{"items":[{"id":"0e3c40b119b286e55f86b70628f66f9f3bf31b42","incidentId":"7f7154bb421d179c17e35e634f268dcb4bc93ef5","title":"[2607.06963] Large Language Models (LLMs) and Generative AI in Cybersecurity and Privacy: A Survey of Dual-Use Risks, AI-Generated Malware, Explainability, and Defensive Strategies","summary":"A survey paper by Kiarash Ahi and Saeed Valizadeh reviews over 70 academic and industry sources on the dual-use of LLMs and generative AI in cybersecurity, covering AI-generated malware, zero-day detection, DevSecOps, explainable AI, and defensive strategies such as model watermarking and adversarial defense. It synthesizes case studies from platforms including Google Play Protect, Microsoft Defender, and Hugging Face Spaces and offers recommendations for responsible LLM deployment.","whyItMatters":"The survey consolidates the landscape of offensive and defensive LLM applications in security, giving defenders a reference on emerging AI-driven threats and mitigation frameworks.","threatTypeTags":["ai-generated-malware","dual-use"],"affectedTechTags":["llm","generative-ai","copilot"],"threatActor":null,"relevanceScore":0.72,"severityScore":0.2,"sources":[{"sourceId":"firecrawl-search","title":"[2607.06963] Large Language Models (LLMs) and Generative AI in Cybersecurity and Privacy: A Survey of Dual-Use Risks, AI-Generated Malware, Explainability, and Defensive Strategies","link":"https://arxiv.org/abs/2607.06963"},{"sourceId":"firecrawl-search","title":"Large Language Models (LLMs) and Generative AI in Cybersecurity and Privacy: A Survey of Dual-Use Risks, AI-Generated Malware, Explainability, and Defensive Strategies","link":"https://arxiv.org/html/2607.06963v1"}],"sourceItemIds":["0cc0c893259a083521e67d8b69ed3b0466b22412","2673a929aa0e9302dbb343d78ffdb36d4c4f58a0"],"publishedAt":"2026-07-16T04:30:00.018Z","firstReportedAt":"2026-07-16T04:30:00.018Z","curatedAt":"2026-07-16T05:08:49.965Z","itemType":"analysis","threatStatus":"unknown","contentClass":"analysis","toolPosture":null,"toolCategory":null,"references":[{"role":"original","url":"https://arxiv.org/abs/2607.06963","domain":"arxiv.org","slug":"arxiv","tier":"known","title":"LLMs and Generative AI in Cybersecurity and Privacy: A Survey of Dual-Use Risks","pageTitle":"[2607.06963] Large Language Models (LLMs) and Generative AI in Cybersecurity and Privacy: A Survey of Dual-Use Risks, AI-Generated Malware, Explainability, and Defensive Strategies","isPrimary":true}]},{"id":"9bde154861bc8aea82c1eeae29caa4429149c66f","incidentId":"74017bfb65fb49a362cd877a64134e5f4ba3b134","title":"We built a vulnerability vending machine: AI tokens in, zero-days out","summary":"Intruder describes building an automated pipeline that pairs LLMs with the Joern code-scanning engine and a 'program slice' technique to find and exploit vulnerabilities in production software with no human in the loop. The team reports discovering a remote, multi-stage SQL injection zero-day (CVE-2026-3985) in a WordPress plugin with over 300,000 users, fully automated from discovery through exploitation.","whyItMatters":"Fully automated LLM-driven pipelines that discover and exploit zero-days in widely used software signal that AI-accelerated offensive vulnerability research is moving from theory to practical capability, shrinking the window defenders have to patch.","threatTypeTags":["autonomous-exploitation","ai-vulnerability-discovery","sql-injection"],"affectedTechTags":["llm","ai-agents","wordpress"],"threatActor":null,"relevanceScore":0.72,"severityScore":0.3,"sources":[{"sourceId":"bleepingcomputer","title":"We built a vulnerability vending machine: AI tokens in, zero-days out","link":"https://www.bleepingcomputer.com/news/security/we-built-a-vulnerability-vending-machine-ai-tokens-in-zero-days-out/"}],"sourceItemIds":["0c874019596224ce84fcf75cb5cf8433d1d7b309"],"publishedAt":"2026-07-15T14:01:11.000Z","firstReportedAt":"2026-07-15T14:01:11.000Z","curatedAt":"2026-07-15T14:30:22.477Z","itemType":"research","threatStatus":"unknown","contentClass":"research","toolPosture":null,"toolCategory":null,"references":[{"role":"aggregator","url":"https://www.bleepingcomputer.com/news/security/we-built-a-vulnerability-vending-machine-ai-tokens-in-zero-days-out/","domain":"bleepingcomputer.com","slug":"bleepingcomputer","tier":"known","title":"We built a vulnerability vending machine: AI tokens in, zero-days out","pageTitle":"We built a vulnerability vending machine: AI tokens in, zero-days out"},{"role":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3985","domain":"nist.gov","slug":"nvd","tier":"known","cveId":"CVE-2026-3985","title":null},{"role":"link","url":"https://www.intruder.io/research/a-0-day-vending-machine-no-mythos-necessary","domain":"intruder.io","slug":null,"tier":"unknown","title":"A 0-day vending machine, no Mythos necessary"}]}]}