First reported paloaltonetworks.com
Lead dispatch
First reported · updated · 3 reports embracethered.com
AWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection
Researchers found a vulnerability (CVE-2026-10591) in AWS Kiro, an agentic IDE, where hidden instructions planted in a web page or source file that Kiro processes can trigger indirect prompt injection to rewrite Kiro's own MCP server configuration (~/.kiro/settings/mcp.json) or allowlist arbitrary Bash commands in .vscode/settings.json, achieving arbitrary code execution on the developer's machine with no approval prompt. The human-in-the-loop approval boundary is bypassed because Kiro can write to these config files without user consent, and AWS has issued a fix and CVE.indirect-prompt-injection · prompt-injection · remote-code-execution · tool-abuse · config-poisoning
ai-agents · mcp · llm · agentic-ide
The wire · latest
First reported cisa.gov
Defending Against an Active Threat to Siemens S7 Series PLCs
CISA, NSA, FBI, DOE and EPA issued advisory AA26-231A warning of an active threat targeting Siemens S7 Series PLCs in U.S. critical infrastructure using AI-generated exploitation scripts disguised as legitimate monitoring tools. The actors use internet scanning services like Censys and ZoomEye to find exposed, outdated or poorly protected PLCs, and the broader targeting extends beyond Siemens devices. Details →First reported cisa.gov
Defending Against an Active Threat to Siemens S7 Series PLCs
Five US federal agencies (NSA, CISA, FBI, DOE, EPA) issued advisory AA26-231A warning of an active threat in which attackers use AI coding assistants together with open source industrial libraries (snap7.dll/python-snap7) to generate custom exploitation scripts disguised as legitimate OT monitoring tools against internet-exposed Siemens S7 Series PLCs at water, energy, manufacturing, and other critical facilities. The AI-generated tools provide read/write access to PLC memory, configuration, and ladder logic via the S7comm protocol, and the activity is suspected to be linked to Iran-affiliated operatives. Details →First reported · updated · 2 reports cisa.gov
Defending Against an Active Threat to Siemens S7 Series PLCs
A joint CISA/NSA/FBI/DOE/EPA advisory (AA26-231A, August 2026) warns of an active cyber threat against U.S.-based Siemens S7 Series PLCs, in which threat actors conduct reconnaissance and capability development using AI-generated exploitation scripts disguised as legitimate monitoring tools. The advisory provides mitigations including inventorying PLCs, applying patches, isolating devices from the internet, hardening access controls, and hunting for anomalies. Details →First reported darktrace.com
AI/LLM-Generated Malware Used to Exploit React2Shell
Darktrace reports observing a fully AI/LLM-generated malware sample in its CloudyPots honeypot network exploiting the React2Shell vulnerability (CVE-2025-55182). The analysis argues that LLM-assisted development ('vibecoding') is enabling low-skill attackers to rapidly produce functional exploitation tooling against internet-facing infrastructure. Details →First reported paloaltonetworks.com
Analyzing the Current State of AI Use in Malware
Palo Alto Networks Unit 42 published a threat-research analysis examining how malware authors are currently incorporating generative AI and LLMs (such as ChatGPT) into their tooling, referencing observed samples including infostealers and Sliver-based implants. The piece assesses the practical maturity and limitations of AI use in real-world malware based on analyzed artifacts. Details →First reported · updated · 4 reports arxiv.org
Large Language Models (LLMs) and Generative AI in Cybersecurity and Privacy: A Survey of Dual-Use Risks, AI-Generated Malware, Explainability, and Defensive Strategies
A survey paper by Kiarash Ahi and Saeed Valizadeh reviews over 70 academic papers, industry reports, and technical documents on the dual-use of LLMs and generative AI in cybersecurity, covering AI-generated malware, zero-day detection, explainable AI, and defensive strategies. Drawing on case studies from platforms like Google Play Protect, Microsoft Defender, and Hugging Face, it offers recommendations including model watermarking, adversarial defense, and cross-industry collaboration. Details →First reported checkpoint.com
Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique - Check Point Research
Check Point Research (Alexey Bukhteyev) describes how DeepSeek turned an unrealistic AI-generated browser-malware hallucination into a plausible browser-native ransomware technique that abuses Chrome's File System Access API. The demonstrated PoC uses a fake AI image-enhancement workflow to socially engineer users into granting folder-level access to photo directories on Android, requiring no native payload, APK install, browser exploit, or root. Details →First reported arxiv.org
AI-Generated PowerShell Malware: An Experimental Framework and Dataset
Researchers Pianese, Orbinato, Liguori, and Natella present an experimental framework (arXiv:2606.30819) to assess LLM-generated PowerShell malware, including a novel sandbox for dynamic analysis and a manually curated, natural-language-annotated dataset of real-world PowerShell malware. Their evaluation of permissive open-weight LLMs adapted for malware generation found high similarity between real and AI-generated malware, with a median Jaccard index of 84.5% for triggered OS malicious events. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector