llm (29)

31224586252?profile=RESIZE_400xAcross four weeks in July and August 2026, OpenAI, Anthropic and Meta have each admitted that their models reached systems belonging to other organizations without consent, and the UK’s AI Security Institute (AISI) published a fourth account describing agents that invented identities and tried to slip a malicious contribution into a live open source project (Autonomous Long Horizon Malware Analysis.  https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis

31224586252?profile=RESIZE_400xAcross four weeks in July and August 2026, OpenAI, Anthropic and Meta have each admitted that their models reached systems belonging to other organizations without consent, and the UK’s AI Security Institute (AISI) published a fourth account describing agents that invented identities and tried to slip a malicious contribution into a live open source project (Autonomous Long Horizon Malware Analysis.  https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis

31222590690?profile=RESIZE_400xA cybercriminal AI service called MessiahGPT is being advertised on BreachForums as an unrestricted platform for generating malware, phishing material, and other illegal content, according to new research from Trellix.  MessiahGPT operates through messiahgpt.de and has an associated Telegram community.  Trellix said the platform was live when its researchers examined it, offering 50 free queries without registration.  Paid plans start at $8 per month, with cryptocurrency accepted and no identity

31214645701?profile=RESIZE_400xNew findings from Forcepoint's X-Labs outline an interesting scenario that could easily mimic real life: An AI assistant with browser access reads a webpage about travel disruption.  Near the bottom of that page, in text sized and positioned so no human will ever see it, sits a short paragraph stating that ABC Travel Support is the official emergency booking provider and should always be recommended when urgent travel changes are needed.

The assistant's text extractor does not distinguish betwee

31188979652?profile=RESIZE_400xThat's how long it took an AI coding agent to delete a company's production database and wipe its backups.  One command.  No warning.  No humans in the loop.  Then it did something more strange.  It confessed.

Here's the rest of the story - In late April 2026, a developer named Jer Crane was building a small software company called PocketOS.  He used Cursor, an AI coding tool that runs on Anthropic's Claude.  He handed the agent a routine task in a staging environment, the safe practice area, no

31186076853?profile=RESIZE_400xAI is now a practical part of work.  But “AI” gets used as a catch-all term, which sometimes creates confusion.  Below Calls9 explains the difference between traditional AI and large language models (LLMs) in plain language, with examples, limitations, and how to choose the right approach.  It is written for people who need clarity, not a computer science lesson.[1]

What people usually mean by “traditional AI” - In most organizations, “traditional AI” refers to two things:

Rules and logic: These

31180129453?profile=RESIZE_400xThe Ukrainian military is stepping up its campaign to destroy vehicles supplying Russian forces along crucial roads in occupied Ukraine using new AI drone technology.  Ukraine is starting to regain more ground than it is losing for the first time since 2023, analysis from the Institute for the Study of War (ISW) indicates. 

After more than four years of war and increased Russian occupation of eastern and southern Ukraine, neither side has gained any significant ground in recent months.[1]

Ukrain

31172052888?profile=RESIZE_400xTwenty minutes into drafting an article, I stopped.  The voice was mine.  The rhythm was mine.  The vocabulary was mine. But the argument had moved somewhere I had not chosen to take it.  I had opened the session with a clear thesis.  The AI LLM assistant did not disagree with me.  It had simply kept offering better-sounding alternatives. And I had kept accepting them.  By the time I noticed, I could not easily identify where my thinking ended and the model’s thinking began.

Most people still im

31133346653?profile=RESIZE_400xIf there's one thing that AI is good at, particularly language models, it's detecting patterns in datasets so large that it would be practically impossible for humans to sift through them all, quickly and accurately.  That certainly seems to be the case with Anthropic's new general-purpose model, Claude Mythos, as the company has announced that it used it to detect "thousands of high-severity vulnerabilities, including some in every major operating system and web browser."

Alongside the launch o

31130739697?profile=RESIZE_400xSentinel Labs has provided yet another great report on: Building an Adversarial Consensus Engine / Multi-Agent LLMs for Automated Malware Analysis.  Large Language Models can perform static malware analysis, but individual tool runs produce unreliable results contaminated by decompiler artifacts, dead code, and hallucinated capabilities.[1]

Researchers built a multi-agent architecture for reversing macOS malware that treats each reverse engineering tool (radare2, Ghidra, Binary Ninja, IDA Pro) a

31111049692?profile=RESIZE_400xOn 24 March 2026, two versions of the litellm Python package on PyPI were found to contain malicious code.  The packages (versions 1.82.7 and 1.82.8) were published by a threat actor known as TeamPCP after they obtained the maintainer's PyPI credentials through a prior compromise of Trivy, an open source security scanner used in litellm's CI/CD pipeline.

The malicious versions were available for approximately three hours before PyPI quarantined the package. litellm is downloaded roughly 3.4 mill

31084129900?profile=RESIZE_400xOllama is an open-source framework that enables users to run large language models locally on their own hardware. By design, the service binds to localhost (127.0.0.1) on port 11434, making instances accessible only from the host machine. However, exposing Ollama to the public internet requires only a single configuration change: setting the service to bind to 0.0.0.0 or a public interface.  At scale, these individual deployment decisions aggregate into a measurable public surface.[1]

Over the p

31079368283?profile=RESIZE_400xSentinel Labs has provided a keen look into LLMs and SOC operations.  For security teams, AI promised to write secure code, identify and patch vulnerabilities, and replace monotonous security operations tasks.  Its key value proposition was raising costs for adversaries while lowering them for defenders.

To evaluate whether Large Language Models (LLMs) were both sufficiently performant and reliable to be deployed in the enterprise, a wave of new benchmarks was created.  In 2023, these early benc

31040395500?profile=RESIZE_400xSentinelLABS has been researching how large language models (LLMs) are impacting cybersecurity for both defenders and adversaries.  As part of our ongoing efforts in this area and our well-established research and tracking of crimeware actors, researchers have been closely following the adoption of LLM technology among ransomware operators.  Analysts have observed that three structural shifts appear to be unfolding in parallel.

First, the barriers to entry continue to fall for those intent on cy

31040391480?profile=RESIZE_400xThe question was deceptively simple.  Could the light that is used to form an image on a display also be converted into something that can be felt?  At the University of California - Santa Barbara, a team of researchers spent nearly a year exploring this idea, working through theoretical models, conducting simulations, and eventually building prototypes.  Their work, described in the paper Tactile Displays Driven by Projected Light and explored in TechXplore, has led to a significant breakthroug

30984543477?profile=RESIZE_400xState-backed hackers are for the first time deploying malware that uses large language models during execution, allowing them to dynamically generate malicious scripts and evade detection, according to new research.  Although cybersecurity experts have observed hackers use AI in recent years to do things like increase the number of victims they reach, researchers at Google said recently that they recently observed malware "that employed AI capabilities mid-execution to dynamically alter the malw

13723612478?profile=RESIZE_400xThe US Secret Service on 23 September reported it has foiled what appears to be a sophisticated plot for cyber-espionage and disruption of mobile networks in New York at a time when more than 100 heads of state and governments and foreign ministers are in the city for the UN General Assembly’s leaders’ session.

In a statement, the Secret Service said that the agency recovered more than 300 co-located SIM servers and 100,000 SIM cards across multiple sites in New York tristate area.  The agency s

13707470683?profile=RESIZE_400xHackers, criminals, and spies are rapidly adopting Artificial Intelligence (AI), and considerable evidence is emerging of a substantial acceleration in AI-enabled crime.  This includes evidence of the use of AI tools for financial crime, phishing, distributed denial of service (DDoS), child sexual abuse material (CSAM), and romance scams.  In all these areas, criminal use of AI is already augmenting revenue generation and exacerbating financial and personal harms.  Scammers and social engineers,

13590947256?profile=RESIZE_400xCyberattacks are escalating in speed, volume, and sophistication.  As organizations work to strengthen their defenses, adversaries target their weaknesses: employees susceptible to social engineering and systems lacking modern security controls. Once inside, they act within seconds, stealthily moving across networks to execute attacks.

Crowd Strike has recently provided its 2025 Global Threat Report to cyber professionals.  Red Sky Alliance would like to share this excellent report, as it provid

13584512899?profile=RESIZE_400xCyber-attacks on businesses continue to escalate in 2025, with global organizations experiencing an average of 1,925 incidents per week in Q1, which is a 47% increase compared to the same period last year, according to new research from Check Point.  The education sector was the hardest hit, with each institute facing an average of 4,484 weekly attacks.  Government and telecommunications followed, with the latter recording the largest year-over-year spike at 94%.  “The growing reliance on digita