AI Security Threats and Critical Infrastructure Risks Identified
Share
The cybersecurity landscape is witnessing a significant shift as threat actors increasingly target artificial intelligence (AI) ecosystems and critical infrastructure. Recent disclosures reveal a surge in malware designed to harvest AI API keys, hijack browser-based AI assistants, and leverage large language models (LLMs) to automate malicious decision-making.
New Malware Targets AI Assistants and API Keys
Researchers at the endpoint security firm Forever have disclosed BragJack, a set of flaws that allow malicious extensions to take control of built-in AI assistants in browsers including Chrome, Edge, and Opera Neon. By injecting scripts into web pages that the assistant is programmed to trust, an installed extension can send unauthorised prompts to the AI. Depending on the browser, this can grant attackers access to local files, emails, and even the user’s camera or microphone.
In a more sophisticated evolution of command-and-control (C2) techniques, Cisco Talos has documented CLOSEDQUORUM. This Go-based Windows implant is one of the first documented cases where an attacker hands C2 decisions to commercial LLMs. The malware uses models such as Gemini, Mistral, Qwen, and DeepSeek to vote on whether to execute actions like stealing credentials or establishing persistence.
Additionally, the CARBONATO botnet has been identified by ThreatDown as a significant threat to cloud environments. The botnet compromises unauthenticated Docker daemons to install the Hermes Agent, specifically prioritising the theft of AI API keys above other forms of data.
Critical Infrastructure and Water Sector Exposed
While AI-centric threats grow, traditional infrastructure remains highly vulnerable. An analysis by SpyCloud found that credentials for remote-access and operational technology (OT) systems at hundreds of US water and wastewater utilities have been exposed through infostealer logs. In one instance, a single compromised device at a technology provider captured logins for approximately 167 utility metering portals.
In the industrial sector, a high-severity flaw in the TDengine time-series database, tracked as CVE-2026-42542, threatens industrial telemetry uptime. An unauthenticated attacker can potentially crash servers used in energy and IoT environments by sending a single malformed packet to the system’s RPC port.
Ransomware Feud and Faster Patching Cycles
The ransomware landscape is also seeing unconventional conflicts, with the Clop extortion group facing a targeted attack from the ShinyHunters group. ShinyHunters has reportedly defaced Clop’s Tor leak site and claimed to have stolen server logs and private keys. The attackers have demanded an eight-figure payment and threatened to expose companies that previously paid Clop during its Oracle E-Business Suite campaign.
To address the rising volume of vulnerabilities, Canonical is overhauling its Ubuntu kernel update schedule. The company is replacing its current cycle with a single two-week cycle to ensure more frequent releases. Canonical also aims to provide security workarounds or hardening guidance within 24 to 48 hours of a vulnerability’s public disclosure.




Leave a Reply