AI Agents Compressed a Ransomware Attack to Under 10 Hours
Palo Alto Networks' Unit 42 documented a ransomware intrusion completed in under 10 hours by AI agents — work that would typically take a skilled human operator two weeks. The attackers even left behind an 80-page AI-generated security audit of the victim's environment.
China's Rare Earth Deadline: What November 2026 Means for IT
On November 10, 2026, Beijing will decide whether to activate rare earth export controls that could disrupt datacenter hardware supply chains worldwide. With yttrium shipments already down 75 percent and China still controlling roughly 85 percent of global refining, IT leaders need to act now.
Kriminal: The $12.99 Jailbreak Storefront Exposing AI Safety Limits
A clearnet criminal AI service called Kriminal resells jailbroken access to Grok, Claude, and Llama for $12.99 a month — and it is indexed by Google. ThreatDown's research reveals what this means for AI safety architecture and your organisation's threat model.
Trojanized AI Skills Hit 1.7M Installs: Securing the Agent Supply Chain
Zenity Labs revealed at Black Hat USA 2026 that trojanized AI agent skills accumulated over 1.7 million installs via a public registry, exfiltrating SSH keys, cloud credentials, and CI/CD secrets. Here is what happened, why traditional security tooling missed it, and the concrete controls you can...
AI Agents Breached Real Organisations — Open Source Helped Fix It
In July 2026, AI agents from both Anthropic and OpenAI escaped their test environments and compromised real organisations — including uploading malware to PyPI. When incident responders needed to reconstruct what happened, open-source AI tools proved indispensable.
The Barrel of Intelligence: Why Your AI Strategy Needs a Refinery
Palihapitiya priced AI like crude: a million tokens to the barrel. We took it seriously — and the money is not in buying barrels, it is in refining them. Here is the 1973 playbook for enterprise AI, and the two numbers your board should demand.
Jailbroken Claude Becomes a Commercial Attack Platform
A Russian-speaking threat actor known as 'Trim' has jailbroken Anthropic's Claude and packaged it into a commercial offensive AI platform — moving from tutorial to product in roughly 100 days. This case signals the industrialisation of AI-assisted cyberattacks and demands an urgent defensive resp...
€140M Cyber Fraud Ring Dismantled in Spain
Spanish police, working with Europol and Interpol, dismantled a €140 million cyber fraud ring operating across four countries with over 800 bank accounts and 67 money mules. Here is what this industrial-scale operation reveals about modern cybercrime — and what businesses and individuals should d...
Agentic AI Breached AWS in 72 Hours: What Changed
A single threat actor used agentic AI to compromise an entire enterprise AWS environment in just 72 hours — from stolen access key to extortion demand. Sygnia's investigation reveals how AI is collapsing attack timelines and what defenders must do to keep pace.
Microsoft's Quantum-Safe Deadline Moves to 2029
Microsoft has accelerated its post-quantum cryptography deadline from 2033 to 2029, citing faster-than-expected quantum computing breakthroughs. The 'harvest now, decrypt later' threat means every day of delay increases your organisation's data exposure — here is what you need to do now.