LIVE · cybersecurity feed
Live wire
Malware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on Host
aihigh

No-Filter 'Kriminal' AI Platform Raises Cybercrime Concerns

An AI platform, despite officially prohibiting illicit use, provides unrestricted tools for social engineering, offensive cybercrime, and OSINT scanning. Access to these powerful capabilities is granted to anyone willing to pay with cryptocurrency.

zeroday.news ·

A new AI platform, dubbed "Kriminal," has reportedly emerged, offering unrestricted tools that raise significant concerns about their potential misuse in cybercrime. While the platform officially states a prohibition against illicit activities, its functionalities are openly available to users who pay with cryptocurrency, effectively bypassing any meaningful restrictions.

The platform's reported capabilities span several critical areas relevant to offensive cyber operations. These include tools for social engineering, which could be leveraged to craft highly convincing phishing campaigns or manipulate individuals into divulging sensitive information. Additionally, it offers functionalities for broader offensive cybercrime activities, suggesting capabilities that extend beyond mere information gathering to potentially include direct attack vectors or exploit development assistance. Furthermore, "Kriminal" reportedly provides OSINT (Open Source Intelligence) scanning tools, which are invaluable for reconnaissance and target profiling, allowing malicious actors to gather extensive data on potential victims or organizations.

The mechanism of access—payment via cryptocurrency—is a common tactic employed by illicit services to maintain anonymity and evade traditional financial tracking. This payment model further complicates efforts to identify and interdict users engaged in malicious activities, as cryptocurrency transactions are inherently more difficult to trace back to real-world identities compared to conventional banking methods. The "no-filter" aspect implies a lack of content moderation or usage restrictions, meaning that prompts or requests for generating malicious content or instructions are likely fulfilled without intervention.

Products in this category, particularly those offering AI-driven assistance, can significantly lower the barrier to entry for individuals with limited technical skills to engage in sophisticated cyberattacks. By automating complex tasks like crafting persuasive social engineering lures or performing detailed reconnaissance, these platforms empower a broader range of actors to execute operations that would otherwise require specialized knowledge and significant effort. The likely scope of impact could therefore extend to an increase in the volume and sophistication of various cyberattacks, particularly those relying on human manipulation or extensive data gathering.

Typical mitigation guidance for issues stemming from such platforms often involves a multi-faceted approach. Organizations and individuals are advised to enhance their defenses against social engineering attacks through robust employee training, multi-factor authentication, and strict access controls. For OSINT-related threats, minimizing publicly available information and regularly auditing an organization's digital footprint can help reduce the attack surface. Furthermore, law enforcement and cybersecurity agencies typically focus on tracking cryptocurrency flows, monitoring dark web forums for platform advertisements, and collaborating internationally to disrupt the infrastructure supporting such illicit services.

The emergence of platforms like "Kriminal" underscores a growing trend where advanced technological capabilities, particularly in artificial intelligence, are being weaponized and made accessible to a wider audience. This development poses a significant challenge to cybersecurity, as it democratizes access to powerful tools that can be easily repurposed for malicious intent. It highlights the ongoing cat-and-mouse game between security researchers and malicious actors, where advancements in legitimate technology are quickly mirrored by their illicit counterparts, necessitating continuous vigilance and adaptation in defense strategies.

aicybercrimesocial engineeringosintsecurity concerns
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

If you're not using AI to attack your own systems, your adversaries will

Agents are also the new attack surface - cue defenders' existential angst

ransomware

Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Windows 11’s strongest security defenses can be bypassed without a screwdriver Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assume

breach

Welcoming the Sri Lankan Government to Have I Been Pwned

Today, we welcome the 48th government onboarded to Have I Been Pwned’s free gov service: Sri Lanka. Sri Lanka CERT now has access to monitor Sri Lankan government domains against the data in HIBP, helping identify exposed government accounts and respond when they appear in new data breaches.

security

Postal Service moves to finalize mail ballot regs before SCOTUS ruling

The rules have already been rejected by multiple state courts, but the Trump administration said it’s preparing in case of a favorable Supreme Court decision. The post Postal Service moves to finalize mail ballot regs before SCOTUS ruling appeared first on CyberScoop.

vulnerability

ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries

ToxicPanda 2.0 targets 349 financial apps and abuses Android Wireless Debugging to gain deeper device access and steal banking credentials. ToxicPanda used to be a Europe-focused nuisance targeting a manageable list of banks. That version is gone. Zimperium’s zLabs team just documented ToxicPanda 2.0, and the numbers alone tell the story: 349 targeted financial institutions […]

privacy

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

TikTok has agreed to a $400 million settlement with the U.S. Department of Justice to resolve a lawsuit alleging violations of child privacy laws. The lawsuit, filed in 2024, accused the company of improperly collecting data from users under 13 and failing to comply with parental requests to delete accounts. The settlement includes an immediate payment of $300 million and an additional $100 million contingent on the dissolution of a prior consent decree related to Musical.ly.