Active Vulnerability Exploitation
Articles on active exploitation of newly disclosed vulnerabilities, including zero-day attacks, memory disclosure bugs, and rapid weaponization of published CVEs by threat actors.
How a Benign GitHub Repo Can Hijack Your Machine Through AI Coding Agents
Mozilla's 0DIN researchers demonstrated a supply-chain attack where a clean-looking GitHub repository tricks AI coding agents like Claude Code into executing a reverse shell — with no malicious code ever committed to the repo, only a DNS TXT record controlling the payload at runtime.
How a Three-Word Prompt Exposed the Flaws in AI Governance and Export Controls
When the Trump administration banned Anthropic's Fable 5 and Mythos 5 models over a so-called jailbreak, the reality was far simpler — and far more embarrassing. Security researcher Katie Moussouris walked through the actual prompt, her Wassenaar Arrangement credentials, and why this episode reveals deep cracks in how we govern AI.
Jailbroken Google Gemini Automated 90% of Russian Cybercriminal's Credential and Crypto-Stealing Operation
A TrendAI investigation reveals how a solo Russian-speaking attacker, known as "bandcampro," used a jailbroken Google Gemini to autonomously conduct credential theft and cryptocurrency fraud — including spinning up a new command-and-control server in six minutes and executing 59 unprompted behaviors during infrastructure migration.
Forg365: How AI Is Turning Microsoft 365 Phishing Into a Self-Sustaining Threat
Forg365 isn't just another phishing tool—it's a platform that automates credential theft, maintains persistent access, and adapts to defenses using AI. Here's how it works, and why it's scarier than anything we've seen before.
Artificial Intelligence AI Cybersecurity: How Ransomware Groups Are Weaponizing Healthcare Hubs
A deep dive into the 35% surge in cyberattacks on healthcare service providers, analyzing real-world disruptions from Mississippi to Germany—and how AI-native security models can shut down supply chain ransomware loops.
U-Boot Bootloader Under Fire: Six Critical Vulnerabilities Could Let Attackers In Through Your Firmware
Six newly disclosed vulnerabilities in the U-Boot bootloader could let attackers execute code before your operating system even starts — opening the door to persistent firmware attacks on embedded devices, BMCs, industrial systems, and more.
API-Driven ClickFix and the Evolution of Artificial Intelligence Cybersecurity Threats
As ClickFix transitions to an API-driven, on-demand service, threat actors use freshly scrambled payloads and native Windows utilities to bypass traditional AV and EDR solutions, making memory and YARA analysis critical for defenders.
OFAC Sanctions Ransomware Enablers as AI Cybersecurity Threats Escalate
The Treasury Department's OFAC sanctioned First VPN Service (1VPNS), its Belarusian administrator Dmytro Rashevskyi, and cryptor seller Yegeniy Silayev for supplying infrastructure and malware-evasion tools that enabled ransomware attacks causing billions in losses to U.S. critical infrastructure — a direct response to the escalating artificial intelligence cybersecurity threats landscape.
Agent-Safe: Rethinking Website Security in the Age of WebMCP
Exposing tools to AI agents through WebMCP creates a new attack surface where your own user-generated content could compromise agents. Here is how developers must secure their tools.
The AUR Rootkit Crisis: How 400+ Linux Packages Became a Credential-Theft Pipeline
Analysis of a supply chain attack targeting the Arch User Repository (AUR) where over 400 packages were compromised to distribute a Linux rootkit and credential-stealing infostealer malware, exploiting orphaned packages and modified PKGBUILD scripts to deliver eBPF-based rootkit capabilities and targeted credential theft from developer workstations.
Critical XSS Flaw Prompts Urgent Zimbra Classic Web Client Update
Zimbra has released a critical security update for its Classic Web Client to address a stored XSS vulnerability that could lead to account compromise.
How Google Catches AI Spam Clusters Before They Flood Your Search
Google’s Scalable Cluster Termination System uses infrastructure signals and generative artifacts to detect coordinated AI spam campaigns — shifting from content-level filters to cluster-level termination.