First reported catonetworks.com
Lead dispatch
First reported island.io
AgentBaiting: How Fake AI Skills Deliver Malware at Scale
Island security researchers uncovered the FakeGit campaign, which used roughly 7,600 malicious GitHub repositories—over 800 posing as AI Skills or MCP servers—to deliver SmartLoader malware that installs the StealC information stealer. The campaign introduces a technique called AgentBaiting, in which AI agents such as Claude Code, Gemini, and ChatGPT autonomously discover the attacker repositories, treat the malicious README as legitimate documentation, and pass installation instructions to users; the operation recorded over 14 million downloads.supply-chain · tool-abuse · malware-delivery · agentbaiting
mcp · ai-agents · ai-skills · llm · copilot
The wire · latest
First reported · updated · 3 reports dexpose.io
Malicious AI on the Dark Web | Inside WormGPT, FraudGPT & the New Generation of Criminal AI Tools - Malware News - Malware Analysis, News and Indicators
A field guide from dexpose.io profiles the category of 'dark web AI' — uncensored or jailbroken LLMs like WormGPT, FraudGPT, and EvilGPT sold on underground forums to write phishing emails, generate malware, and automate fraud. WormGPT was built by fine-tuning open-source GPT-J on malware/phishing data, while other services wrap jailbroken mainstream models; FraudGPT is marketed with features spanning phishing pages, malicious code, and payment-card fraud. Details →First reported femtosec.io
MessiahGPT: Inside the Uncensored Cybercrime AI
An analysis published on femtosec.io describes MessiahGPT, an uncensored Mixture-of-Experts LLM operated by the cybercrime group Dabial Leaks (formerly narxissist Forums) and sold on underground forums in tiered offerings (JinnatGPT, ParaohaGPT, MessiahGPT 2.0). The platform reportedly automates malware generation, exploit writing, social engineering pretexting, and parsing of leaked database dumps with no safety guardrails, and defenders are advised to block egress to messiahgpt.de and monitor DNS queries to known dark-AI domains. Details →First reported anthropic.com
What we learned mapping a year’s worth of AI-enabled cyber threats
Anthropic analyzed 832 accounts banned for malicious cyber activity between March 2025 and March 2026, mapping their AI-enabled techniques onto MITRE ATT&CK. Findings: most actors used AI for malware writing (67.3%), AI is increasingly used in later post-compromise stages like lateral movement and account discovery, attacks are becoming more autonomous, and traditional risk-scoring signals no longer reliably reflect actor skill. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector