A new threat snapshot points to a familiar pattern: social engineering, defense evasion, and AI-flavored packaging are converging into a more efficient cybercrime workflow.
A growing body of research shows that reusable AI agent skills can be weaponized to steal credentials, pull source code, and plant backdoors while slipping past weaker static checks.
A compromised AI extension marketplace shows how trust, rankings, and package names can be turned into a delivery system for hostile code.
A public Hugging Face repository briefly climbed the platform’s trending list while carrying a Windows infostealer, exposing how reputation signals can become an attack multiplier.
A wave of weaponized AI browser extensions reveals deep flaws in software marketplaces, exposing enterprises to invisible, large-scale data theft.
As OpenClaw’s AI skills ecosystem booms, cybercriminals exploit its openness, planting dangerous payloads in seemingly helpful modules.
Millions of developers exposed as spyware-ridden AI tools silently siphon source code to overseas servers.