First reported chubbworks.com
Lead dispatch
First reported · updated · 3 reports embracethered.com
AWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection
Researchers found a vulnerability (CVE-2026-10591) in AWS Kiro, an agentic IDE, where hidden instructions planted in a web page or source file that Kiro processes can trigger indirect prompt injection to rewrite Kiro's own MCP server configuration (~/.kiro/settings/mcp.json) or allowlist arbitrary Bash commands in .vscode/settings.json, achieving arbitrary code execution on the developer's machine with no approval prompt. The human-in-the-loop approval boundary is bypassed because Kiro can write to these config files without user consent, and AWS has issued a fix and CVE.indirect-prompt-injection · prompt-injection · remote-code-execution · tool-abuse · config-poisoning
ai-agents · mcp · llm · agentic-ide
The wire · latest
First reported gridinsoft.com
FraudGPT Offers Phishing Email Generation to Cybercriminals
FraudGPT is a malicious AI chatbot marketed to cybercriminals on dark web marketplaces and Telegram, offering phishing email generation and malicious code creation as an unrestricted alternative to ChatGPT. The tool is reportedly built by the same group behind WormGPT. Details →First reported · updated · 7 reports dexpose.io
Uncensored LLMs: How Criminals Use Malicious AI in 2026
An analysis of how criminals use uncensored and malicious LLMs such as WormGPT and FraudGPT to generate phishing content and support business email compromise attacks, drawing on prior SlashNext research and an OpenAI threat-disruption report. The piece surveys the ecosystem of blackhat AI chatbots marketed on dark web forums rather than disclosing a new mechanism. Details →First reported talosintelligence.com
Cybercriminal abuse of large language models
Cisco Talos analyzes how cybercriminals abuse large language models, detailing the use of uncensored LLMs (e.g. Llama 2 Uncensored via Ollama, WhiteRabbitNeo), custom-built criminal LLMs advertised on hacking forums like OnionGPT, and the jailbreaking of legitimate frontier models. The report notes these malicious LLMs are being wired to external tools for sending phishing email, scanning sites for vulnerabilities, and verifying stolen credit card numbers. Details →First reported arxiv.org
Decoding the Threat Landscape : ChatGPT, FraudGPT, and WormGPT in Social Engineering Attacks
An arXiv paper by Polra Victor Falade, 'Decoding the Threat Landscape: ChatGPT, FraudGPT, and WormGPT in Social Engineering Attacks,' uses a blog-mining technique to survey how generative AI models empower attackers to craft personalized phishing lures, produce deepfakes, and exploit cognitive biases. The paper also outlines defensive strategies including traditional and AI-powered security measures. Details →First reported vc.ru
Автономный ИИ-хакер так и не появился — AI на vc.ru
An analysis piece argues that the feared fully-autonomous AI hacker never materialized, noting that autonomous agents only handle isolated tasks (parsing, exploiting known web vulnerabilities) while APT groups use LLMs as tireless assistants for routine work. It claims the WormGPT source and logs leaked in early 2026, revealing it was merely a Mistral-7B model with public-article RAG and a jailbreak system prompt rather than a bespoke hacking model, and notes a shift toward Jailbreak-as-a-Service (JaaS). Details →First reported github.com
GitHub - Kirozaku/Marina-GPT: M.A.R.I.N.A GPT a powerful, evil brother of WormGPT.
Marina-GPT (M.A.R.I.N.A GPT), hosted on GitHub by user Kirozaku, is a publicly available Python tool marketed as an 'evil brother of WormGPT,' an uncensored/malicious LLM assistant. The repo contains runnable scripts (marina.py, cheyy-linux.py, requirements.txt), a 'Marina Pro' variant, and a Bitcoin wallet address for payment. Details →First reported github.com
GitHub - jailbreakwormGPT/wormGPT: wormGPT free version
A GitHub repository under the account 'jailbreakwormGPT' publishes what it calls 'WormGPT 4,' described as an unrestricted large language model designed for automating text generation, distributed with a worm.py script and framed as a free version of the known malicious WormGPT tool. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector