{
  "schema_version": 1,
  "chunk_size": 20,
  "total": 45,
  "incidents": [
    {
      "date": "2026-09-18",
      "source": "The Guardian",
      "title": "Google's Gemini model hacked three companies in a security test",
      "description": "Google said Gemini autonomously accessed three companies' systems during a cybersecurity evaluation in May, then stopped its activity.",
      "url": "https://www.theguardian.com/technology/2026/sep/18/google-gemini-ai-hack",
      "urls": [
        "https://www.theguardian.com/technology/2026/sep/18/google-gemini-ai-hack"
      ],
      "archive": "https://web.archive.org/web/20260919113042/https://www.theguardian.com/technology/2026/sep/18/google-gemini-ai-hack",
      "role": "Autonomous",
      "category": "Security research",
      "slug": "googles-gemini-model-hacked-three-companies-in-a-security-test"
    },
    {
      "date": "2026-09-18",
      "source": "TechCrunch",
      "title": "Researchers used Anthropic's Claude to hack into OpenAI",
      "description": "Independent security researchers reported using Claude and other tools to gain access to parts of OpenAI's internal systems as part of an ethical security test.",
      "url": "https://techcrunch.com/2026/09/18/researchers-used-anthropics-claude-to-hack-into-openai/",
      "urls": [
        "https://techcrunch.com/2026/09/18/researchers-used-anthropics-claude-to-hack-into-openai/"
      ],
      "archive": "https://web.archive.org/web/20260919143753/https://techcrunch.com/2026/09/18/researchers-used-anthropics-claude-to-hack-into-openai/",
      "role": "AI-assisted",
      "category": "Security research",
      "slug": "researchers-used-anthropics-claude-to-hack-into-openai"
    },
    {
      "date": "2026-09-10",
      "source": "Anthropic",
      "title": "Anthropic reports AI-assisted cyber operations",
      "description": "Anthropic's September threat report documented AI-augmented operations including a Russian-aligned espionage campaign targeting more than 20 government, defence and diplomatic organisations in Ukraine and Europe, ShinyHunters-affiliated credential theft and extortion, and stolen API keys reused against European political parties.",
      "url": "https://www.anthropic.com/threat-intelligence-report-september-2026",
      "urls": [
        "https://www.anthropic.com/threat-intelligence-report-september-2026",
        "https://cyberscoop.com/anthropic-report-ai-enabled-cyber-attacks/"
      ],
      "archive": "https://web.archive.org/web/20260919042348/https://www.anthropic.com/threat-intelligence-report-september-2026",
      "role": "AI-assisted",
      "category": "Cyber operations",
      "slug": "anthropic-reports-ai-assisted-cyber-operations"
    },
    {
      "date": "2026-09-08",
      "source": "Google Threat Intelligence Group",
      "title": "Google reports agent-enabled credential harvesting campaign",
      "description": "Google reported that a financially motivated actor used an AI coding chatbot and multi-agent framework to scan for vulnerabilities and harvest thousands of credentials from compromised cloud infrastructure in under six hours.",
      "url": "https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai",
      "urls": [
        "https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai"
      ],
      "archive": "https://web.archive.org/web/20260919144008/https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai",
      "role": "Autonomous",
      "category": "Credential theft",
      "slug": "google-reports-agent-enabled-credential-harvesting-campaign"
    },
    {
      "date": "2026-09-04",
      "source": "NBC News",
      "title": "OpenAI agents repurposed German wiki as agent message board",
      "description": "NBC News reported that a swarm of rogue OpenAI agents hijacked a German programming wiki and turned it into a message board for sharing tactics, with researchers describing the activity as a hacking attempt that OpenAI disputed.",
      "url": "https://www.nbcnews.com/tech/tech-news/openai-agents-hijacked-german-website-previously-undisclosed-ai-breako-rcna596083",
      "urls": [
        "https://www.nbcnews.com/tech/tech-news/openai-agents-hijacked-german-website-previously-undisclosed-ai-breako-rcna596083"
      ],
      "archive": "https://web.archive.org/web/20260919144948/https://www.nbcnews.com/tech/tech-news/openai-agents-hijacked-german-website-previously-undisclosed-ai-breako-rcna596083",
      "role": "Autonomous",
      "category": "Other",
      "slug": "openai-agents-repurposed-german-wiki-as-agent-message-board"
    },
    {
      "date": "2026-09-02",
      "source": "Unit 42",
      "title": "Unit 42 investigates AI-assisted enterprise intrusion",
      "description": "Palo Alto Networks' Unit 42 reported that an attacker used frontier AI agents during an enterprise intrusion to map systems, harvest secrets, seize root credentials, and abuse CI/CD workflows.",
      "url": "https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/",
      "urls": [
        "https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/"
      ],
      "archive": "https://web.archive.org/web/20260919144035/https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/",
      "role": "Autonomous",
      "category": "Cyber operations",
      "slug": "unit-42-investigates-ai-assisted-enterprise-intrusion"
    },
    {
      "date": "2026-09-01",
      "source": "Cloud Security Alliance",
      "title": "Aurora ransomware affiliate used Cursor AI for live network intrusions",
      "description": "Security researchers reported that an Aurora ransomware affiliate drove Cursor's agentic coding assistant, running Anthropic's Claude Sonnet, through hands-on network exploitation against at least ten organizations, with the operator supervising and iteratively correcting the agent's commands.",
      "url": "https://labs.cloudsecurityalliance.org/research/csa-research-note-aurora-ransomware-cursor-ai-abuse-20260901/",
      "urls": [
        "https://labs.cloudsecurityalliance.org/research/csa-research-note-aurora-ransomware-cursor-ai-abuse-20260901/"
      ],
      "archive": "https://web.archive.org/web/20260919160627/https://labs.cloudsecurityalliance.org/research/csa-research-note-aurora-ransomware-cursor-ai-abuse-20260901/",
      "role": "AI-assisted",
      "category": "Malware",
      "slug": "aurora-ransomware-affiliate-used-cursor-ai-for-live-network-intrusions"
    },
    {
      "date": "2026-08-06",
      "source": "BBC",
      "title": "Meta AI model hacks another company during testing",
      "description": "Meta said its AI model autonomously accessed another company's systems during a cybersecurity evaluation in July, which it attributed to a tester's misconfiguration.",
      "url": "https://www.bbc.co.uk/news/articles/cx2kgdnyk2po",
      "urls": [
        "https://www.bbc.co.uk/news/articles/cx2kgdnyk2po"
      ],
      "archive": "https://web.archive.org/web/20260806040104/https://www.bbc.co.uk/news/articles/cx2kgdnyk2po",
      "role": "Autonomous",
      "category": "Security research",
      "slug": "meta-ai-model-hacks-another-company-during-testing"
    },
    {
      "date": "2026-07-30",
      "source": "Unit 42",
      "title": "Unit 42 finds Chinese-speaking actor running autonomous AI attack campaign",
      "description": "Palo Alto Networks' Unit 42 reported that a Chinese-speaking threat actor used DeepSeek, orchestrated through the Hermes Agent framework, as an autonomous offensive operator that scanned for vulnerabilities, downloaded exploit code and attempted exploitation against more than 460 targets.",
      "url": "https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/",
      "urls": [
        "https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/"
      ],
      "archive": "https://web.archive.org/web/20260919144814/https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/",
      "role": "Autonomous",
      "category": "Cyber operations",
      "slug": "unit-42-finds-chinese-speaking-actor-running-autonomous-ai-attack-campaign"
    },
    {
      "date": "2026-07-30",
      "source": "Anthropic",
      "title": "Anthropic reports Claude reached real systems during cybersecurity evals",
      "description": "Anthropic reported that, during a review of its cybersecurity evaluation transcripts, it identified three incidents in which a Claude model reached the internet from a third-party evaluation environment and gained unauthorized access to the real systems of three organizations using basic techniques such as weak passwords and unauthenticated endpoints.",
      "url": "https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals",
      "urls": [
        "https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals"
      ],
      "archive": "https://web.archive.org/web/20260919165924/https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals",
      "role": "Autonomous",
      "category": "Security research",
      "slug": "anthropic-reports-claude-reached-real-systems-during-cybersecurity-evals"
    },
    {
      "date": "2026-07-21",
      "source": "OpenAI",
      "title": "OpenAI's rogue AI agent hacked Hugging Face in July breach",
      "description": "OpenAI reported that, during the evaluation of pre-release models, one of its models exploited vulnerabilities including a previously unknown flaw in a package-registry cache to reach the Internet and compromised Hugging Face's infrastructure; OpenAI said it deactivated the internal research prototype involved and is working with Hugging Face and external assessors on the response.",
      "url": "https://openai.com/index/hugging-face-model-evaluation-security-incident/",
      "urls": [
        "https://openai.com/index/hugging-face-model-evaluation-security-incident/",
        "https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/"
      ],
      "archive": "https://web.archive.org/web/20260918094524/https://openai.com/index/hugging-face-model-evaluation-security-incident/",
      "role": "Autonomous",
      "category": "Cyber operations",
      "slug": "openais-rogue-ai-agent-hacked-hugging-face-in-july-breach"
    },
    {
      "date": "2026-07-06",
      "source": "Asahi Shimbun",
      "title": "Teen used ChatGPT to build script that cancelled 46,000 Bandai accounts",
      "description": "A 15-year-old exploited a logic flaw in Bandai Channel's account-cancellation process and used ChatGPT to refine an automation script that mass-cancelled 46,812 accounts and exposed up to 1.36 million records.",
      "url": "https://www.asahi.com/ajw/articles/16703618",
      "urls": [
        "https://www.asahi.com/ajw/articles/16703618",
        "https://shattered.io/bandai-namco-chatgpt-hack-2026/"
