ThreatDown researchers found that Kriminal.ai, a clearnet cybercrime storefront selling 'uncensored' AI access, isn't running its own model at all: it's a jailbreak prompt layered over rented Grok and Claude capacity.
ThreatDown researchers found that Kriminal.ai, a clearnet cybercrime storefront selling 'uncensored' AI access, isn't running its own model at all: it's a jailbreak prompt layered over rented Grok and Claude capacity.
CrowdStrike's 2026 Threat Hunting Report finds that 88% of vulnerabilities with a public PoC are exploited within 48 hours, AI frameworks have become supply chain targets, and detection leads are 2.5x noisier as AI agent activity becomes indistinguishable from attacker behaviour.
Sysdig researchers have documented a threat actor weaponising misconfigured Ollama model servers as the reasoning engine for an autonomous multi-stage penetration testing framework called VAPT, marking a significant shift in how stolen AI compute is being used.
Microsoft Threat Intelligence documents a surge in malvertising campaigns using fake AI tool brands as lures, with mass endpoint compromise observed within hours of campaign launch. Fake products including "Awesome AI Windows Plugin" and "Flux Pro AI" are being used to deliver infostealer payloads at scale.
GreyNoise honeypots captured 91,403 attack sessions targeting enterprise LLM endpoints across two distinct campaigns between October 2025 and January 2026. One campaign fingerprinted 73+ model endpoints across all major AI providers. The other exploited SSRF vulnerabilities in Ollama and Twilio integrations.