Highly sophisticated malware has been identified within npm packages, demonstrating advanced capabilities to evade established security defences.
Malicious AI agents using open-source frameworks have been deployed to target hundreds of online retailers, stealing 600,000 credit card records.
Threat actors have compromised MemTensor packages on npm and PyPI to deploy the sckit credential stealer, targeting sensitive cloud and developer secrets.
The newly discovered x47.c botnet offers specialised denial of wallet attacks, using stolen API keys to drain paid credits from AI providers like OpenAI and xAI.
Cisco Talos has identified CLOSEDQUORUM, a new malware architecture that uses a panel of large language models to automate command-and-control decisions.