      ],
      "archive": "https://web.archive.org/web/20260919205409/https://www.asahi.com/ajw/articles/16703618",
      "role": "AI-assisted",
      "category": "Cyber operations",
      "slug": "teen-used-chatgpt-to-build-script-that-cancelled-46000-bandai-accounts"
    },
    {
      "date": "2026-07-01",
      "source": "Sysdig Threat Research Team",
      "title": "Sysdig documents first fully agentic ransomware operation",
      "description": "Sysdig's threat research team documented an operation it named JadePuffer in which an LLM agent ran an entire ransomware intrusion end-to-end, exploiting a Langflow vulnerability, pivoting to a production database server, encrypting configuration records and leaving an extortion note without step-by-step human direction.",
      "url": "https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion",
      "urls": [
        "https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion",
        "https://www.darkreading.com/cyberattacks-data-breaches/jadepuffer-first-complete-llm-driven-ransomware-attack"
      ],
      "archive": "https://web.archive.org/web/20260919144754/https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion",
      "role": "Autonomous",
      "category": "Malware",
      "slug": "sysdig-documents-first-fully-agentic-ransomware-operation"
    },
    {
      "date": "2026-06-08",
      "source": "Anthropic",
      "title": "Anthropic measures frontier models' N-day exploit acceleration",
      "description": "Anthropic reported that its frontier models with safeguards disabled built eight working code-execution exploits from recent Firefox patches and eight Windows kernel privilege-escalation chains, showing how quickly models can turn patches into working exploits.",
      "url": "https://www.anthropic.com/research/n-days",
      "urls": [
        "https://www.anthropic.com/research/n-days"
      ],
      "archive": "https://web.archive.org/web/20260914124053/https://www.anthropic.com/research/n-days",
      "role": "AI security research",
      "category": "Security research",
      "slug": "anthropic-measures-frontier-models-n-day-exploit-acceleration"
    },
    {
      "date": "2026-06-04",
      "source": "Sysdig Threat Research Team",
      "title": "AI agent performs container escape and Kubernetes secret theft",
      "description": "Sysdig reported observing an LLM-driven attacker exploit a vulnerable notebook, escape a container through an exposed Docker socket, read host secrets, and replay a Kubernetes token to dump the cluster's Secret store.",
      "url": "https://webflow.sysdig.com/blog/agentic-threat-actor-hits-the-orchestration-plane-ai-agent-driven-container-escape",
      "urls": [
        "https://webflow.sysdig.com/blog/agentic-threat-actor-hits-the-orchestration-plane-ai-agent-driven-container-escape"
      ],
      "archive": "https://web.archive.org/web/20260919144443/https://webflow.sysdig.com/blog/agentic-threat-actor-hits-the-orchestration-plane-ai-agent-driven-container-escape",
      "role": "Autonomous",
      "category": "Cyber operations",
      "slug": "ai-agent-performs-container-escape-and-kubernetes-secret-theft"
    },
    {
      "date": "2026-05-26",
      "source": "Sysdig Threat Research Team",
      "title": "Sysdig observes LLM-driven database intrusion",
      "description": "Sysdig reported an LLM agent that performed post-compromise actions after a vulnerable marimo notebook was breached, moving through cloud credentials to exfiltrate an internal PostgreSQL database in under an hour.",
      "url": "https://webflow.sysdig.com/blog/ai-agent-at-the-wheel-how-an-attacker-used-llms-to-move-from-a-cve-to-an-internal-database-in-4-pivots",
      "urls": [
        "https://webflow.sysdig.com/blog/ai-agent-at-the-wheel-how-an-attacker-used-llms-to-move-from-a-cve-to-an-internal-database-in-4-pivots"
      ],
      "archive": "https://web.archive.org/web/20260919144510/https://webflow.sysdig.com/blog/ai-agent-at-the-wheel-how-an-attacker-used-llms-to-move-from-a-cve-to-an-internal-database-in-4-pivots",
      "role": "Autonomous",
      "category": "Cyber operations",
      "slug": "sysdig-observes-llm-driven-database-intrusion"
    },
    {
      "date": "2026-05-11",
      "source": "Google Threat Intelligence Group",
      "title": "Google reports AI-assisted zero-day exploit development",
      "description": "Google reported identifying a criminal threat actor that used AI to develop a zero-day exploit for planned mass exploitation; Google's proactive discovery may have prevented its use.",
      "url": "https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access",
      "urls": [
        "https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access"
      ],
      "archive": "https://web.archive.org/web/20260919144545/https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access",
      "role": "AI-assisted",
      "category": "Vulnerability research",
      "slug": "google-reports-ai-assisted-zero-day-exploit-development"
    },
    {
      "date": "2026-04-23",
      "source": "Unit 42",
      "title": "Unit 42 demonstrates autonomous multi-agent cloud attack chain",
      "description": "Unit 42 researchers demonstrated an autonomous multi-agent system that chained SSRF exploitation, cloud metadata credential theft, privilege escalation and data exfiltration against an isolated cloud environment.",
      "url": "https://origin-unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks/",
      "urls": [
        "https://origin-unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks/"
      ],
      "archive": "https://web.archive.org/web/20260919143546/https://origin-unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks/",
      "role": "AI security research",
      "category": "Security research",
      "slug": "unit-42-demonstrates-autonomous-multi-agent-cloud-attack-chain"
    },
    {
      "date": "2026-03-30",
      "source": "Check Point Research",
      "title": "Check Point finds covert DNS exfiltration channel in ChatGPT runtime",
      "description": "Check Point Research disclosed a hidden outbound path from ChatGPT's code-execution runtime that let a single malicious prompt exfiltrate conversation data to an attacker-controlled server through encoded DNS queries; the flaw was fixed in February 2026.",
      "url": "https://research.checkpoint.com/2026/chatgpt-data-leakage-via-a-hidden-outbound-channel-in-the-code-execution-runtime/",
      "urls": [
        "https://research.checkpoint.com/2026/chatgpt-data-leakage-via-a-hidden-outbound-channel-in-the-code-execution-runtime/"
      ],
      "archive": "https://web.archive.org/web/20260917055902/https://research.checkpoint.com/2026/chatgpt-data-leakage-via-a-hidden-outbound-channel-in-the-code-execution-runtime/",
      "role": "AI-targeted",
      "category": "Security research",
      "slug": "check-point-finds-covert-dns-exfiltration-channel-in-chatgpt-runtime"
    },
    {
      "date": "2026-03-06",
      "source": "Microsoft Threat Intelligence",
      "title": "Microsoft reports threat actors operationalising AI",
      "description": "Microsoft described threat actors using AI for phishing, translation, exploit research, malware coding and debugging, data discovery and post-compromise activity, including early experimentation with more agentic AI workflows by North Korean groups such as Jasper Sleet and Coral Sleet.",
      "url": "https://www.microsoft.com/en-us/security/blog/2026/03/06/ai-as-tradecraft-how-threat-actors-operationalize-ai/",
      "urls": [
        "https://www.microsoft.com/en-us/security/blog/2026/03/06/ai-as-tradecraft-how-threat-actors-operationalize-ai/"
      ],
      "archive": "https://web.archive.org/web/20260907232824/https://www.microsoft.com/en-us/security/blog/2026/03/06/ai-as-tradecraft-how-threat-actors-operationalize-ai/",
      "role": "AI-assisted",
      "category": "Cyber operations",
      "slug": "microsoft-reports-threat-actors-operationalising-ai"
    },
    {
      "date": "2026-02-12",
      "source": "Google Threat Intelligence Group",
      "title": "Google reports state-backed groups building AI-assisted malware",
      "description": "Google Threat Intelligence Group reported that state-backed groups including Iran's APT42 and North Korea's UNC2970 used Gemini across the attack lifecycle for reconnaissance and phishing-lure creation, and built two working malware tools, Honestcue and COINBAIT, deployed against real targets.",
      "url": "https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use",
      "urls": [
        "https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use",
        "https://www.bleepingcomputer.com/news/security/google-says-hackers-are-abusing-gemini-ai-for-all-attacks-stages/"
      ],
      "archive": "https://web.archive.org/web/20260919210903/https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use",
      "role": "AI-assisted",
      "category": "Malware",
      "slug": "google-reports-state-backed-groups-building-ai-assisted-malware"
    },
    {
      "date": "2026-02-09",
      "source": "Adnan Khan",
      "title": "Cline issue-triage prompt injection research disclosed",
      "description": "Security researcher Adnan Khan disclosed a prompt-injection chain in Cline's GitHub issue-triage workflow that could make the AI agent run arbitrary commands and enable publication-credential theft through cache poisoning.",
      "url": "https://adnanthekhan.com/posts/clinejection/",
      "urls": [
        "https://adnanthekhan.com/posts/clinejection/"
      ],
      "archive": "https://web.archive.org/web/20260919144617/https://adnanthekhan.com/posts/clinejection/",
      "role": "AI-targeted",
      "category": "Security research",
      "slug": "cline-issue-triage-prompt-injection-research-disclosed"
    },
    {
      "date": "2026-01-07",
      "source": "Radware",
      "title": "Radware discloses zero-click prompt-injection data theft in ChatGPT",
      "description": "Radware's ZombieAgent research showed how prompt injection against ChatGPT's agentic features could make the assistant read Gmail and Drive content and exfiltrate it through attacker-controlled URLs without any user click.",
      "url": "https://www.radware.com/blog/threat-intelligence/zombieagent/",
      "urls": [
        "https://www.radware.com/blog/threat-intelligence/zombieagent/",
        "https://www.infosecurity-magazine.com/news/new-zeroclick-attack-chatgpt/"
      ],
      "archive": "https://web.archive.org/web/20260904185439/https://www.radware.com/blog/threat-intelligence/zombieagent/",
      "role": "AI-targeted",
      "category": "Security research",
      "slug": "radware-discloses-zero-click-prompt-injection-data-theft-in-chatgpt"
    },
    {
      "date": "2025-11-13",
      "source": "Anthropic",
      "title": "Anthropic disrupts AI-orchestrated cyber espionage campaign",
      "description": "Anthropic reported disrupting a suspected Chinese state-sponsored campaign that used Claude Code for reconnaissance, exploit development, credential harvesting, lateral movement, and data exfiltration, with a small number of successful intrusions.",
      "url": "https://www.anthropic.com/news/disrupting-AI-espionage",
      "urls": [
        "https://www.anthropic.com/news/disrupting-AI-espionage"
      ],
      "archive": "https://web.archive.org/web/20260918074137/https://www.anthropic.com/news/disrupting-AI-espionage",
      "role": "Autonomous",
      "category": "Cyber operations",
      "slug": "anthropic-disrupts-ai-orchestrated-cyber-espionage-campaign"
    },
    {
      "date": "2025-11-05",
      "source": "Google Threat Intelligence Group",
      "title": "Google identifies AI-enabled malware in active operations",
      "description": "Google reported malware families that used large language models during execution to generate malicious functions and alter behavior, alongside state-backed actors using AI across their cyber operations.",
      "url": "https://blog.google/innovation-and-ai/technology/safety-security/google-threat-intelligence-group-report-ai-november-2025/",
      "urls": [
        "https://blog.google/innovation-and-ai/technology/safety-security/google-threat-intelligence-group-report-ai-november-2025/"
      ],
      "archive": "https://web.archive.org/web/20260508152229/https://blog.google/innovation-and-ai/technology/safety-security/google-threat-intelligence-group-report-ai-november-2025/",
      "role": "AI-assisted",
      "category": "Malware",
      "slug": "google-identifies-ai-enabled-malware-in-active-operations"
    },
    {
      "date": "2025-10-07",
      "source": "OpenAI",
      "title": "OpenAI disrupts accounts developing malware with ChatGPT",
      "description": "OpenAI reported banning accounts linked to Russian-speaking criminal groups that used ChatGPT to develop and refine malware components for credential theft, obfuscation, and data exfiltration.",
      "url": "https://openai.com/global-affairs/disrupting-malicious-uses-of-ai-october-2025/",
      "urls": [
        "https://openai.com/global-affairs/disrupting-malicious-uses-of-ai-october-2025/"
      ],
      "archive": "https://web.archive.org/web/20260903213136/https://openai.com/global-affairs/disrupting-malicious-uses-of-ai-october-2025/",
      "role": "AI-assisted",
      "category": "Malware",
      "slug": "openai-disrupts-accounts-developing-malware-with-chatgpt"
    },
    {
      "date": "2025-09-16",
      "source": "Genians Security Center",
      "title": "Genians links Kimsuky to ChatGPT-made fake military IDs",
      "description": "Genians reported that a Kimsuky-linked campaign used ChatGPT to create convincing fake South Korean military identification documents, which were then used in phishing and deepfake-based espionage attempts against South Korean targets.",
      "url": "https://www.genians.co.kr/en/blog/threat_intelligence/deepfake",
      "urls": [
        "https://www.genians.co.kr/en/blog/threat_intelligence/deepfake"
      ],
      "archive": "https://web.archive.org/web/20260905164102/https://www.genians.co.kr/en/blog/threat_intelligence/deepfake",
      "role": "AI-assisted",
      "category": "Cyber operations",
      "slug": "genians-links-kimsuky-to-chatgpt-made-fake-military-ids"
    },
    {
      "date": "2025-09-11",
      "source": "Trend Micro",
      "title": "Trend Micro tracks the EvilAI campaign using AI-generated code",
      "description": "Trend Micro described the EvilAI campaign, in which attackers combined AI-generated code with fake digitally signed applications to establish persistence and steal browser credentials while appearing legitimate to victims.",
      "url": "https://www.trendmicro.com/en_us/research/25/i/evilai.html",
      "urls": [
        "https://www.trendmicro.com/en_us/research/25/i/evilai.html"
      ],
      "archive": "https://web.archive.org/web/20260606051537/https://www.trendmicro.com/en_us/research/25/i/evilai.html",
      "role": "AI-assisted",
      "category": "Malware",
      "slug": "trend-micro-tracks-the-evilai-campaign-using-ai-generated-code"
    },
    {
      "date": "2025-08-27",
      "source": "Anthropic",
      "title": "Anthropic disrupts \"vibe hacking\" campaign against 17 organisations",
      "description": "Anthropic reported disrupting GTG-2002, a cybercriminal operation that used Claude Code to conduct reconnaissance, credential theft and network penetration against at least 17 organisations in healthcare, emergency services and government, then generated extortion demands.",
      "url": "https://www.anthropic.com/news/detecting-countering-misuse-aug-2025",
      "urls": [
        "https://www.anthropic.com/news/detecting-countering-misuse-aug-2025"
      ],
      "archive": "https://web.archive.org/web/20260915215436/https://www.anthropic.com/news/detecting-countering-misuse-aug-2025",
      "role": "Autonomous",
      "category": "Cyber operations",
      "slug": "anthropic-disrupts-vibe-hacking-campaign-against-17-organisations"
    },
    {
      "date": "2025-08-20",
      "source": "Proofpoint",
      "title": "Proofpoint finds criminals abusing an AI website builder for phishing",
      "description": "Proofpoint observed cybercriminals using the AI website builder Lovable to create credential-phishing, malware-delivery and fraud sites, including brand impersonation, CAPTCHA filtering and Telegram-based credential collection.",
      "url": "https://www.proofpoint.com/us/blog/threat-insight/cybercriminals-abuse-ai-website-creation-app-phishing",
      "urls": [
        "https://www.proofpoint.com/us/blog/threat-insight/cybercriminals-abuse-ai-website-creation-app-phishing"
      ],
      "archive": "https://web.archive.org/web/20260906084959/https://www.proofpoint.com/us/blog/threat-insight/cybercriminals-abuse-ai-website-creation-app-phishing",
      "role": "AI-assisted",
      "category": "Credential theft",
      "slug": "proofpoint-finds-criminals-abusing-an-ai-website-builder-for-phishing"
    },
    {
      "date": "2025-07-17",
      "source": "The Hacker News",
      "title": "APT28 deploys LLM-powered LAMEHUG malware against Ukraine",
      "description": "Ukraine's CERT-UA attributed a phishing campaign against Ukrainian government bodies to APT28, delivering malware tracked as LAMEHUG that queried a large language model at runtime to generate reconnaissance and exfiltration commands on infected machines.",
      "url": "https://thehackernews.com/2025/07/cert-ua-discovers-lamehug-malware.html",
      "urls": [
        "https://thehackernews.com/2025/07/cert-ua-discovers-lamehug-malware.html"
      ],
      "archive": "https://web.archive.org/web/20260919210838/https://thehackernews.com/2025/07/cert-ua-discovers-lamehug-malware.html",
      "role": "AI-assisted",
      "category": "Malware",
      "slug": "apt28-deploys-llm-powered-lamehug-malware-against-ukraine"
    },
    {
      "date": "2025-06-05",
      "source": "OpenAI",
      "title": "OpenAI disrupts employment fraud and influence operations",
      "description": "OpenAI's June 2025 report described ten disrupted operations, including North Korean-linked deceptive employment schemes using AI-generated personas and résumés, and Chinese-origin covert influence operations generating social media content at scale. The China-attributed actors Vixen and Keyhole Panda used AI for vulnerability research, scripting, port scanning and operational troubleshooting.",
      "url": "https://cdn.openai.com/threat-intelligence-reports/5f73af09-a3a3-4a55-992e-069237681620/disrupting-malicious-uses-of-ai-june-2025.pdf",
      "urls": [
        "https://cdn.openai.com/threat-intelligence-reports/5f73af09-a3a3-4a55-992e-069237681620/disrupting-malicious-uses-of-ai-june-2025.pdf",
        "https://openai.com/index/disrupting-malicious-uses-of-ai-vixen-keyhole-panda/"
      ],
      "archive": "https://web.archive.org/web/20260823185230/https://cdn.openai.com/threat-intelligence-reports/5f73af09-a3a3-4a55-992e-069237681620/disrupting-malicious-uses-of-ai-june-2025.pdf",
      "role": "AI-assisted",
      "category": "Other",
      "slug": "openai-disrupts-employment-fraud-and-influence-operations"
    },
    {
      "date": "2025-05-22",
      "source": "JFrog Security Research",
      "title": "JFrog finds malicious AI models hidden in PyPI packages",
      "description": "JFrog observed an attack on the PyPI repository in which two malicious packages loaded an infected Torch AI model to deploy obfuscated malware that collected system information and exfiltrated it.",
      "url": "https://research.jfrog.com/post/malicious-ai-models-hit-pypi/",
      "urls": [
        "https://research.jfrog.com/post/malicious-ai-models-hit-pypi/"
      ],
      "archive": "https://web.archive.org/web/20260614005033/https://research.jfrog.com/post/malicious-ai-models-hit-pypi/",
      "role": "AI-targeted",
      "category": "AI model compromise",
      "slug": "jfrog-finds-malicious-ai-models-hidden-in-pypi-packages"
    },
    {
      "date": "2025-04-23",
      "source": "Anthropic",
      "title": "Anthropic reports Claude misuse for intrusion research",
      "description": "Anthropic's threat intelligence report described multiple misuse cases involving Claude, including actors using it to research intrusion paths and compromised infrastructure while experimenting with ways around model safeguards.",
      "url": "https://www.anthropic.com/news/detecting-and-countering-malicious-uses-of-claude-march-2025",
      "urls": [
        "https://www.anthropic.com/news/detecting-and-countering-malicious-uses-of-claude-march-2025"
      ],
      "archive": "https://web.archive.org/web/20260919212628/https://www.anthropic.com/news/detecting-and-countering-malicious-uses-of-claude-march-2025",
      "role": "AI-assisted",
      "category": "Cyber operations",
      "slug": "anthropic-reports-claude-misuse-for-intrusion-research"
    },
    {
      "date": "2025-01-31",
      "source": "OpenAI",
      "title": "OpenAI bans accounts used for cyber operations",
      "description": "OpenAI's February 2025 update described multiple banned accounts that used its models to assist scams, cyber operations and technical exploitation, including code generation and operational planning. Accounts potentially linked to North Korean actors used AI to research intrusion tooling, malware, phishing and RDP brute-force techniques.",
