Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-platform-securityai-enabled-threat-activitydata-exfiltration-methoddefense-evasion-method

AI-Driven Security Risks, Bypasses, and Exploits in Modern Cybersecurity

Updated 3mo agoFirst seen Oct 31, 202510 sources

Security researchers and industry experts are raising alarms about the growing use of artificial intelligence (AI) in both offensive and defensive cybersecurity operations. Attackers are leveraging AI to bypass advanced security controls, as demonstrated by a researcher who used AI to defeat an "AI-powered" web application firewall, and by the emergence of new malware that exploits AI model files and browser vulnerabilities to evade detection and exfiltrate credentials. Meanwhile, defenders are grappling with the proliferation of unsanctioned AI tools in the workplace, the challenge of auditing AI decision-making, and the surge in AI-powered bug hunting, which has led to a dramatic increase in vulnerability discoveries and bug bounty payouts. The risks are compounded by the lack of clear AI usage policies, the potential for data leaks through generative AI tools, and the difficulty in monitoring or controlling how sensitive information is processed and stored by these systems.

Industry reports highlight that a significant portion of employees use unauthorized AI applications, often exposing sensitive data without IT oversight, and that prompt injection and model manipulation are now common vulnerability types. The security community is also debating the extent to which ransomware and other attacks are truly "AI-driven," with some reports criticized for overstating the role of AI in current threat activity. As organizations rush to adopt AI for efficiency and innovation, experts urge the implementation of robust governance, continuous monitoring, and red-teaming to anticipate and mitigate the evolving risks posed by both sanctioned and shadow AI systems. The rapid evolution of AI in cybersecurity is forcing a reevaluation of traditional defense models, emphasizing the need for transparency, operational oversight, and adaptive security strategies.

Share:
AI-Driven Security Risks, Bypasses, and Exploits in Modern Cybersecurity
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

12 events from the most recent confirmed update back to the earliest known activity.

12 EVENTS
Oct 30, 20258mo ago

Researcher hxr1 demonstrates malware-hiding ONNX PoC on Windows AI stack

Researcher hxr1 disclosed a proof-of-concept living-off-the-land attack that hides malware in ONNX model files used by Windows' native AI stack. The PoC showed how trusted Microsoft-signed components could load malicious content from AI files while evading traditional EDR scrutiny.

Mozilla introduces new Firefox extension data collection disclosure policy

Mozilla announced a new policy requiring clearer disclosure of data collection practices for Firefox extensions. The move was intended to improve transparency around extension behavior and user privacy.

Counter Ransomware Initiative issues new supply chain security guidance

The Counter Ransomware Initiative released new guidance focused on supply chain security. The publication represented a policy and defensive response aimed at improving resilience against ransomware-related supply chain risks.

AWS suffers major outage tied to DNS defect

A major AWS outage was attributed to a DNS defect. The incident was noted as a significant cloud-service disruption affecting availability.

Russia proposes law mandating FSB reporting of vulnerabilities

Russia proposed legislation that would require all vulnerability disclosures to be reported to the FSB. The proposal prompted concern that vulnerability reporting could be redirected toward state misuse rather than coordinated disclosure.

Hacking Team resurfaces as Memento Labs with new spyware

The surveillance vendor formerly known as Hacking Team, now operating as Memento Labs, was reported to have resurfaced with new spyware. The development marked the re-emergence of a historically controversial spyware supplier.

Apple iOS 26 update found to overwrite shutdown logs

Apple's iOS 26 update was reported to overwrite shutdown logs, removing forensic evidence that could reveal Pegasus and Predator spyware infections. The finding raised concerns about the impact of the update on mobile forensic investigations.

Everest ransomware gang claims 280 GB theft from Svenska Kraftnät

The Everest ransomware gang claimed responsibility for the Svenska Kraftnät incident and said it exfiltrated 280 GB of data. This added an attacker attribution and a reported scale of data theft to the breach narrative.

Svenska Kraftnät confirms ransomware-related data breach

Sweden's power grid operator, Svenska Kraftnät, confirmed that it suffered a data breach related to a ransomware incident. The disclosure established the organization as a victim in a significant critical-infrastructure cyber event.

Attackers launch millions of attempts against GutenKit and Hunk Companion flaws

Threat actors targeted critical vulnerabilities in the WordPress plugins GutenKit and Hunk Companion in millions of exploitation attempts. The activity underscored the continued security risk posed by widely deployed plugin ecosystems.

CISA warns about exploitation of WSUS flaw CVE-2025-59287

Following reports of active exploitation of CVE-2025-59287 in Microsoft WSUS, CISA issued a warning urging attention to the vulnerability. The warning elevated the significance of the flaw beyond Microsoft's patch release.

Microsoft patches actively exploited WSUS RCE CVE-2025-59287

Microsoft released an urgent patch for CVE-2025-59287, a major remote code execution flaw in Windows Server Update Services (WSUS) that was reported as being under active exploitation. The issue was highlighted as one of the week's most critical vulnerability developments.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

48 LINKEDOpen in app
Organizations
34 linked
Microsoft CorporationMozillaCheck Point Software TechnologiesAmazonHugging FaceCisco SystemsQuesmaTinderAmazon Web ServicesUniFiEuropolTata MotorsTrenchantCISAL3Harris TechnologiesUnited NationsTP-LinkfsbWordpressNSO GroupHudson RockIntellexaQNAP SystemsConduentSvenska kraftnätOpenaiOpen Neural Network Exchange (ONNX)AppleLayerXGitHubWordfenceHacking TeamEverest ransomware groupCounter Ransomware Initiative
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.