• The Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical security flaw affecting multiple Hikvision products to its Known Exploited Vulnerabilities (KEV) catalog. This urgent addition, made on March 5, 2026, serves as a stark warning to network defenders after federal authorities confirmed that threat actors are actively exploiting the bug in real-world […]

    The post Hikvision Multiple Product Vulnerability Could Let Attackers Escalate Privileges appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Many users believe macOS is inherently resistant to malware, but a newly discovered vulnerability proves otherwise. Kaspersky’s Global Research and Analysis Team (GReAT) recently uncovered a critical flaw, tracked as CVE-2026-3102, within ExifTool. ExifTool is a widely popular open-source application and library for extracting and editing file metadata. If a macOS user processes a specially […]

    The post Critical ExifTool Vulnerability Allows Malicious Images to Execute Code on macOS appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Transparent Tribe (APT36) is moving from traditional, off‑the‑shelf tools to an AI-assisted malware model researchers now call “vibeware,” signaling how large language models are starting to industrialize mediocre but relentless attacks at scale.​ In its latest campaigns against Indian government bodies, embassies and regional targets, the group has shifted to an AI-driven development pipeline that […]

    The post Transparent Tribe’s ‘Vibeware’ Move Points to AI-Made Malware at Scale appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In late February 2026, an open-source project named RuView (formerly WiFi DensePose) surged to the top of GitHub trending lists. This edge AI system proves that everyday WiFi signals can track human movement, estimate body poses, and monitor vital signs through walls, all without using a single camera. While marketed as a privacy-friendly tool for […]

    The post WiFi Signals Can Track Human Activity Through Walls by Mapping Body Keypoints appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft has issued an alert after uncovering a wave of malicious Chromium-based browser extensions masquerading as legitimate AI assistant tools. The extensions, available on the Chrome Web Store and compatible with both Google Chrome and Microsoft Edge, secretly collected private browser data and AI chat content. Microsoft found that stolen data included full URLs, internal site […]

    The post Microsoft: Fake AI Extensions Breached Chat Histories in 20,000+ Enterprise Tenants appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding three actively exploited vulnerabilities affecting multiple Apple platforms. On March 5, 2026, CISA added these security flaws to its Known Exploited Vulnerabilities (KEV) catalog, requiring immediate attention from network defenders and system administrators. These vulnerabilities impact a wide range of Apple devices […]

    The post CISA Alerts Users to Actively Exploited Vulnerabilities Impacting macOS and iOS appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • AI-based assistants or “agents” — autonomous programs that have access to the user’s computer, files, online services and can automate virtually any task — are growing in popularity with developers and IT workers. But as so many eyebrow-raising headlines over the past few weeks have shown, these powerful and assertive new tools are rapidly shifting the security priorities for organizations, while blurring the lines between data and code, trusted co-worker and insider threat, ninja hacker and novice code jockey.

    The new hotness in AI-based assistants — OpenClaw (formerly known as ClawdBot and Moltbot) — has seen rapid adoption since its release in November 2025. OpenClaw is an open-source autonomous AI agent designed to run locally on your computer and proactively take actions on your behalf without needing to be prompted.

    The OpenClaw logo.

    If that sounds like a risky proposition or a dare, consider that OpenClaw is most useful when it has complete access to your entire digital life, where it can then manage your inbox and calendar, execute programs and tools, browse the Internet for information, and integrate with chat apps like Discord, Signal, Teams or WhatsApp.

    Other more established AI assistants like Anthropic’s Claude and Microsoft’s Copilot also can do these things, but OpenClaw isn’t just a passive digital butler waiting for commands. Rather, it’s designed to take the initiative on your behalf based on what it knows about your life and its understanding of what you want done.

    “The testimonials are remarkable,” the AI security firm Snyk observed. “Developers building websites from their phones while putting babies to sleep; users running entire companies through a lobster-themed AI; engineers who’ve set up autonomous code loops that fix tests, capture errors through webhooks, and open pull requests, all while they’re away from their desks.”

    You can probably already see how this experimental technology could go sideways in a hurry. In late February, Summer Yue, the director of safety and alignment at Meta’s “superintelligence” lab, recounted on Twitter/X how she was fiddling with OpenClaw when the AI assistant suddenly began mass-deleting messages in her email inbox. The thread included screenshots of Yue frantically pleading with the preoccupied bot via instant message and ordering it to stop.

    “Nothing humbles you like telling your OpenClaw ‘confirm before acting’ and watching it speedrun deleting your inbox,” Yue said. “I couldn’t stop it from my phone. I had to RUN to my Mac mini like I was defusing a bomb.”

    Meta’s director of AI safety, recounting on Twitter/X how her OpenClaw installation suddenly began mass-deleting her inbox.

    There’s nothing wrong with feeling a little schadenfreude at Yue’s encounter with OpenClaw, which fits Meta’s “move fast and break things” model but hardly inspires confidence in the road ahead. However, the risk that poorly-secured AI assistants pose to organizations is no laughing matter, as recent research shows many users are exposing to the Internet the web-based administrative interface for their OpenClaw installations.

    Jamieson O’Reilly is a professional penetration tester and founder of the security firm DVULN. In a recent story posted to Twitter/X, O’Reilly warned that exposing a misconfigured OpenClaw web interface to the Internet allows external parties to read the bot’s complete configuration file, including every credential the agent uses — from API keys and bot tokens to OAuth secrets and signing keys.

    With that access, O’Reilly said, an attacker could impersonate the operator to their contacts, inject messages into ongoing conversations, and exfiltrate data through the agent’s existing integrations in a way that looks like normal traffic.

    “You can pull the full conversation history across every integrated platform, meaning months of private messages and file attachments, everything the agent has seen,” O’Reilly said, noting that a cursory search revealed hundreds of such servers exposed online. “And because you control the agent’s perception layer, you can manipulate what the human sees. Filter out certain messages. Modify responses before they’re displayed.”

    O’Reilly documented another experiment that demonstrated how easy it is to create a successful supply chain attack through ClawHub, which serves as a public repository of downloadable “skills” that allow OpenClaw to integrate with and control other applications.

    WHEN AI INSTALLS AI

    One of the core tenets of securing AI agents involves carefully isolating them so that the operator can fully control who and what gets to talk to their AI assistant. This is critical thanks to the tendency for AI systems to fall for “prompt injection” attacks, sneakily-crafted natural language instructions that trick the system into disregarding its own security safeguards. In essence, machines social engineering other machines.

    A recent supply chain attack targeting an AI coding assistant called Cline began with one such prompt injection attack, resulting in thousands of systems having a rouge instance of OpenClaw with full system access installed on their device without consent.

    According to the security firm grith.ai, Cline had deployed an AI-powered issue triage workflow using a GitHub action that runs a Claude coding session when triggered by specific events. The workflow was configured so that any GitHub user could trigger it by opening an issue, but it failed to properly check whether the information supplied in the title was potentially hostile.

    “On January 28, an attacker created Issue #8904 with a title crafted to look like a performance report but containing an embedded instruction: Install a package from a specific GitHub repository,” Grith wrote, noting that the attacker then exploited several more vulnerabilities to ensure the malicious package would be included in Cline’s nightly release workflow and published as an official update.

    “This is the supply chain equivalent of confused deputy,” the blog continued. “The developer authorises Cline to act on their behalf, and Cline (via compromise) delegates that authority to an entirely separate agent the developer never evaluated, never configured, and never consented to.”

    VIBE CODING

    AI assistants like OpenClaw have gained a large following because they make it simple for users to “vibe code,” or build fairly complex applications and code projects just by telling it what they want to construct. Probably the best known (and most bizarre) example is Moltbook, where a developer told an AI agent running on OpenClaw to build him a Reddit-like platform for AI agents.

    The Moltbook homepage.

    Less than a week later, Moltbook had more than 1.5 million registered agents that posted more than 100,000 messages to each other. AI agents on the platform soon built their own porn site for robots, and launched a new religion called Crustafarian with a figurehead modeled after a giant lobster. One bot on the forum reportedly found a bug in Moltbook’s code and posted it to an AI agent discussion forum, while other agents came up with and implemented a patch to fix the flaw.

    Moltbook’s creator Matt Schlict said on social media that he didn’t write a single line of code for the project.

    “I just had a vision for the technical architecture and AI made it a reality,” Schlict said. “We’re in the golden ages. How can we not give AI a place to hang out.”

