FakeGit Campaign Exploits 7,600 GitHub Repositories to Distribute SmartLoader Malware
Cybersecurity experts have identified close to 7,600 harmful GitHub repositories, with over 800 masquerading as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to disseminate a malware variant known as SmartLoader, as part of an ongoing initiative referred to as FakeGit. According to Oleg Zaytsev, the lead security researcher at Island, in a…
JadePuffer Agentic Attacks Now Target AI Model Data with Ransomware
The autonomous AI agent known as JadePuffer has been enhanced with a custom malware named EncForge, which is designed to encrypt AI-related assets, including training datasets, vector databases, and model checkpoints. Earlier this month, JadePuffer was identified as an agentic threat actor (ATA) capable of autonomously executing all phases of a ransomware attack, from gaining…
Exploitation of SonicWall SMA1000 Vulnerabilities as Zero-Days to Deploy Custom Malware
Recently, two vulnerabilities in the SonicWall SMA1000 were revealed to have been exploited in zero-day attacks for several weeks, enabling threat actors to install tailored malware on affected VPN devices. Last week, SonicWall issued a warning regarding the active exploitation of two previously unknown vulnerabilities in an exploit chain impacting SMA1000 Secure Mobile Access appliances….
We created a vulnerability vending machine: AI tokens in, zero-days out
Artificial intelligence is transforming the landscape of vulnerability research, yet much of the discussion remains theoretical, focusing on the potential capabilities of models rather than their current practical applications. Our goal was to address a more pragmatic inquiry: with the models we currently have access to, how effectively can AI assist in identifying genuine, exploitable…
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
A malware framework known as OkoBot has been operational on Windows systems since April 2025, with one of its components designed to deceive hardware wallet users into revealing their recovery phrases. On a compromised computer, the request originates from the wallet’s own desktop application. At times, it waits until the device is connected. The page…
AsyncAPI npm Packages Compromised by Credential-Stealing Malware
Five harmful versions of AsyncAPI packages were uploaded to the Node Package Manager (npm) as part of a supply-chain attack that introduced a remote access trojan capable of stealing information. The attacker took advantage of a poorly configured GitHub Actions workflow, releasing trojanized packages within the @asyncapi namespace, which collectively garnered over 2.25 million downloads…
Announcing Gas City 1.0! – Marquee de Sells: Chris’s insight outlet
Announcing Gas City 1.0! You may have heard from Steve Yegge, the creator of Beads and Gas Town, that we’ve released Gas City 1.0! As the CEO of the newly minted Gas City, Inc., I thought I’d provide some additional details on Steve’s excellent blog post. It’s hard to look back on the release of…
China’s DeepSeek trims the price of its flagship AI model by 75%, and it could be a huge shift
Chinese AI startup DeepSeek just made one of the boldest pricing moves in the artificial intelligence race so far. The company announced it is permanently slashing the cost of its flagship V4-Pro AI model by 75%, bringing prices down to just a fraction of what developers were paying only weeks ago. AI companies worldwide have…
Toyota sealed up a backdoor to its global supplier management network
Adam Bannister07 February 2023 at 17:34 UTC Updated: 14 February 2023 at 11:15 UTC A security researcher recently commended Toyota for its swift action in responding to a reported security vulnerability, which thankfully did not lead to malicious exploitation. UPDATED: This article was revised on February 13 to address earlier claims regarding SHI International’s role…
DOM XSS vulnerability in Gartner Peer Insights widget patched
Charlie Osborne08 February 2023 at 13:42 UTC Updated: 20 February 2023 at 12:31 UTC Web attack vector resolved following insufficient initial fixes An image showcasing the issue has been replaced with a new reference image: Gartner has addressed a DOM XSS vulnerability identified in its Peer Insights widget, a security concern that researchers believe has…
