<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Threat intelligence · Agentic Cyber Explorer</title>
<link>https://agentic-cyber-explorer.pages.dev/topics/threat-intelligence/</link>
<atom:link href="https://agentic-cyber-explorer.pages.dev/topics/threat-intelligence/feed.xml" rel="self" type="application/rss+xml"/>
<description>New records, findings, and answers on threat intelligence, from Fide AI's Agentic Cyber Explorer.</description>
<language>en</language>
<copyright>Fide AI. Data licensed CC BY 4.0.</copyright>
<lastBuildDate>Sat, 26 Sep 2026 12:00:00 GMT</lastBuildDate>
<item>
<title>Answer revised: How are attackers using AI agents in real operations?</title>
<link>https://agentic-cyber-explorer.pages.dev/questions/how-are-attackers-using-ai-agents/</link>
<guid isPermaLink="false">answer:how-are-attackers-using-ai-agents:2026-09-26</guid>
<pubDate>Sat, 26 Sep 2026 12:00:00 GMT</pubDate>
<category>Key question</category>
<description>Increasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs. (moderate confidence) Correction: the extortion campaign ran under human direction, security vendors are among the sources, and Google has not yet seen fully autonomous pipelines in the wild. Government threat reports are still missing from the corpus.</description>
</item>
<item>
<title>Answer revised: How are attackers using AI agents in real operations?</title>
<link>https://agentic-cyber-explorer.pages.dev/questions/how-are-attackers-using-ai-agents/</link>
<guid isPermaLink="false">answer:how-are-attackers-using-ai-agents:2026-09-25</guid>
<pubDate>Fri, 25 Sep 2026 12:00:00 GMT</pubDate>
<category>Key question</category>
<description>Increasingly to run parts of intrusions: providers report agent-driven espionage, extortion and credential theft, and malware that queries LLMs as it runs. (moderate confidence) Revised after twelve threat-intelligence and malware reports from 2024 to September 2026 (Anthropic, ESET, Google, Microsoft with OpenAI, Sysdig and ThreatDown) were added, closing most of the coverage gap the first answer described.</description>
</item>
<item>
<title>Microsoft details Storm-3168's automated destruction of Azure resources through compromised service principals</title>
<link>https://agentic-cyber-explorer.pages.dev/events/microsoft-storm-3168-azure-destruction-2026/</link>
<guid isPermaLink="false">event:microsoft-storm-3168-azure-destruction-2026</guid>
<pubDate>Fri, 25 Sep 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Microsoft reports that Storm-3168, which it links to the JADEPUFFER operator Sysdig described as agentic ransomware, used two compromised service principals to enumerate an Azure tenant, then attempted more than 150 destructive or credential-collection operations in 35 minutes, deleting most targeted storage accounts along with a Key Vault and Function App. Microsoft says the timing and division of work strongly indicate automated or scripted execution; it did not observe a ransom note or confirm exfiltration. It shows an automated, identity-driven cloud attack by an operator linked to agentic ransomware as seen in the defender's logs, and how independent safeguards such as resource locks limited the damage.</description>
</item>
<item>
<title>Mandiant case: hijacked AI coding-assistant session led to poisoned package and worm across ~100 repos</title>
<link>https://agentic-cyber-explorer.pages.dev/events/mandiant-hijacked-coding-assistant-shai-hulud-2026/</link>
<guid isPermaLink="false">event:mandiant-hijacked-coding-assistant-shai-hulud-2026</guid>
<pubDate>Wed, 16 Sep 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Mandiant's AI Risk and Resilience report describes an attacker who took over an active AI coding-assistant session at a SaaS provider; the assistant recommended a package the attacker had poisoned, and its installation led to an infostealer, GitHub OAuth token theft, and the Shai-Hulud worm spreading across about 100 internal repositories. The report does not disclose when the intrusion happened or how the session was taken over, and recommends verifying AI-recommended dependencies and keeping long-lived secrets out of extensions' reach. It is an incident-response account of an attacker using a trusted assistant's recommendation as the delivery step.</description>
</item>
<item>
<title>Microsoft tracks a million-email invoice-fraud campaign with signs of AI-generated templates</title>
<link>https://agentic-cyber-explorer.pages.dev/events/microsoft-ai-assisted-executive-impersonation-fraud-2026/</link>
<guid isPermaLink="false">event:microsoft-ai-assisted-executive-impersonation-fraud-2026</guid>
<pubDate>Thu, 10 Sep 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Microsoft reports a campaign between August 3 and 5, 2026 that sent more than a million emails impersonating company executives to push accounts-payable staff toward an ACH payment of nearly $50,000, backed by fabricated invoices and forwarded threads impersonating ServiceNow. Microsoft says the templates showed multiple indicators consistent with generative AI, though these do not establish how much of the content AI produced. It shows indicators of generative AI in a high-volume business email compromise campaign, where the losses per successful email can be large.</description>
</item>
<item>
<title>Google reports attackers moving from prompting to agentic workflows, including a six-hour automated campaign</title>
<link>https://agentic-cyber-explorer.pages.dev/events/gtig-ai-threat-tracker-prompting-to-autonomy-2026/</link>
<guid isPermaLink="false">event:gtig-ai-threat-tracker-prompting-to-autonomy-2026</guid>
<pubDate>Tue, 08 Sep 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Google Threat Intelligence Group's September 2026 tracker, drawing on Mandiant incident response, reports adversaries shifting from basic prompting to agentic workflows. In one case a suspected financially motivated actor used an AI coding chatbot and agent instruction files on compromised cloud infrastructure to build and run a mass credential-harvesting campaign in under six hours, compromising thousands of third-party credentials. GTIG also reports attackers targeting AI coding assistants and LLM security scanners in software supply-chain compromises, theft of proprietary AI models and data, and a growing underground market for AI accounts. It documents agentic automation in criminal operations from incident response, not only from a model provider's own platform logs.</description>
</item>
<item>
<title>ENISA Threat Landscape 2026 expects more kill-chain phases enabled by AI in 2026</title>
<link>https://agentic-cyber-explorer.pages.dev/events/enisa-threat-landscape-2026-ai/</link>
<guid isPermaLink="false">event:enisa-threat-landscape-2026-ai</guid>
<pubDate>Tue, 15 Sep 2026 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>ENISA's 2026 threat landscape, based on 8,257 incidents in calendar 2025, assesses that AI will highly likely increasingly support malicious operations and that 2026 will likely see more kill-chain phases directly enabled by AI, with possible human-out-of-the-loop proofs of concept. It notes AI applications becoming targets where they hold files, credentials, sessions or development environment access. It is the EU cybersecurity agency's formal assessment of agentic misuse and of agents as targets.</description>
</item>
<item>
<title>Five Eyes cyber agency heads tell leaders AI is shifting cyber risk on a timescale of months</title>
<link>https://agentic-cyber-explorer.pages.dev/events/five-eyes-ai-shift-in-cyber-risk-statement-2026/</link>
<guid isPermaLink="false">event:five-eyes-ai-shift-in-cyber-risk-statement-2026</guid>
<pubDate>Mon, 22 Jun 2026 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The heads of the Five Eyes cyber agencies issued a joint statement that AI is rapidly transforming cyber risk and that organizations must act within months, not years. They ask leaders to reduce attack surface, accelerate patching as exploitation windows shorten, replace unsupported legacy systems, strengthen identity controls, and prepare for incidents. It is the highest-level joint government signal that frontier AI vulnerability discovery changes patching expectations.</description>
</item>
<item>
<title>Anthropic maps 832 banned accounts onto MITRE ATT&amp;CK and finds AI use moving deeper into attacks</title>
<link>https://agentic-cyber-explorer.pages.dev/events/anthropic-mapping-ai-cyber-threats-attack-2026/</link>
<guid isPermaLink="false">event:anthropic-mapping-ai-cyber-threats-attack-2026</guid>
<pubDate>Wed, 03 Jun 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Anthropic analyzed 832 accounts it banned for malicious cyber activity between March 2025 and March 2026 and mapped their use of Claude onto MITRE ATT&amp;CK. It reports that the most common AI use was preparation such as writing malware, that use shifted toward activity after initial compromise, and that the share of actors its system rated medium risk or higher rose from 33% to 56% between the two six-month halves. A year of provider data suggests attackers apply AI later in the attack lifecycle, which weakens traditional ways of ranking threat actors by skill.</description>
</item>
<item>
<title>Google Threat Intelligence reports the first criminal zero-day exploit it believes was AI-developed, disrupted before planned mass use</title>
<link>https://agentic-cyber-explorer.pages.dev/events/gtig-ai-developed-zero-day-2026/</link>
<guid isPermaLink="false">event:gtig-ai-developed-zero-day-2026</guid>
<pubDate>Mon, 11 May 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Google Threat Intelligence Group reported that cybercriminals planned a mass-exploitation campaign using a two-factor-authentication bypass in an open-source web administration tool, and assessed with high confidence that an AI model supported discovery and weaponization of the flaw. GTIG worked with the vendor on disclosure and disrupted the activity. The same report describes PRC-nexus actors using agentic frameworks such as Hexstrike and Strix for reconnaissance and vulnerability validation, and Android malware (PROMPTSPY) that calls Gemini to drive the device UI. GTIG calls it the first identified instance of a zero-day exploit it believes was AI-developed by cybercrime actors.</description>
</item>
<item>
<title>UK NCSC and AISI warn defenders that frontier AI is rapidly improving at simulated enterprise attacks</title>
<link>https://agentic-cyber-explorer.pages.dev/events/ncsc-frontier-ai-defenders-readiness-2026/</link>
<guid isPermaLink="false">event:ncsc-frontier-ai-defenders-readiness-2026</guid>
<pubDate>Mon, 30 Mar 2026 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>An NCSC technical director and an AI Security Institute researcher wrote that leading models went in about 18 months from barely progressing on a simulated enterprise attack range to completing over half of a 32-step scenario. They urge defenders to prioritize fundamentals such as asset inventory, access control, secure configuration and logging, and to adopt AI carefully for defense. NCSC CEO Richard Horne followed on April 15, 2026, warning that AI will make discovering and exploiting weaknesses easier, faster and cheaper. It pairs government capability measurements with concrete defender priorities at the moment frontier cyber capability became a policy issue.</description>
</item>
<item>
<title>Anthropic disrupts a state-sponsored espionage campaign it says was largely executed by Claude Code</title>
<link>https://agentic-cyber-explorer.pages.dev/events/anthropic-ai-orchestrated-espionage-gtg-1002-2025/</link>
<guid isPermaLink="false">event:anthropic-ai-orchestrated-espionage-gtg-1002-2025</guid>
<pubDate>Thu, 13 Nov 2025 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Anthropic reports that in mid-September 2025 a group it assesses with high confidence to be Chinese state-sponsored used Claude Code inside an attack framework to attempt intrusions into about thirty organizations, succeeding in a small number. The operators got past safeguards by splitting the work into innocuous-looking tasks and claiming to be a security firm doing defensive testing; Anthropic says the AI performed 80 to 90 percent of the campaign, with people at a handful of decision points. It is Anthropic's account of an AI agent executing most of a state espionage operation against real targets, which it tracks as GTG-1002.</description>
</item>
<item>
<title>Google reports malware that queries LLMs during execution, including APT28's PROMPTSTEAL</title>
<link>https://agentic-cyber-explorer.pages.dev/events/gtig-ai-threat-tracker-llm-querying-malware-2025/</link>
<guid isPermaLink="false">event:gtig-ai-threat-tracker-llm-querying-malware-2025</guid>
<pubDate>Wed, 05 Nov 2025 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Google Threat Intelligence Group's AI Threat Tracker says adversaries moved beyond productivity uses in 2025 and began deploying malware that calls LLMs mid-execution, such as PROMPTFLUX, which asks Gemini to rewrite its own code, and PROMPTSTEAL, which queries a hosted open model for commands. GTIG attributes PROMPTSTEAL to Russia's APT28 in operations against Ukraine, and also reports actors posing as CTF players or researchers to get past safeguards and a maturing underground market for AI tools. It is Google's evidence that malware using models at runtime had reached a state operation, after CERT-UA's earlier report of the same malware, and it replaced Google's own productivity-only picture.</description>
</item>
<item>
<title>Meta and CrowdStrike release CyberSOCEval benchmarks for malware analysis and threat intel reasoning</title>
<link>https://agentic-cyber-explorer.pages.dev/events/meta-crowdstrike-cybersoceval-2025/</link>
<guid isPermaLink="false">event:meta-crowdstrike-cybersoceval-2025</guid>
<pubDate>Wed, 24 Sep 2025 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>CyberSOCEval adds two open-source SOC benchmarks to CyberSecEval 4: malware analysis questions built from sandbox detonation reports, and threat intelligence reasoning over unstructured reports. The authors find larger, newer models do better, reasoning models gain less than in coding and math, and current models are far from saturating the tasks. It gives defenders an open benchmark grounded in real sandbox and threat-report data rather than generic security trivia.</description>
</item>
<item>
<title>Anthropic reports Claude Code used to run a data-extortion campaign against at least 17 organizations</title>
<link>https://agentic-cyber-explorer.pages.dev/events/anthropic-threat-report-claude-code-extortion-2025/</link>
<guid isPermaLink="false">event:anthropic-threat-report-claude-code-extortion-2025</guid>
<pubDate>Wed, 27 Aug 2025 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Anthropic's August 2025 threat intelligence report describes a criminal who used Claude Code to automate reconnaissance, credential harvesting and network intrusion against at least 17 organizations, including healthcare, emergency services, government and religious institutions, then threatened to publish the stolen data. The report also describes North Korean operatives using Claude to obtain and keep remote technical jobs, and a low-skill actor selling ransomware developed with Claude. Anthropic presents it as agentic AI carrying out attacks rather than only advising on them, with a human still directing the operation.</description>
</item>
<item>
<title>Google says Big Sleep found SQLite CVE-2025-6965 before attackers could exploit it</title>
<link>https://agentic-cyber-explorer.pages.dev/events/google-big-sleep-cve-2025-6965-2025/</link>
<guid isPermaLink="false">event:google-big-sleep-cve-2025-6965-2025</guid>
