## ESET takes part in Operation Endgame to disrupt Amadey and Stealc

DevFeed: [ESET takes part in Operation Endgame to disrupt Amadey and Stealc](<https://devfeed.tech/articles/eset-takes-part-in-operation-endgame-to-disrupt-amadey-and-stealc-8364.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/>)

Author: Jakub Tomanek Tomáš Procházka

Published: 2026-06-24T12:35:24Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [ESET research](<https://devfeed.tech/topics/eset-research.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [C2](<https://devfeed.tech/topics/c2.md>), [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [data](<https://devfeed.tech/topics/data.md>), [Statistics](<https://devfeed.tech/topics/statistics.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [data](<https://devfeed.tech/tags/data.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [maas](<https://devfeed.tech/tags/maas.md>), [malware](<https://devfeed.tech/tags/malware.md>), [network](<https://devfeed.tech/tags/network.md>), [research](<https://devfeed.tech/tags/research.md>)

### AI overview

ESET Research describes its contribution to Operation Endgame, a coordinated global effort that disrupted the Amadey botnet and Stealc infostealer. The article covers infrastructure tracking, technical and statistical analysis, malware configuration data, command-and-control servers, encryption keys, campaign identifiers, and affiliate-level activity within the malware-as-a-service ecosystem.

### Source excerpt

ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights

[Next page](<https://devfeed.tech/topics/threat-research.md?cursor=WyIyMDI2LTA2LTI0VDEyOjM1OjI0KzAwOjAwIiwgIjEyNDM2YzgxLTAwOWMtNGI4NS04NGQ2LTRjNDcxY2M4MDk2NSJd>)