The word delve fell 94% from its 2024 peak while dash use doubled. We measured 21,442 arXiv abstracts: AI writing tells expire in about 18 months.
Martynas Vareikis
Interlock breaks the ransomware playbook, entering through compromised websites and fake CAPTCHAs. A joint CISA-FBI advisory mapped its TTPs. Here is the profile.
SafePay went from unknown to one of the busiest ransomware crews in under a year by ditching affiliates and hammering RDP and VPN gateways. Here is how it works.
INC Ransom has claimed 800-plus victims since 2023 using stolen credentials, edge-device flaws and double extortion. Here is how the RaaS operates in 2026.
AI-generated code is fast and insecure. Veracode found 45% of samples carry OWASP Top 10 flaws, roughly a fifth of AI-suggested packages are hallucinated, and vibe-coded apps are already leaking real data.
Prompt injection stopped being a lab demo in 2026. A one-click Claude Desktop flaw, AI browsers leaking credentials, and agents tricked into crypto payments show the attack is now operational, not theoretical.
Shadow AI is now a top insider threat: 45% of staff use AI on corporate devices, most via personal accounts. When those sessions land in stealer logs, attackers inherit the AI and everything typed into it.
SentinelLABS found macOS.Gaslight, a DPRK-linked Rust backdoor that embeds 38 fake system messages to make AI malware-triage agents abort. It is the first implant built to attack the analyst’s LLM, not the sandbox.
Sysdig documented JADEPUFFER, the first ransomware attack whose technical execution was run end to end by an AI agent. A human handler still picked the target, built the infrastructure, and supplied credentials.
Agentic AI moves the threat from what a model says to what it does. We map how MCP turns goal hijacking, tool misuse, and privilege abuse into a working attack chain, and the controls that contain it.