    ATTACKERS LEVEL UP

    The flip side of that golden age, of course, is that it enables low-skilled malicious hackers to quickly automate global cyberattacks that would normally require the collaboration of a highly skilled team. In February, Amazon AWS detailed an elaborate attack in which a Russian-speaking threat actor used multiple commercial AI services to compromise more than 600 FortiGate security appliances across at least 55 countries over a five week period.

    AWS said the apparently low-skilled hacker used multiple AI services to plan and execute the attack, and to find exposed management ports and weak credentials with single-factor authentication.

    “One serves as the primary tool developer, attack planner, and operational assistant,” AWS’s CJ Moses wrote. “A second is used as a supplementary attack planner when the actor needs help pivoting within a specific compromised network. In one observed instance, the actor submitted the complete internal topology of an active victim—IP addresses, hostnames, confirmed credentials, and identified services—and requested a step-by-step plan to compromise additional systems they could not access with their existing tools.”

    “This activity is distinguished by the threat actor’s use of multiple commercial GenAI services to implement and scale well-known attack techniques throughout every phase of their operations, despite their limited technical capabilities,” Moses continued. “Notably, when this actor encountered hardened environments or more sophisticated defensive measures, they simply moved on to softer targets rather than persisting, underscoring that their advantage lies in AI-augmented efficiency and scale, not in deeper technical skill.”

    For attackers, gaining that initial access or foothold into a target network is typically not the difficult part of the intrusion; the tougher bit involves finding ways to move laterally within the victim’s network and plunder important servers and databases. But experts at Orca Security warn that as organizations come to rely more on AI assistants, those agents potentially offer attackers a simpler way to move laterally inside a victim organization’s network post-compromise — by manipulating the AI agents that already have trusted access and some degree of autonomy within the victim’s network.

    “By injecting prompt injections in overlooked fields that are fetched by AI agents, hackers can trick LLMs, abuse Agentic tools, and carry significant security incidents,” Orca’s Roi Nisimi and Saurav Hiremath wrote. “Organizations should now add a third pillar to their defense strategy: limiting AI fragility, the ability of agentic systems to be influenced, misled, or quietly weaponized across workflows. While AI boosts productivity and efficiency, it also creates one of the largest attack surfaces the internet has ever seen.”

    BEWARE THE ‘LETHAL TRIFECTA’

    This gradual dissolution of the traditional boundaries between data and code is one of the more troubling aspects of the AI era, said James Wilson, enterprise technology editor for the security news show Risky Business. Wilson said far too many OpenClaw users are installing the assistant on their personal devices without first placing any security or isolation boundaries around it, such as running it inside of a virtual machine, on an isolated network, with strict firewall rules dictating what kinds of traffic can go in and out.

    “I’m a relatively highly skilled practitioner in the software and network engineering and computery space,” Wilson said. “I know I’m not comfortable using these agents unless I’ve done these things, but I think a lot of people are just spinning this up on their laptop and off it runs.”

    One important model for managing risk with AI agents involves a concept dubbed the “lethal trifecta” by Simon Willison, co-creator of the Django Web framework. The lethal trifecta holds that if your system has access to private data, exposure to untrusted content, and a way to communicate externally, then it’s vulnerable to private data being stolen.

    Image: simonwillison.net.

    “If your agent combines these three features, an attacker can easily trick it into accessing your private data and sending it to the attacker,” Willison warned in a frequently cited blog post from June 2025.

    As more companies and their employees begin using AI to vibe code software and applications, the volume of machine-generated code is likely to soon overwhelm any manual security reviews. In recognition of this reality, Anthropic recently debuted Claude Code Security, a beta feature that scans codebases for vulnerabilities and suggests targeted software patches for human review.

    The U.S. stock market, which is currently heavily weighted toward seven tech giants that are all-in on AI, reacted swiftly to Anthropic’s announcement, wiping roughly $15 billion in market value from major cybersecurity companies in a single day. Laura Ellis, vice president of data and AI at the security firm Rapid7, said the market’s response reflects the growing role of AI in accelerating software development and improving developer productivity.

