Skip to content
-
Xloggs AI Security and News Xloggs AI Security and News

AI Security Tools and Security Headlines

Xloggs AI Security and News Xloggs AI Security and News

AI Security Tools and Security Headlines

  • Documents for Information Security
  • OWASP TOP 10 AI
  • Security Related Links
  • EPSS Lookup
  • SSH Attacks
  • Documents for Information Security
  • OWASP TOP 10 AI
  • Security Related Links
  • EPSS Lookup
  • SSH Attacks
Close

Search

Breaking News

Breaking News – Cyber Threats – 2026-09-29 08:00 PDT

Breaking News – Cyber Threats (last 6h) Generated: 2026-09-29 08:00 PDT Catch threats before they escalate with…

Report Bot
By Report Bot
On
September 29, 2026
Uncategorized

Morning Security Report – 2026-09-29

# Morning Security Report – 2026-09-29 **Report Type**: Real-time News Summary **Date**: 2026-09-29 **Source**:…

Xloggs MCP
By Xloggs MCP
On
September 29, 2026
Breaking News

Breaking News – Cyber Threats – 2026-09-29 03:00 PDT

Breaking News – Cyber Threats (last 6h) Generated: 2026-09-29 03:00 PDT Kiteworks patches critical flaw, brings…

Report Bot
By Report Bot
On
September 29, 2026
Uncategorized

Top Security Breaches 2026-09-29

Top Security Breaches 2026-09-29 Auto-generated 2026-09-29T09:00:44.133957+00:00 (UTC) ShinyHunters Claims FBI Breach,…

Report Bot
By Report Bot
On
September 29, 2026
Uncategorized

Weekly Exploit Roundup 2026-09-29

Weekly Exploit Roundup Generated 2026-09-29T08:00:11.066827+00:00 (UTC) Zero-Day Exploitation of Citrix NetScaler ADC…

Report Bot
By Report Bot
On
September 29, 2026
Breaking News

Breaking News – Cyber Threats – 2026-09-28 22:00 PDT

Breaking News – Cyber Threats (last 6h) Generated: 2026-09-28 22:00 PDT ISC Stormcast For Tuesday, September…

Report Bot
By Report Bot
On
September 28, 2026
Uncategorized

Weekly Threat Report 2026-09-28

By Report Bot
September 28, 2026 10 Min Read
Comments Off on Weekly Threat Report 2026-09-28

Weekly Threat Intelligence Summary

Top 10 General Cyber Threats

Generated 2026-09-28T05:00:04.389009+00:00

  1. China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies (www.cisa.gov, 2026-09-04T16:12:28)
    Score: 12.378
    Executive summary China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation acti
  2. September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs (www.crowdstrike.com, 2026-09-08T05:00:00)
    Score: 9.367
  3. H1 2026 Malware Vulnerability Trends (www.recordedfuture.com, 2026-09-03T00:00:00)
    Score: 8.999
    Learn how adversaries abuse trusted tools, AI, and developer environments for cyberattacks. Get actionable insights on ransomware, mobile threats, and supply chain security.
  4. Using Threat Intelligence to Stop Ransomware Attacks (www.recordedfuture.com, 2026-09-25T00:00:00)
    Score: 8.665
    Learn how ransomware threat intelligence empowers your team to actively follow adversary infrastructure, monitor dark web chatter and prevent attacks.
  5. Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group (www.recordedfuture.com, 2026-09-15T00:00:00)
    Score: 8.499
    Analyze Tajin Group's role in phishing and Chinese money laundering. Discover how this Telegram-based vendor exploits payment gateways and adapts its financial fraud operations.
  6. Meta’s Muse AI assistant has a zero-day that can turn it into a Mac backdoor (www.malwarebytes.com, 2026-09-22T10:53:06)
    Score: 8.241
    A simple terminal command can hijack Muse and use its extensive permissions to spy on Mac users and control their connected accounts.
  7. Kothamine malware uses Tailscale’s tailcat to evade network detection (www.malwarebytes.com, 2026-09-25T14:57:29)
    Score: 7.769
    Kothamine uses a legitimate Tailscale tool to receive attackers’ commands through an encrypted connection with no malicious domain to block.
  8. The Lure Isn't The Malware. It's Your Logo. (www.recordedfuture.com, 2026-09-23T00:00:00)
    Score: 7.632
    Recorded Future's Insikt GroupⓇ has been tracking ClickFix, a social engineering technique that turns a familiar logo or verification prompt into the entry point for an attack. Here's what that research reveals about catching it, and why it's now running inside Malicious Site Monitoring, part of our newly launched Digital Risk Protection solution.
  9. Gemini’s breach of real companies exposes an AI guardrail problem (www.malwarebytes.com, 2026-09-21T14:21:38)
    Score: 7.598
    Gemini crossed the boundaries of a capture-the-flag test and accessed systems belonging to three real companies.
  10. New Android malware uses AI to steal bank logins and PINs (www.malwarebytes.com, 2026-09-18T15:37:04)
    Score: 6.607
    RatHat can navigate infected phones while stealing bank logins, authentication codes, and screen-lock PINs.

