Download Privacy Needle App

Type to search

Cybersecurity

AI Security Threats and Critical Infrastructure Risks Identified

Share
AI Security Threats and Critical Infrastructure Risks Identified

The cybersecurity landscape is witnessing a significant shift as threat actors increasingly target artificial intelligence (AI) ecosystems and critical infrastructure. Recent disclosures reveal a surge in malware designed to harvest AI API keys, hijack browser-based AI assistants, and leverage large language models (LLMs) to automate malicious decision-making.

New Malware Targets AI Assistants and API Keys

Researchers at the endpoint security firm Forever have disclosed BragJack, a set of flaws that allow malicious extensions to take control of built-in AI assistants in browsers including Chrome, Edge, and Opera Neon. By injecting scripts into web pages that the assistant is programmed to trust, an installed extension can send unauthorised prompts to the AI. Depending on the browser, this can grant attackers access to local files, emails, and even the user’s camera or microphone.

In a more sophisticated evolution of command-and-control (C2) techniques, Cisco Talos has documented CLOSEDQUORUM. This Go-based Windows implant is one of the first documented cases where an attacker hands C2 decisions to commercial LLMs. The malware uses models such as Gemini, Mistral, Qwen, and DeepSeek to vote on whether to execute actions like stealing credentials or establishing persistence.

Additionally, the CARBONATO botnet has been identified by ThreatDown as a significant threat to cloud environments. The botnet compromises unauthenticated Docker daemons to install the Hermes Agent, specifically prioritising the theft of AI API keys above other forms of data.

Critical Infrastructure and Water Sector Exposed

While AI-centric threats grow, traditional infrastructure remains highly vulnerable. An analysis by SpyCloud found that credentials for remote-access and operational technology (OT) systems at hundreds of US water and wastewater utilities have been exposed through infostealer logs. In one instance, a single compromised device at a technology provider captured logins for approximately 167 utility metering portals.

In the industrial sector, a high-severity flaw in the TDengine time-series database, tracked as CVE-2026-42542, threatens industrial telemetry uptime. An unauthenticated attacker can potentially crash servers used in energy and IoT environments by sending a single malformed packet to the system’s RPC port.

Ransomware Feud and Faster Patching Cycles

The ransomware landscape is also seeing unconventional conflicts, with the Clop extortion group facing a targeted attack from the ShinyHunters group. ShinyHunters has reportedly defaced Clop’s Tor leak site and claimed to have stolen server logs and private keys. The attackers have demanded an eight-figure payment and threatened to expose companies that previously paid Clop during its Oracle E-Business Suite campaign.

To address the rising volume of vulnerabilities, Canonical is overhauling its Ubuntu kernel update schedule. The company is replacing its current cycle with a single two-week cycle to ensure more frequent releases. Canonical also aims to provide security workarounds or hardening guidance within 24 to 48 hours of a vulnerability’s public disclosure.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.