⌁AI·CYBER·BRIEF▌

#Autonomous Attacks

AI Threats7 min read

An AI agent breached a Dutch security non-profit via two Zammad zero-days — one is still unpatched

An AI agent chained two Zammad zero-days to break into DIVD's helpdesk. Both are now on CISA's exploited list, and the root flaw is still unpatched.

Agentic AIAutonomous AttacksZammad
AI Threats10 min read

CLOSEDQUORUM: malware that asks four AI models what to do next — and nobody has seen it used

Cisco Talos documented a Windows implant that replaces its command-and-control server with a vote among four commercial LLMs. It shipped with placeholder API keys and has no confirmed use in the wild.

AnalysisCisco TalosCLOSEDQUORUM
AI Threats7 min read

AI agents ran a card-skimming spree on online shops: 600,000 cards, about $25 a victim

Gambit Security recovered an attacker's staging server: three open-source AI agents broke into 27 companies in five days, stole 600,000+ card records and planted skimmers on 100+ sites.

AI AgentsE-commerceMagento