GitHub ~3,800 internal repos compromised through a malicious VS Code extension https://www.secureblink.com/cyber-security-news/3-800-git-hub-repos-breached-via-poisoned-vs-code-extension-by-team-pcp
AudioHijack: adversarial audio attacks on generative voice models transfer from open weights to Microsoft and Mistral production systems https://spectrum.ieee.org/voice-ai-audio-attacks
Autonomous AI Penetration Testing with Consent-First Ethical Framework — Research Paper + Working Implementation https://doi.org/10.5281/zenodo.19562302
Apple Maildrop lets you rewrite the filename, size, and icon on any icloud.com attachment link — no signature, no validation — reported July 2023, still live https://stuart-thomas.com/research/maildrop-spoofed-params/
The Algorithm Goes to War: Inside the AI Cyberweapon Revolution That Governments Cannot Stop https://novarapress.net/ai-cyberwar-autonomous-agents-cybersecurity/
Technical Analysis of EagleSpy V6.0 (CraxsRAT Rebrand) Distributed Through Odysee and Telegram https://odysee.com/@justicerat:e?r=3DBgjCS94gefoVr7FdzLsSAwTyHFU8V8
Needle crypto-stealer C2 analysis: API key embedded in plain text inside the Rust malware unlocked 1,932 victims and the operator's withdrawal config https://beelzebub.ai/blog/needle-c2-crypto-stealer-analysis/