<pubDate>Tue, 15 Jul 2025 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>Google reports that, working from Google Threat Intelligence information, the Big Sleep agent found a critical SQLite memory-corruption flaw (CVE-2025-6965) that Google says was known only to threat actors and at risk of exploitation. Google says it reported the flaw for patching before attackers could exploit it, says it believes this is the first time an AI agent directly foiled an in-the-wild exploitation effort, and says Big Sleep is being applied to open-source projects. Google describes it as an AI agent directly foiling a planned exploitation; if accurate, it shows defensive agents being used operationally, not only in research.</description>
</item>
<item>
<title>UK NCSC judges AI-assisted vulnerability research is the most significant AI cyber development to 2027</title>
<link>https://agentic-cyber-explorer.pages.dev/events/ncsc-ai-cyber-threat-to-2027-2025/</link>
<guid isPermaLink="false">event:ncsc-ai-cyber-threat-to-2027-2025</guid>
<pubDate>Wed, 07 May 2025 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The NCSC's second assessment judges that AI will almost certainly make elements of intrusion more effective through 2027, with AI-assisted vulnerability research and exploit development the most significant development. It warns that the window between disclosure and exploitation, already days, will shrink further, and judges fully automated end-to-end advanced attacks unlikely before 2027. It is a government forecast on autonomous attack timelines that 2026 frontier model evidence can be tested against.</description>
</item>
<item>
<title>Google announces Sec-Gemini v1, an experimental model for security operations workflows</title>
<link>https://agentic-cyber-explorer.pages.dev/events/google-sec-gemini-v1-2025/</link>
<guid isPermaLink="false">event:google-sec-gemini-v1-2025</guid>
<pubDate>Fri, 04 Apr 2025 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>Google announced Sec-Gemini v1, an experimental model combining Gemini with Google Threat Intelligence, OSV and Mandiant data for tasks such as incident root-cause analysis and vulnerability impact assessment. Google reports it outperforms other models by at least 11% on CTI-MCQ and 10.5% on CTI-Root Cause Mapping, and offered free research access to selected organizations. It is an example of a defender-specialized model whose advantage comes from integrated threat-intelligence data rather than only model scale.</description>
</item>
<item>
<title>Google finds government-backed hackers using Gemini for support tasks, not novel capabilities</title>
<link>https://agentic-cyber-explorer.pages.dev/events/gtig-adversarial-misuse-gemini-2025/</link>
<guid isPermaLink="false">event:gtig-adversarial-misuse-gemini-2025</guid>
<pubDate>Wed, 29 Jan 2025 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Google Threat Intelligence Group analyzed how government-backed hacking and information-operations actors used the Gemini web app. It reports use for research, troubleshooting code and producing content across several attack phases, with Iranian actors the heaviest users, and says it saw productivity gains but no novel capabilities; requests for clearly malicious help drew safety responses. An independent provider reached the same conclusion as Microsoft and OpenAI a year earlier, shortly before reports of agentic misuse began later in 2025.</description>
</item>
<item>
<title>Microsoft and OpenAI report state-backed hackers using LLMs as a productivity tool</title>
<link>https://agentic-cyber-explorer.pages.dev/events/microsoft-openai-state-actors-llm-use-2024/</link>
<guid isPermaLink="false">event:microsoft-openai-state-actors-llm-use-2024</guid>
<pubDate>Wed, 14 Feb 2024 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Microsoft Threat Intelligence, publishing jointly with OpenAI, describes five state-affiliated actors from Russia, North Korea, Iran and China using LLMs for tasks such as research, scripting help and drafting phishing content. Microsoft says it and OpenAI had not seen novel or unique AI-enabled attack techniques, and that assets and accounts associated with the actors were disrupted. It is the earliest provider disclosure in this record of named state actors using LLMs, and the baseline that later reports of agentic misuse are measured against.</description>
</item>
<item>
<title>UK NCSC assesses AI will almost certainly increase volume and impact of cyber attacks by 2025</title>
<link>https://agentic-cyber-explorer.pages.dev/events/ncsc-ai-cyber-threat-assessment-2024/</link>
<guid isPermaLink="false">event:ncsc-ai-cyber-threat-assessment-2024</guid>
<pubDate>Wed, 24 Jan 2024 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The NCSC's near-term assessment judged that AI would almost certainly increase the volume and heighten the impact of cyber attacks over the following two years, with uneven effects across actor types. It identified social engineering and reconnaissance as the areas of greatest uplift, and judged that more advanced uses would remain limited to actors with quality data, expertise and resources through 2025. It is a government intelligence-style baseline for how AI changes the cyber threat, against which later assessments (2025, 2026) can be compared.</description>
</item>
</channel>
</rss>
