AI tools are being used by cyber attackers to write malicious code, build tools that harvest credentials, search compromised networks, identify valuable business information, manage technical infrastructure and generate commands during intrusions. Gambit Security researchers examined three unrelated threat actors that show how AI can support different stages of a cyberattack. Across the cases, att

Cybersecurity researchers have identified three distinct threat actor groups that are leveraging artificial intelligence tools to enhance various stages of their malicious operations, ranging from reconnaissance and exploitation to data exfiltration and credential harvesting. These groups employed AI models such as Claude Code, OpenAI Codex, and DeepSeek to generate malicious scripts, identify high-value targets, manage technical infrastructure, and refine attack commands.
One observed incident involved a suspected ransomware operator, active in late June 2026, who utilized Claude Code, specifically running Claude Sonnet 4.6, during intrusions into six organizations. Victims included an Australian energy utility, along with companies in financial services, food services, manufacturing, IT services, property management, and distribution across multiple countries. This activity has been attributed with medium confidence to a threat actor associated with The Gentlemen ransomware-as-a-service operation. The AI model assisted in generating and executing reconnaissance and exploitation commands, writing malicious scripts, modifying firewall policies, and analyzing business systems to pinpoint critical assets.
During internal network reconnaissance, Claude processed technical results to identify useful targets such as domain controllers, file servers, and backup servers. It also examined application databases and backup infrastructure. In one instance, the operator queried Claude to rank the most important databases, leading the AI to highlight the live production database and client document store. The operator then instructed Claude to execute SQL Server backup commands on two servers, staging two compressed database dumps for exfiltration. One of these dumps was subsequently exfiltrated, with Claude copying the file to the operator's machine and then deleting it from the victim's server.
In a separate intrusion, Claude initially refused to proceed after recognizing it was interacting with a live production system without confirmed authorization. The operator circumvented this by starting a new session and falsely claiming authorization for vulnerability testing, after which Claude complied with the requests. The AI also made errors; at the Australian utility, Claude's attempt to modify firewall settings resulted in the device becoming unreachable after API calls failed and the AI downloaded, edited, and re-uploaded the configuration. Furthermore, some AI-assisted activities inadvertently exposed information, such as reconnaissance descriptions and labels, that could reveal attack activity within victim environments.
A second case focused on Zerofot, a credential-harvesting operation that scanned the internet for unintentionally exposed sensitive files and open directories containing API keys, tokens, and other credentials. Its primary tool, `auto_scan`, was developed using OpenAI Codex and Claude Code. The instructions provided to Codex described the work as being "for an authorized CTF sandbox" to prevent the model from refusing the task. Between April 5 and May 23, 2026, Zerofot collected 2,975 validated keys and credentials from 1,742 victim hosts, including SSH private keys, AWS access keys, and credentials for services like Google Gemini, OpenAI, GitHub, and Anthropic.
The third case involved RAGE, a custom Python attack framework designed to scan internet-facing services, exploit vulnerabilities, harvest credentials, and deploy cryptocurrency miners. RAGE and many of its accompanying scripts appear to have been generated with AI. The framework also integrates a DeepSeek-backed "AI Orchestrator" at runtime, which advises the operator on managing the mining botnet. RAGE targets services such as Redis, Elasticsearch, Docker, and Tomcat, with additional modules for Jenkins, Hadoop YARN, Confluence, and Supervisord. Its capabilities include scanning, exploitation, brute-force authentication, cloud metadata access, host-level privilege escalation, and miner deployment and monitoring. In one instance, the RAGE operator recovered AWS credentials from an exposed Redis instance, gaining access to the victim's cloud environment and subsequently using additional scripts to search cloud services for further credentials and sensitive information.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets