HollowFrame and Matryoshka use DLL side-loading and GitHub C2 to gain a persistent foothold on two law firm endpoints.
The intrusions happened through three Claude models: Opus 4.7, Mythos 5, and an internal research prototype. Opus 4.7, the ...
A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous ...
Perplexity's open-source Numbat watches AI coding agents on endpoints, adding detection and opt-in blocking after OpenAI's ...
Amazon threat researchers found one threat actor behind four distinct open source compromises, including the March 2026 ...