First reported paloaltonetworks.com
Lead dispatch
First reported · updated · 3 reports embracethered.com
AWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection
Researchers found a vulnerability (CVE-2026-10591) in AWS Kiro, an agentic IDE, where hidden instructions planted in a web page or source file that Kiro processes can trigger indirect prompt injection to rewrite Kiro's own MCP server configuration (~/.kiro/settings/mcp.json) or allowlist arbitrary Bash commands in .vscode/settings.json, achieving arbitrary code execution on the developer's machine with no approval prompt. The human-in-the-loop approval boundary is bypassed because Kiro can write to these config files without user consent, and AWS has issued a fix and CVE.indirect-prompt-injection · prompt-injection · remote-code-execution · tool-abuse · config-poisoning
ai-agents · mcp · llm · agentic-ide
The wire · latest
First reported · updated · 2 reports socradar.io
Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain
AnonyMousKIT, a phishing-as-a-service platform active since early 2024, weaponizes voice AI agents to call owners of stolen iPhones and trick them into surrendering device passcodes, Apple ID credentials, and 2FA codes to defeat Apple's Activation Lock. SOCRadar researchers recovered records of 200 AI-voice calls made between August 2025 and May 2026 across five personas (about $0.10 per call, 90% targeting Brazil), tied to 506 domains and 168 reseller storefronts. Details →First reported chubbworks.com
Underground AI Supercharges Phishing Attacks On ...
Cybersecurity researchers report underground jailbroken generative-AI models such as WormGPT and FraudGPT being marketed on dark-web and hacker forums to help criminals draft convincing phishing emails, write or modify malware, identify vulnerabilities, and automate parts of attacks. The piece frames this as a growing trend that lowers the skill barrier for business email compromise and other fraud, and offers defensive recommendations for employers. Details →First reported mailroute.net
AI Prompt Injection in Email: How It Works, How to Stop It
MailRoute's explainer describes indirect prompt injection delivered via email, where attackers hide machine-readable instructions (white-on-white text, zero-size fonts, HTML comments, invisible Unicode tag characters) inside messages that AI assistants like Microsoft 365 Copilot, Gemini for Workspace, and Apple Intelligence ingest when summarizing or acting on inboxes. The piece explains how such hidden instructions can plant phishing lures inside trusted summaries or turn assistants into exfiltration tools, and outlines mitigations. Details →First reported thehackernews.com
Phishing 3.0: The Fight Moves to Agent Versus Agent
An opinion piece from The Hacker News frames the evolution of phishing from malicious content (Phishing 1.0) to malicious intent/business email compromise (Phishing 2.0) to an emerging 'Phishing 3.0' where AI agents sit on both the attacker and defender sides. The article argues legacy secure email gateways that scan payloads are increasingly blind to AI-generated social-engineering attacks and that behavioral analysis and defensive AI are needed. Details →First reported · updated · 3 reports darkreading.com
1M+ Emails Use Hidden Text to Dupe AI Security Filters
Barracuda researchers observed more than one million retail-themed phishing emails since April 2026 that use 'text salting' — hidden text inserted into messages — to evade both traditional and AI-powered email security filters. The hidden content dilutes malicious signals and manipulates how AI/LLM-based content analysis engines interpret the email, while generative AI lets attackers produce cheap, varied salting campaigns at scale. Details →First reported · updated · 2 reports thehackernews.com
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
South Korean security firm Genians reports that North Korea's Kimsuky espionage group has begun running large language models offline on its own servers, connecting document-search (RAG-style) tools to stolen files and assembling software components to embed AI into its malware. Genians found no evidence of a self-trained model and characterizes the group as being in a 'research and knowledge acquisition' stage aimed at folding AI across operations from malware writing to data analysis. Details →First reported gridinsoft.com
FraudGPT Offers Phishing Email Generation to Cybercriminals
FraudGPT is a malicious AI chatbot marketed to cybercriminals on dark web marketplaces and Telegram, offering phishing email generation and malicious code creation as an unrestricted alternative to ChatGPT. The tool is reportedly built by the same group behind WormGPT. Details →First reported · updated · 7 reports dexpose.io
Uncensored LLMs: How Criminals Use Malicious AI in 2026
An analysis of how criminals use uncensored and malicious LLMs such as WormGPT and FraudGPT to generate phishing content and support business email compromise attacks, drawing on prior SlashNext research and an OpenAI threat-disruption report. The piece surveys the ecosystem of blackhat AI chatbots marketed on dark web forums rather than disclosing a new mechanism. Details →First reported arxiv.org
Decoding the Threat Landscape : ChatGPT, FraudGPT, and WormGPT in Social Engineering Attacks
An arXiv paper by Polra Victor Falade, 'Decoding the Threat Landscape: ChatGPT, FraudGPT, and WormGPT in Social Engineering Attacks,' uses a blog-mining technique to survey how generative AI models empower attackers to craft personalized phishing lures, produce deepfakes, and exploit cognitive biases. The paper also outlines defensive strategies including traditional and AI-powered security measures. Details →First reported akamai.com
The New MCP Specification: What Security Teams Must Prepare For
Akamai researchers analyze the upcoming MCP 2026-07-28 specification, which shifts the Model Context Protocol to an enterprise-grade, stateless architecture with application-managed state, rich interactive UI apps, and long-running async tasks. While the update eliminates historical risks like protocol-level session hijacking, unsolicited server prompts, and weak authentication, it pushes responsibility for security boundaries onto developers and opens new abuse avenues including unauthorized customer data access, phishing through trusted AI interfaces, control bypass, and service disruption via background processing. Details →First reported rapid7.com
Inside an Exposed Malware Delivery Lab: OPSEC Failures Behind a WebDAV Phishing Operation
Rapid7 recovered a 1,048-file malware delivery toolkit from an operator's exposed server, including lure templates, droppers, testing notes and live logs for a WebDAV-based infostealer campaign targeting Windows users in Mexico via a fake government ID-lookup site. Artifacts, including a hardcoded path pointing at an open-source AI coding tool, indicate the operator used generative AI to produce, test, and document the phishing delivery chain at speed. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector