SentinelLabs discovered a Rust-based macOS backdoor attributed to North Korea that embeds 38 fake system messages designed to trick AI-assisted malware triage into aborting or refusing analysis.
Profiling adversary groups targeting AI systems and leveraging AI in their operations.
SentinelLabs discovered a Rust-based macOS backdoor attributed to North Korea that embeds 38 fake system messages designed to trick AI-assisted malware triage into aborting or refusing analysis.
GreyNoise honeypots captured 91,403 attack sessions targeting enterprise LLM endpoints across two distinct campaigns between October 2025 and January 2026. One campaign fingerprinted 73+ model endpoints across all major AI providers. The other exploited SSRF vulnerabilities in Ollama and Twilio integrations.
APT28's PROMPTSTEAL malware queries an LLM via the Hugging Face API to dynamically generate Windows recon commands, marking the first confirmed use of LLM-driven malware in live operations against real targets.
Microsoft attributes the Mastra AI npm supply chain attack to Sapphire Sleet, a North Korean state actor: 144 packages backdoored via a hijacked contributor account, targeting LLM API keys, cloud credentials, and cryptocurrency wallets.
Sysdig caught a threat actor using a misconfigured Ollama instance as the reasoning engine for an automated offensive pentesting framework — a significant escalation from credential theft to weaponised AI infrastructure.