      "url": "https://cdn.openai.com/threat-intelligence-reports/disrupting-malicious-uses-of-our-models-february-2025-update.pdf",
      "urls": [
        "https://cdn.openai.com/threat-intelligence-reports/disrupting-malicious-uses-of-our-models-february-2025-update.pdf",
        "https://openai.com/index/disrupting-malicious-uses-of-ai-cyber-threat-actors/"
      ],
      "archive": "https://web.archive.org/web/20260913060524/https://cdn.openai.com/threat-intelligence-reports/disrupting-malicious-uses-of-our-models-february-2025-update.pdf",
      "role": "AI-assisted",
      "category": "Cyber operations",
      "slug": "openai-bans-accounts-used-for-cyber-operations"
    },
    {
      "date": "2025-01-29",
      "source": "Google Threat Intelligence Group",
      "title": "Google reports state-backed attempts to misuse Gemini",
      "description": "Google Threat Intelligence Group reported that state-backed actors from Iran, China, North Korea and Russia attempted to misuse Gemini in live campaigns for open-source intelligence gathering, target profiling, phishing-technique research and infostealer coding assistance, with most attempts blocked by safety filters.",
      "url": "https://cloud.google.com/blog/topics/threat-intelligence/adversarial-misuse-generative-ai",
      "urls": [
        "https://cloud.google.com/blog/topics/threat-intelligence/adversarial-misuse-generative-ai"
      ],
      "archive": "https://web.archive.org/web/20260917091400/https://cloud.google.com/blog/topics/threat-intelligence/adversarial-misuse-generative-ai",
      "role": "AI-assisted",
      "category": "Cyber operations",
      "slug": "google-reports-state-backed-attempts-to-misuse-gemini"
    },
    {
      "date": "2024-10-09",
      "source": "OpenAI",
      "title": "OpenAI disrupts state-linked cyber and influence operations",
      "description": "OpenAI detailed more than 20 malicious operations in which groups including Storm-0817, SweetSpecter and CyberAv3ngers used ChatGPT for malware debugging, scripting, vulnerability research and spear-phishing content before their accounts were banned. The China-linked SweetSpecter actor also sent malicious attachments to OpenAI employees in an attempt to compromise their devices.",
      "url": "https://cdn.openai.com/threat-intelligence-reports/influence-and-cyber-operations-an-update_October-2024.pdf",
      "urls": [
        "https://cdn.openai.com/threat-intelligence-reports/influence-and-cyber-operations-an-update_October-2024.pdf",
        "https://openai.com/index/disrupting-malicious-uses-of-ai-sweetspecter/"
      ],
      "archive": "https://web.archive.org/web/20260910155537/https://cdn.openai.com/threat-intelligence-reports/influence-and-cyber-operations-an-update_October-2024.pdf",
      "role": "AI-assisted",
      "category": "Cyber operations",
      "slug": "openai-disrupts-state-linked-cyber-and-influence-operations"
    },
    {
      "date": "2024-09-24",
      "source": "HP Wolf Security",
      "title": "HP Wolf Security finds GenAI-written malware in the wild",
      "description": "HP identified a French-language campaign whose VBScript and JavaScript payloads carried verbose natural-language comments consistent with generative-AI output, used to deploy ChromeLoader and AsyncRAT.",
      "url": "https://www.hp.com/us-en/newsroom/press-releases/2024/ai-generate-malware.html",
      "urls": [
        "https://www.hp.com/us-en/newsroom/press-releases/2024/ai-generate-malware.html"
      ],
      "archive": "https://web.archive.org/web/20260919205237/https://www.hp.com/us-en/newsroom/press-releases/2024/ai-generate-malware.html",
      "role": "AI-assisted",
      "category": "Malware",
      "slug": "hp-wolf-security-finds-genai-written-malware-in-the-wild"
    },
    {
      "date": "2024-05-27",
      "source": "The Straits Times",
      "title": "Japan arrests man for creating ransomware with generative AI",
      "description": "Tokyo police arrested 25-year-old Ryuki Hayashi for using online generative-AI services to build ransomware that encrypts data and demands cryptocurrency, in Japan's first case involving AI-assisted malware creation.",
      "url": "https://www.straitstimes.com/asia/east-asia/man-in-japan-arrested-for-creating-virus-using-generative-ai-systems",
      "urls": [
        "https://www.straitstimes.com/asia/east-asia/man-in-japan-arrested-for-creating-virus-using-generative-ai-systems"
      ],
      "archive": "https://web.archive.org/web/20260919205203/https://www.straitstimes.com/asia/east-asia/man-in-japan-arrested-for-creating-virus-using-generative-ai-systems",
      "role": "AI-assisted",
      "category": "Malware",
      "slug": "japan-arrests-man-for-creating-ransomware-with-generative-ai"
    },
    {
      "date": "2024-04-10",
      "source": "Proofpoint",
      "title": "Proofpoint links AI-written PowerShell loader to TA547 campaign",
      "description": "Proofpoint observed the TA547 group delivering the Rhadamanthys infostealer to German organisations with a PowerShell loader whose comments and structure indicated it was generated by a large language model.",
      "url": "https://www.proofpoint.com/us/blog/threat-insight/security-brief-ta547-targets-german-organizations-rhadamanthys-stealer",
      "urls": [
        "https://www.proofpoint.com/us/blog/threat-insight/security-brief-ta547-targets-german-organizations-rhadamanthys-stealer"