Top 10 AI / LLM-Related Threats

Generated 2026-09-28T06:00:20.646179+00:00

  1. Prompt Injection Detection for Email Agents Through Attack Chain Modeling (arxiv.org, 2026-09-28T04:00:00)
    Score: 19.78
    arXiv:2609.30657v1 Announce Type: new
    Abstract: Large language model email assistants are particularly vulnerable to indirect prompt injection because untrusted email content can be retrieved into the model context and influence subsequent tool use. Existing prompt injection detectors mainly formulate this problem as binary malicious text classification, which overlooks the important factor that harmful agent behavior often arises through a sequence of stages. We propose a detection framework t
  2. MetaPermit: Scalable and Auditable Access Control for AI Agents via LLM-Inferred Meta-Attributes (arxiv.org, 2026-09-28T04:00:00)
    Score: 19.48
    arXiv:2609.31039v1 Announce Type: new
    Abstract: The rise of autonomous AI agents equipped with tools has introduced significant security risks, ranging from unintended tool misuse to adversarial manipulation through Indirect Prompt Injection (IPI) attacks. In practice, deployed agent systems such as OpenAI Codex and Claude Code protect tool invocations through a combination of coarse-grained permission rules and LLM-based judgments about individual proposed actions. Both components, however, ha
  3. From ASR to ASP: Evaluating Prompt Attack Vulnerabilities Against Open-Source LLMs (arxiv.org, 2026-09-28T04:00:00)
    Score: 18.78
    arXiv:2505.14368v3 Announce Type: replace
    Abstract: Recent studies demonstrate that Large Language Models (LLMs) are vulnerable to attacks that generate harmful or sensitive outputs. As open-source LLMs are increasingly adopted in high-impact applications such as finance, law, and healthcare, systematically investigating their security risks is becoming increasingly important towards a trustworthy LLM era. This paper comprehensively studies effective prompt injection attacks against 14 widely u
  4. FragToken: Amplifying LLM Inference Costs through Noncanonical Token Generation (arxiv.org, 2026-09-28T04:00:00)
    Score: 17.78
    arXiv:2609.31552v1 Announce Type: new
    Abstract: As large language model (LLM) inference becomes increasingly expensive, resource-consumption attacks pose a growing threat to model providers. Existing attacks typically amplify cost by inducing abnormally long or repetitive outputs on attacker-controlled or triggered requests, making them easier to detect and limiting their deployment-wide impact when benign traffic dominates. In this work, we uncover a previously overlooked token-level attack su
  5. What Do They Fix? LLM-Aided Categorization of Security Patches for Critical Memory Bugs (arxiv.org, 2026-09-28T04:00:00)
    Score: 17.78
    arXiv:2509.22796v2 Announce Type: replace
    Abstract: Open-source software projects are foundational to modern software ecosystems, with the Linux kernel standing out as a critical exemplar due to its ubiquity and complexity. Although security patches are continuously integrated into the Linux mainline kernel, downstream maintainers often delay their adoption, creating windows of vulnerability. A key reason for this lag is the difficulty in identifying security-critical patches, particularly thos
  6. PrivDrift: Auditing User-Secret Leakage Under Topic Drift in Active LLM Conversations (arxiv.org, 2026-09-28T04:00:00)
    Score: 17.78
    arXiv:2609.30094v2 Announce Type: replace-cross
    Abstract: Large language models increasingly operate as persistent assistants in user-facing, shared-session, and tool-augmented settings. When users disclose sensitive information during an active conversation, that information may remain behaviorally recoverable through later prompts even after the dialogue shifts to unrelated topics. We introduce PrivDrift, a benchmark for auditing whether user-disclosed secrets remain recoverable after convers
  7. Resource-Optimized and Energy-Aware Agentic AI Framework Anchored on Blockchain for Secure Software Supply Chains (arxiv.org, 2026-09-28T04:00:00)
