LIVE · cybersecurity feed
Live wire
Malware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on Host
ai

If you're not using AI to attack your own systems, your adversaries will

Agents are also the new attack surface - cue defenders' existential angst

zeroday.news ·

The increasing use of AI agents in cyberattacks presents a new and rapidly evolving threat landscape, compelling organizations to adopt AI-powered defenses, including automated red teaming. These autonomous agents excel at identifying vulnerabilities and executing exploit chains, operating continuously without human limitations. This capability is proving invaluable to both financially motivated criminals and state-sponsored actors.

Matt Hartman, former acting head of cyber at the US Cybersecurity and Infrastructure Security Agency (CISA), emphasized that as AI transitions from content generation to taking actions, it will inevitably gain access to sensitive systems and data. He noted that organizations must begin treating every AI agent as a privileged identity, highlighting the significant risks associated with agentic AI and machine identities.

Hartman also pointed to a rise in AI-enabled or AI-amplified identity and social engineering attacks, which produce highly personalized phishing attempts, sophisticated impersonations, and automated reconnaissance. This makes traditional indicators of trust increasingly unreliable. For defenders, this necessitates a continued focus on robust identity management, phishing-resistant authentication, behavioral signals, and zero-trust principles.

The speed at which AI agents can operate is a critical factor. Adversaries can leverage AI to discover and exploit vulnerabilities in seconds, a process that previously took days for human teams. This accelerated threat environment makes traditional, periodic penetration testing insufficient.

Kevin Mandia, founder of Mandiant, launched a new company called Armadin in March, securing $190 million in seed and Series A funding. Armadin focuses on building and training autonomous attacker swarms—thousands of AI agents designed to operate 24/7 within an organization's infrastructure to simulate real-world attacks.

Ahead of Black Hat, Armadin, in collaboration with Tenex.ai, an agentic security operations provider, conducted what they described as the "largest controlled live AI cyberattack on record" for a major global institution. Over three days, Armadin's swarm executed 17 million offensive actions, uncovered 38 validated attack paths, and generated 238 security findings. Simultaneously, Tenex.ai's agentic platform triaged 100% of 101,169 alerts and reconstructed the entire attack from 231 billion raw events. This exercise, if performed by a five-person analyst team, would have required approximately 2,400 hours, or four months.

Evan Peña, Armadin's co-founder and Chief Offensive Security Officer, previously led Mandiant's global red-team. He noted that human-led security assessments, typically lasting a few weeks or a month, are becoming archaic in the age of AI, which offers significant scaling capabilities.

Peña explained that AI agents provide three key advantages: more time, as they operate continuously; enhanced expertise, through pre-training in areas like coding, source-code review, application security, and network configuration, supplemented by human post-training; and expanded coverage. While human teams might only cover a fraction of an organization's attack surface, AI agents can cover tens of thousands of external systems in hours.

Armadin claims its AI agents have successfully breached every customer environment they have tested, identifying over 50 high-impact zero-days that allowed for remote code execution rather than just website defacement. This underscores the necessity for organizations to proactively use AI agents to attack their own systems, a practice known as agentic red teaming, to stay ahead of adversaries. As former NSA cyber boss Rob Joyce stated, organizations will be red-teamed whether they pay for it or not, and the only difference is who receives the results.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

Hackers infect Android car head units with proxy botnet malware

A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [...]

security

Named Pipes Under Attack: Securing Windows Interprocess Communication

Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict input validation, and narrowly scoped privileges can help secure named-pipe communication. [...]

security

Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments

Plus: Apple sends out an “unprecedented” number of spyware warnings, Ukraine hits a Russian ecommerce giant with cyber and drone attacks, and more.

malwarehigh

Malware Hijacks Android Car Head Units

Researchers have identified new Android malware that hijacks car head units by exploiting their official update mechanisms. The malware installs proxy software, turning vehicles into nodes for the BADBOX botnet, primarily for ad fraud and to provide anonymized internet connections. This marks the first documented instance of malware specifically targeting car head units through their native update channels.

malware

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware. The post Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight appeared first on SecurityWeek.

nasacritical

Critical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command Execution

A critical vulnerability has been discovered in NASA/JPL's open-source AIT-GUI software, which is used to control spacecraft instruments. The flaw allows unauthenticated attackers to execute arbitrary commands, run server-side scripts, and manipulate command sequences by exploiting a lack of authentication, session checks, and CSRF protection. Researchers confirmed the issue, which has a CVSS score of 9.4, and a fix is available in version 2.5.2.