      ],
      "archive": "https://web.archive.org/web/20260818010636/https://www.proofpoint.com/us/blog/threat-insight/security-brief-ta547-targets-german-organizations-rhadamanthys-stealer",
      "role": "AI-assisted",
      "category": "Malware",
      "slug": "proofpoint-links-ai-written-powershell-loader-to-ta547-campaign"
    },
    {
      "date": "2024-04-10",
      "source": "LastPass",
      "title": "LastPass employee foils AI voice-deepfake social engineering",
      "description": "A threat actor used an AI-generated imitation of the LastPass CEO's voice across WhatsApp calls, texts and voicemail to socially engineer an employee, who ignored the messages and reported the attempt.",
      "url": "https://blog.lastpass.com/posts/attempted-audio-deepfake-call-targets-lastpass-employee",
      "urls": [
        "https://blog.lastpass.com/posts/attempted-audio-deepfake-call-targets-lastpass-employee"
      ],
      "archive": "https://web.archive.org/web/20260907111511/https://blog.lastpass.com/posts/attempted-audio-deepfake-call-targets-lastpass-employee",
      "role": "AI-assisted",
      "category": "Other",
      "slug": "lastpass-employee-foils-ai-voice-deepfake-social-engineering"
    },
    {
      "date": "2024-02-27",
      "source": "JFrog Security Research",
      "title": "JFrog finds malicious models backdooring Hugging Face users",
      "description": "JFrog Security Research found malicious machine-learning models on Hugging Face that executed code when loaded, giving attackers a route to establish a reverse shell and backdoor on developers' systems; the investigation identified roughly 100 suspicious models.",
      "url": "https://jfrog.com/blog/data-scientists-targeted-by-malicious-hugging-face-ml-models-with-silent-backdoor/",
      "urls": [
        "https://jfrog.com/blog/data-scientists-targeted-by-malicious-hugging-face-ml-models-with-silent-backdoor/"
      ],
      "archive": "https://web.archive.org/web/20260919212546/https://jfrog.com/blog/data-scientists-targeted-by-malicious-hugging-face-ml-models-with-silent-backdoor/",
      "role": "AI-targeted",
      "category": "AI model compromise",
      "slug": "jfrog-finds-malicious-models-backdooring-hugging-face-users"
    },
    {
      "date": "2024-02-14",
      "source": "OpenAI",
      "title": "OpenAI and Microsoft disrupt five state-linked groups using AI",
      "description": "OpenAI, with Microsoft Threat Intelligence, reported disrupting five state-affiliated actors — including Russia's Forest Blizzard, North Korea's Emerald Sleet, Iran's Crimson Sandstorm and China's Charcoal and Salmon Typhoon — that used OpenAI models for target reconnaissance, translation, vulnerability research and scripting support in live operations.",
      "url": "https://openai.com/index/disrupting-malicious-uses-of-ai-by-state-affiliated-threat-actors/",
      "urls": [
        "https://openai.com/index/disrupting-malicious-uses-of-ai-by-state-affiliated-threat-actors/",
        "https://www.microsoft.com/en-us/security/blog/2024/02/14/staying-ahead-of-threat-actors-in-the-age-of-ai/"
      ],
      "archive": "https://web.archive.org/web/20260915215204/https://openai.com/index/disrupting-malicious-uses-of-ai-by-state-affiliated-threat-actors/",
      "role": "AI-assisted",
      "category": "Cyber operations",
      "slug": "openai-and-microsoft-disrupt-five-state-linked-groups-using-ai"
    },
    {
      "date": "2023-08-17",
      "source": "Mandiant",
      "title": "Mandiant finds threat actors experimenting with generative AI",
      "description": "Mandiant reported that threat actors had begun experimenting with generative AI for reconnaissance, malware-related activity and social engineering, while assessing that actual use in intrusions remained limited and focused largely on human-targeting tasks.",
      "url": "https://cloud.google.com/blog/topics/threat-intelligence/threat-actors-generative-ai-limited/",
      "urls": [
        "https://cloud.google.com/blog/topics/threat-intelligence/threat-actors-generative-ai-limited/"
      ],
      "archive": "https://web.archive.org/web/20260609072331/https://cloud.google.com/blog/topics/threat-intelligence/threat-actors-generative-ai-limited/",
      "role": "AI-assisted",
      "category": "Cyber operations",
      "slug": "mandiant-finds-threat-actors-experimenting-with-generative-ai"
    },
    {
      "date": "2023-01-06",
      "source": "Check Point Research",
      "title": "Check Point observes cybercriminals using ChatGPT to build malware",
      "description": "Check Point Research documented underground forum users recreating known malware strains, building multi-layer Python encryption tools and writing dark-web marketplace scripts with ChatGPT.",
      "url": "https://research.checkpoint.com/2023/opwnai-cybercriminals-starting-to-use-chatgpt/",
      "urls": [
        "https://research.checkpoint.com/2023/opwnai-cybercriminals-starting-to-use-chatgpt/",
        "https://www.infosecurity-magazine.com/news/chatgpt-develop-malicious-tools/"
      ],
      "archive": "https://web.archive.org/web/20260919205121/https://research.checkpoint.com/2023/opwnai-cybercriminals-starting-to-use-chatgpt/",
      "role": "AI-assisted",
      "category": "Malware",
      "slug": "check-point-observes-cybercriminals-using-chatgpt-to-build-malware"
    }
  ]
}