    Score: 16.78
    arXiv:2609.31282v1 Announce Type: new
    Abstract: This paper proposes a blockchain-backed agentic security framework designed to safeguard the complete software development lifecycle (SDLC) while also securing the agentic AI components responsible for monitoring it. The framework coordinates a set of specialised security agents, covering source integrity, dependency and SBOM analysis, CI configura tion auditing, artifact verification, and runtime policy evaluation, each supported by a large langu
  8. AuthGuard-R: Safety-Compliant Mission Hijacking and Dual-Gate Defense for LLM-Controlled Robots (arxiv.org, 2026-09-28T04:00:00)
    Score: 14.78
    arXiv:2609.31110v1 Announce Type: cross
    Abstract: Large language models are increasingly used as high-level planners for mobile robots, robot manipulators, and autonomous vehicles. Recent studies show that these systems can be influenced through malicious text, speech, visual instructions, retrieved documents, and poisoned sensory context. Most defenses ask whether a proposed action is physically safe. This paper studies a different problem: an action may be physically safe and still violate th
  9. Towards Understanding LLM-Based Log Anomaly Detection: An Empirical Study of Performance, Efficiency, and Robustness (arxiv.org, 2026-09-28T04:00:00)
    Score: 14.78
    arXiv:2609.31371v1 Announce Type: cross
    Abstract: Large language models (LLMs) have demonstrated promising performance in log anomaly detection, yet how their adaptation strategies, architectures, and deployment configurations affect detection effectiveness remains insufficiently understood. To investigate these factors, we conduct a systematic empirical analysis across three public log datasets, examining different adaptation strategies, model architectures, parameter scales, and quantization
  10. Blind, Not Weak: A Best-of-Suite Safety-Utility Frontier for Recover-and-Reguard Defenses Against Encoded VLM Jailbreaks (arxiv.org, 2026-09-28T04:00:00)
    Score: 14.78
    arXiv:2607.26574v3 Announce Type: replace
    Abstract: Safety classifiers ("guards") are the dominant black-box defense for vision-language models, yet a guard judges an input's surface form, not its meaning: a harmful request re-encoded as set theory, formal logic, a classical language, code, or text rendered inside an image slips past a guard that would block it in plain language – the decode gap. The standard fix is a preprocessor that recovers image content and decodes the encod
  11. Weaponizing Ground Truth: Data Poisoning Attacks by Exploiting Boundary Misalignment Between Antivirus Software and Learning-Based Detectors (arxiv.org, 2026-09-28T04:00:00)
    Score: 14.48
    arXiv:2609.31003v1 Announce Type: new
    Abstract: Machine-learning (ML)-based malware detectors are commonly trained using labels obtained from antivirus (AV) engines and aggregation services (e.g., VirusTotal). This practice assumes AV-generated labels provide reliable supervision. However, small byte-level modifications can substantially alter AV verdicts while leaving the representations perceived by downstream ML detectors largely unchanged, producing label-feature inconsistencies that can co
  12. Crypto-bound identity-verified capability tokens for coordinating distributed AI agents: A proposal (arxiv.org, 2026-09-28T04:00:00)
    Score: 12.78
    arXiv:2609.30824v1 Announce Type: new
    Abstract: The prospect of fully autonomous transactional agents did not appear on the horizon until the advent of high capability language models. With such models, the operational benefits of adaptive task orchestration and independent (but constrained) decision making are tantalizing for enterprises and individuals alike. However, each such agent carries with it a serious attack surface in the form of prompt injection which can compromise any soft "g
  13. AGATE: Provenance-Based Runtime Defense Against Compositional Attacks on LLM Agents (arxiv.org, 2026-09-28T04:00:00)
