LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
malware

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, sponsored search results, and ClickFix-style lures. [...]

zeroday.news ·

Threat actors are increasingly exploiting trusted artificial intelligence (AI) platforms by weaponizing their legitimate features to deliver malware and steal sensitive data, according to observations from the Huntress Security Operations Center (SOC). Over the past nine months, Huntress has tracked multiple campaigns that leverage shareable AI content, public mini-applications, and sponsored search placements to target users. These attacks do not compromise the AI platforms themselves but rather abuse the trust users place in familiar brands and legitimate domains.

One observed tactic involves the abuse of Claude Artifacts, which are content snippets generated by Anthropic's Claude AI and displayed in a chat preview pane. These artifacts can be published and shared via public links on the claude.ai domain. In July, a campaign dubbed "FakeAgent" affected over 29 organizations. Attackers created a convincing fake Claude Desktop download page hosted as a malicious Claude Artifact. Victims searching Bing for a Claude desktop application were directed to this fake page, where a seemingly legitimate download link redirected them to an external domain that delivered the SectopRAT malware. Huntress reported the artifact, and Anthropic removed it by July 22, though incidents linked to the same redirect domain persisted into August.

Another incident involved a weaponized claude.ai/share link. A victim searching Google for "Claude on Mac" clicked a sponsored search result that led to a shared Claude conversation. This conversation, posing as an Apple Support install guide, instructed the victim to paste a curl command into their Terminal. This action initiated a six-stage attack chain that deployed the MacSync stealer, which harvested cookies, credentials, keychain secrets, Telegram sessions, and SSH and cloud keys. The page's presence on Anthropic's legitimate domain, claude.ai, lent it an air of authenticity, lacking typical red flags like lookalike URLs or certificate warnings.

A third pattern of attack targets AI-generated troubleshooting advice itself. In December, attackers used SEO poisoning to push high-ranking ChatGPT and Grok conversations to the top of Google search results for queries like "clear disk space on macOS." These conversations, hosted on the legitimate chatgpt.com and grok.com domains, provided "ClickFix-style" instructions rather than actual solutions. Victims who trusted the advice and executed the suggested Terminal commands unknowingly deployed the AMOS stealer.

These campaigns often operate for only hours or days before the malicious content is removed by the platform providers, but this short window is sufficient to trick victims. The core issue is not a breach of the AI platform's security but rather the exploitation of user trust in the platform's branding and domain.

To mitigate these risks, security professionals recommend treating clipboard-driven execution and AI-assisted troubleshooting as potential security threats. Organizations should restrict script execution from the clipboard, enforce application allow-listing, and monitor for new scheduled tasks and changes to antivirus exclusions. User training is also crucial to help individuals identify "ClickFix-style" lures. Promptly reporting suspicious AI-hosted content to the respective platform vendors can help shrink the window of opportunity for attackers.

malwarepatchai
ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]