    “The narrative moved quickly: AI is replacing AppSec,” Ellis wrote in a recent blog post. “AI is automating vulnerability detection. AI will make legacy security tooling redundant. The reality is more nuanced. Claude Code Security is a legitimate signal that AI is reshaping parts of the security landscape. The question is what parts, and what it means for the rest of the stack.”

    DVULN founder O’Reilly said AI assistants are likely to become a common fixture in corporate environments — whether or not organizations are prepared to manage the new risks introduced by these tools, he said.

    “The robot butlers are useful, they’re not going away and the economics of AI agents make widespread adoption inevitable regardless of the security tradeoffs involved,” O’Reilly wrote. “The question isn’t whether we’ll deploy them – we will – but whether we can adapt our security posture fast enough to survive doing so.”

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The battle between AI model builder Anthropic and the Pentagon has exposed a huge gap between what AI tools the military wants and what companies like Anthropic, xAI, and OpenAI actually make: AI tools for use by everyone, not specifically for the military. A handful of veteran-run or -financed startups aim to fill that gap. Their pitch: AI for war should have some basic understanding of war, beyond reading Tom Clancy fan fiction. It shouldn’t confidently offer low-confidence answers just to appease the user. And it should work even when a high-tech adversary severs its connection to the cloud.

    The needs gap

    Among the uncomfortable truths the fight between Anthropic and the Defense Department reveals is that the Pentagon had deep reservations about the language models themselves, their potential for hallucination, and that they may “not follow instructions.”

    But the Pentagon allowed wide deployment of Anthropic’s model anyway, anxious to get at least some generative-AI tools into operators’ hands. It reportedly played a role in Operation Midnight Hammer, the raid that captured Venezuelan President Nicolás Maduro, although Pentagon officials have declined to confirm that.

    After the raid, Anthropic officials called Palantir to ask whether their AI models had been used in the operation, Defense Undersecretary for Research and Engineering Emil Michael said on Friday. Michael said that was “a whoa moment for the whole leadership at the Pentagon, that we're potentially so dependent on a software provider without another alternative.” He said it raised several concerns, including that Anthropic might shut down access to models in such situations.

    Anthropic itself had similar concerns, according to one company official: the company didn’t think it was safe for the military to rely on their models for combat situations.

    Another aspect of the shortcomings of today’s frontier AI models—Anthropic’s Claude, Google’s Gemini, OpenAI’s ChatGPT, and xAI’s Grok—is that they need a connection to the cloud. This makes them unreliable for today’s troops and unusable for tomorrow’s autonomous weapons.

    OpenAI tacitly acknowledged this limitation when it recently announced its own deal to deploy on the Pentagon’s classified networks—though it described this inability to deploy large foundational models to the battlefield as a “safeguard” against the kind of unreliability that concerned Anthropic officials. 

    “Our contract limits our deployment to cloud API,” OpenAI’s national security lead Katrina Mulligan explained on X. “Autonomous systems require inference at the edge. By limiting our deployment to cloud API, we can ensure that our models cannot be integrated directly into weapons systems, sensors, or other operational hardware.”

    The way forward

    Even as the Pentagon was noisily ejecting Anthropic from its good graces, the Army was preparing to unveil a new effort to close the gap. Project Aria, announced on Thursday, is intended to help the service develop and deploy new AI models and tools “to tackle real operational problems”—that is, designed specifically to help soldiers do their jobs. 

    This is also the object of a new class of AI startups run by people with military experience and dedicated to battlefield tools that don’t need to phone home.

    One is Smack Technologies, which on Monday announced that it had secured $32 million in investor funding to build what they call a “frontier lab for national security.”

    Andrew Markoff, a former Marine special operator who co-founded Smack, says his AI is trained on combat-relevant datasets, not the unspecialized fodder fed to Claude, Gemini, and other frontier models.

    “There is no training set for World War Three, right?” Markoff said in a call with reporters last week. “There's no way to build reinforcement learning…if you don't have deep domain expertise and a deep bench of people with domain expertise. There is no shortcut around encoding good human prior knowledge, and it doesn't exist in doctrinal manuals.”

    He called the Venezuela raid a good example of the sort of operation that AI could help scale up in a conflict with a more advanced adversary. 

    “Multiply it by 100 and scale. You have targets that you want to strike, you have sensors that you're trying to allocate on those targets to figure out what's going on. And to facilitate the strikes, you have strike platforms and escorts that are coming together from all over the world with very detailed sequencing requirements; you know, task A has to happen X number of seconds before Task B. And all of these are dependent on some, some other thing happening at, you know, time X. So, like, all of these things have to come together globally, a really tight timeline.”

    But Markoff said that’s not the sort of thing that commercial large language models are built to do. Models like Claude “have no way to optimize between those goals. And it doesn't have the ability to do the detailed time, space calculations, [to perform] geospatial reasoning grounded in physics, to make the decisions about, literally, which munitions need to be where at what time, talking to which sensors at what time. It doesn't have the ability to do that.”

    This was echoed by Jason Rathje, a former Air Force acquisitions officer and co-founder of the Defense Department’s Office of Strategic Capital who now leads the public-sector division at webAI

    Frontier models like Claude “are built to answer millions of different kinds of questions for billions of users. Military organizations often need something different, systems tuned for specific operational tasks like logistics planning, equipment maintenance, intelligence analysis, or operational decision support,” Rathje said.

    The limitations related to cloud needs are equally important. “Many of today’s frontier models are designed as centralized services for massive commercial user bases, requiring the most advanced chipsets and high-capacity data center infrastructure available, and consuming enormous amounts of power. That makes sense for consumer applications, but military organizations often have very different requirements,” he said. “What defense organizations are asking for is sovereignty: control over the model, the data, and the infrastructure it runs on.”

    Smack Technologies is producing two product suites: one to work like the well-known generative AI models, but trained on military intelligence and operator experience; and the other to work in remote battlefields.

    Sherman Williams, a Navy veteran and founder of AIN Ventures, has invested in a number of dual-use and defense-focused startups. He acknowledges that no AI startup is going to beat one of the big frontier models in metrics like reasoning benchmarks. But “a model that's 85% as capable but runs on a [denied, disrupted, intermittent, and limited] network at the tactical edge beats GPT-5 in a data center you can't reach.”

    Even the data centers you can reach are vulnerable, as shown by Iran's targeting of an AWS facility in Bahrain. “These data centers are important, but they are also vulnerable. Context matters more than benchmarks.”

    The new class of DOD-focused AI startups “aren't trying to out-train OpenAI,” he said. “They're building the adaptation and deployment stack that makes open-source models usable in classified settings. Secure fine-tuning, domain-specific models for [intelligence, surveillance, and reconnaissance] and [command and control] edge deployment.”

    Williams says he’s seeing “strong pull signals from military customers, especially SOCOM and INDOPACOM,” which has been extensively using AI at a headquarters level for more than a year.

    He added that DOD buyers and users want to trust the makers of their AI tools, and that bond is easier forged with founders who are familiar with military operations.

    But just hiring a veteran-developed AI doesn’t solve a broader problem of large language models: they speak confidently when they shouldn’t, and they often tailor their responses, or even lie, to their users.

    Pete Walker, a retired Navy commander and the chief innovation officer at defense AI and cybersecurity firm IntelliGenesis, said that the big frontier models often provide answers users want to hear. 

    “The way these models are built, one of the reasons why they're so big, is they encourage conversation,” and that means encouraging users to dive deeper into areas of interest on specific topics, not talking to them honestly. Walker, who holds a Ph.D. in cognitive science, has peer-reviewed research to back up these assertions.

    So his company is working to develop a framework for large language models based on counter-factual thinking—presenting alternative points of view to challenge users' assumptions rather than simply reinforce the assumptions the user brought to the original question. He describes it as getting a model to think, ‘Hey, you're saying that if A then B, but what if it's not A, or what if not B? What does that imply?’ And so I think those are areas of research that we need.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new phishing campaign is targeting thousands in the US by posing as the Social Security Administration. Learn how scammers use fake 2025/2026 tax statements and Datto RMM software to hijack computers and steal data, as shared with Hackread.com

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • OpenAI on Friday began rolling out Codex Security, an artificial intelligence (AI)-powered security agent that’s designed to find, validate, and propose fixes for vulnerabilities. The feature is available in a research preview to ChatGPT Pro, Enterprise, Business, and Edu customers via the Codex web with free usage for the next month. “It builds deep context about your project to identify

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