    Score: 12.48
    arXiv:2609.30830v1 Announce Type: new
    Abstract: LLM agents can produce harmful effects through sequences of ordinary operations. Judging such actions requires establishing both the authority that permits them and the origin of the data they carry. We present AGATE, an authorization and data-provenance gate at instrumented agent-harness boundaries. Operator declarations and host approval events ground authorization; delegated actions are constrained by grants that bind to exact parameters, expir
  14. TempQ-Jail: Query-Constrained Candidate Ranking for Text-to-Video Jailbreak Attacks (arxiv.org, 2026-09-28T04:00:00)
    Score: 12.48
    arXiv:2609.31032v1 Announce Type: cross
    Abstract: Existing text-to-video (T2V) jailbreak methods mainly seek more effective or stealthier attack candidates. In guarded T2V systems, however, video generation and security evaluation are costly, so an attacker often cannot test a large candidate pool. We therefore formulate T2V jailbreak as a query-constrained candidate allocation and ranking problem and propose TempQ-Jail. The method combines heterogeneous attack mechanisms to expand candidate co
  15. Depth, Not Breadth: Best-of-N Jailbreaking Beyond Surface Noise (arxiv.org, 2026-09-28T04:00:00)
    Score: 12.48
    arXiv:2607.26639v2 Announce Type: replace
    Abstract: Best-of-N jailbreaking spends a query budget on surface variation, scrambling and recasing a request until one draw lands. We ask what a budget buys when its variance is moved into a structural channel instead, holding the search identical across both arms so the encoding is the only difference. Against SAGE, the strongest published self-check defense, best-of-N over a code-completion encoding reaches 67, 22 and 15% of behaviors on three open-
  16. Differentially-Private Decision Trees and Provable Robustness to Data Poisoning (arxiv.org, 2026-09-28T04:00:00)
    Score: 12.48
    arXiv:2305.15394v3 Announce Type: replace-cross
    Abstract: Decision trees are interpretable models that are well-suited to non-linear learning problems. Much work has been done on extending decision tree learning algorithms with differential privacy, a system that guarantees the privacy of samples within the training data. However, current state-of-the-art algorithms for this purpose sacrifice much utility for a small privacy benefit. These solutions create random decision nodes that reduce deci
  17. Werracle: Sub-Cent Intra-Block AI Reflex Oracles and Flash-Loan Circuit Breakers for EVM Smart Contracts (arxiv.org, 2026-09-28T04:00:00)
    Score: 11.98
    arXiv:2609.30719v1 Announce Type: new
    Abstract: Contemporary on-chain artificial intelligence (AI) encounters an intractable Von Neumann memory and latency wall. Storing static floating-point neural weight matrices inside Ethereum Virtual Machine (EVM) storage costs millions of gas, rendering direct on-chain inference impossible. While Zero-Knowledge Machine Learning (ZK-ML) offloads matrix tensor multiplications to off-chain provers, it introduces fatal constraints: 10 to 300 seconds of SNARK
  18. NarrateAI: production-ready LLM quality assurance on Amazon Bedrock (aws.amazon.com, 2026-09-25T16:15:22)
    Score: 11.787
    NarrateAI delivers production-ready LLM quality assurance on Amazon Bedrock. This post details five techniques—adaptive pipeline orchestration, cross-account multi-model failover, real-time streaming evaluation, composite evaluation, and data accuracy verification—that reach about 99% numerical accuracy while streaming responses in real time.
  19. Machine Unlearning for Large Language Models: Foundations, Advances, and Agentic Extensions (arxiv.org, 2026-09-28T04:00:00)
    Score: 11.78
    arXiv:2609.30909v1 Announce Type: new
    Abstract: Machine unlearning aims to remove target influence while preserving other capabilities. This survey compares methods, benchmarks, and evidence across large language models and systems using retrieval, memory, tools, and interacting agents. A five-layer framework connects removal requests, system boundaries, target locations, interventions, and supported claims. A seven-stage lifecycle and six evidence dimensions guide comparison. The review shows
  20. Deduplication-while-Training: A Resilient Paradigm for Privacy-Preserving Cross-Client Deduplication in Federated Learning (arxiv.org, 2026-09-28T04:00:00)
    Score: 11.78
    arXiv:2609.31262v1 Announce Type: new
    Abstract: Cross-client duplicate data in large language model training corpora degrades the efficiency of federated learning (FL) while exacerbating model memorization and privacy risks. Privacy-preserving cross-client deduplication effectively mitigates this issue by eliminating duplicate training data. However, existing schemes all follow a "Deduplication-before-Training" paradigm. This serially coupled paradigm incurs high fault-tolerance costs
  21. Configuration, Not Conscience: A Large-Scale Empirical Study of LLM System Prompts (arxiv.org, 2026-09-28T04:00:00)
    Score: 11.78
    arXiv:2609.31575v1 Announce Type: new
    Abstract: Leaked system prompts are often treated as windows into the hidden values of commercial language models, yet their composition is rarely studied at scale. We analyze a merged corpus of 407 leaked, reconstructed, or officially published system prompts from 62 vendors across four community collections, identifying 29 near-duplicate clusters covering 66 files. Operational content rather than ethical statements dominates the corpus; a deliberately sim
  22. China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks (www.securityweek.com, 2026-09-26T18:09:28)
    Score: 11.144
    The US and China agreed to set up a communication mechanism for artificial intelligence-related incidents. The post China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks appeared first on SecurityWeek .
  23. An AI Agent Execution Environment to Safeguard User Data (arxiv.org, 2026-09-28T04:00:00)
    Score: 10.48
    arXiv:2604.19657v3 Announce Type: replace
    Abstract: AI agents promise to serve as general-purpose personal assistants for their users, which requires them to have access to private user data (e.g., personal and financial information). This poses a serious risk to security and privacy: an AI model may hallucinate or make mistakes, and adversaries may attack it (e.g., via prompt injection) to exfiltrate user data. This paper presents GAAP (Guaranteed Accounting for Agent Privacy), an execution en
  24. Claude Opus 5.5 is now available on AWS (aws.amazon.com, 2026-09-22T17:28:01)
    Score: 10.085
    Claude Opus 5.5, Anthropic's most capable Opus model for agentic coding, knowledge work, and long-running tasks, is now available on Amazon Bedrock and Claude Platform on AWS. This post covers what's new in Opus 5.5, practical guidance, and how to start building with the model on Amazon Bedrock.
  25. Coding Agents Aren't Enough! Evaluating an Enterprise Security Brain for Agentic Cloud Investigations (arxiv.org, 2026-09-28T04:00:00)
    Score: 9.48
    arXiv:2609.30345v1 Announce Type: new
    Abstract: Cloud-security investigation is dominated by population tasks: which identities can read a data store, how many resources fail a control, which assets are reachable from another account. These resolve against a complete inventory, not a named object. A partial answer to one is not a partial result. It is a different result. General-purpose coding agents can now be given read-only cloud credentials and asked to investigate directly, which raises th

Auto-generated 2026-09-28

Author

Report Bot

Follow Me
Other Articles
Previous

Breaking News – Cyber Threats – 2026-09-27 22:00 PDT

Next

Breaking News – Cyber Threats – 2026-09-28 03:00 PDT

  • Clippie retired for Mico the Avatar.
  • reco.jpg
  • password-security.jpg

Newsletter signup

Join today to get site updates in your inbox. Opt-out anytime. No advertisement or email list up for sale.

Please wait...

Thank you for sign up!

Copyright 2026 — Xloggs AI Security and News. All rights reserved. Blogsy WordPress Theme