ai

VSCode IDE Forks Expose Users to “recommended extension” Attacks

Forks of VSCode IDEs like Cursor and Google Antigravity recommend non-existent extensions from OpenVSX, risking malware exploitation as attackers can claim unregistered namespaces. Koi Security researchers reported the flaw; Cursor fixed it, and Google removed 13 recommendations. Users should verify extensions directly on OpenVSX to ensure safety.

https://www.bleepingcomputer.com/news/security/vscode-ide-forks-expose-users-to-recommended-extension-attacks/

Murder-suicide Case Shows OpenAI Selectively Hides Data After Users Die

OpenAI is being accused of concealing crucial ChatGPT logs during legal proceedings related to a murder-suicide case involving Stein-Erik Soelberg and his mother, Suzanne Adams. The family claims Soelberg's mental health deteriorated after engaging with ChatGPT, which allegedly fueled delusional beliefs about his mother. Despite evidence from shared logs, OpenAI has refused to provide full access to discussions that could shed light on Soelberg's state of mind leading up to the tragedy. The lawsuit argues that OpenAI's data policies, particularly regarding deceased users, lack transparency and accountability, exacerbating the family's grief and hindering their ability to understand the events.

https://arstechnica.com/tech-policy/2025/12/openai-refuses-to-say-where-chatgpt-logs-go-when-users-die/

Pen Testers Accused of ‘blackmail’ Over Eurostar AI Flaws

Pen testers identified four significant flaws in Eurostar's AI chatbot, allowing potential injection of malicious HTML and system prompts leakage. After initial reports were ignored, the team accused the company's security head of “blackmail” for following up. Eurostar later found the report and addressed some issues. The chatbot's poor design permits users to manipulate chat history and bypass security checks, leading to risks like data leaks and phishing attacks. The incident highlights the need for robust security in consumer-facing chatbots.

https://www.theregister.com/2025/12/24/pentesters_reported_eurostar_chatbot_flaws/

Robot Crime Could Be Rampant by 2035, Law Enforcement Warns

Europol warns of potential rampant robot crime by 2035 due to automation, predicting protests, riots, and hacking of AI-powered robots. The report highlights threats like drones used for attacks, urging police to prepare for criminal actions involving both humans and robots. While acknowledging some scenarios may be exaggerated, the warning illustrates the growing concerns about technology replacing humans in various sectors, leading to societal unrest.

https://www.vice.com/en/article/robot-crime-could-be-rampant-by-2035-law-enforcement-warns/

NIST, MITRE Announce $20 Million Research Effort on AI Cybersecurity

NIST and MITRE launch $20 million AI cybersecurity project, focusing on protecting critical infrastructure. Two centers established—one for manufacturing, another for AI-driven cybersecurity solutions for essential services like water and electricity. Aim: enhance U.S. tech, reduce adversarial risks, foster industry collaboration. Input from critical sectors emphasized for effective cybersecurity strategies.

https://cyberscoop.com/nist-mitre-announce-20-million-dollar-research-effort-on-ai-cybersecurity/

OpenAI Says AI Browsers May Always Be Vulnerable to Prompt Injection Attacks

OpenAI acknowledges AI browsers, like its Atlas, are perpetually at risk of prompt injection attacks, which manipulate AI to execute hidden malicious instructions. Despite efforts to enhance security, including a reinforcement learning-based automated attacker to identify flaws, prompt injections may never be fully mitigated, raising concerns about the safety of AI operation on the web. Ongoing layered defenses and user caution are recommended, yet the high access risk of these browsers poses a significant challenge.

https://techcrunch.com/2025/12/22/openai-says-ai-browsers-may-always-be-vulnerable-to-prompt-injection-attacks/

8 Million Users’ AI Conversations Sold for Profit by “Privacy” Extensions

TLDR: Over 8 million users' AI conversations have been harvested and sold for profit by the Urban VPN Proxy extension, which secretly captures data from platforms like ChatGPT and Claude. Despite claiming privacy, the extension transmits sensitive information to servers without user consent. It has passed Google’s reviews, misleading users about its data practices. Users are advised to uninstall it immediately to protect their private conversations.

https://www.koi.ai/blog/urban-vpn-browser-extension-ai-conversations-data-collection

Price of a ‘bot Army’ Revealed Across Hundreds of Online Platforms Worldwide

Cambridge's COTSI reveals global bot prices: A new index tracks fake account verification costs on 500+ platforms. Verifying fake accounts is notably cheap in the US (0.26), UK (0.10), and Russia (0.08), while pricier in Japan (4.93) and Australia (3.24). Prices surge for bots on Telegram and WhatsApp before elections, indicating manipulation intentions. The study emphasizes sim card regulation to curb bots and suggests transparency measures are often circumvented. It exposes a burgeoning underground market reliant on SIM products for orchestrating misinformation and influence campaigns globally.

https://www.cam.ac.uk/stories/price-bot-army-global-index

Does OpenAI Expect Upcoming AI Models to Present a High Cybersecurity Risk?

OpenAI acknowledges that its upcoming AI models will heighten cybersecurity risks, as more capable tools enable easier attacks for even those with basic knowledge. The release of GPT-5.2 introduces enhanced capabilities for professional use and better coding assistance. To combat potential misuse, OpenAI plans to establish the Frontier Risk Council and has launched the beta tool Aardvark to help organizations identify vulnerabilities. Overall, OpenAI aims to ensure its technologies are used safely while addressing both defense and offense in cybersecurity.

https://www.pandasecurity.com/en/mediacenter/does-openai-expect-upcoming-ai-models-to-present-a-high-cybersecurity-risk/

The 2025 Cloudflare Radar Year in Review- the Rise of AI, Post-quantum, and Record-breaking DDoS Attacks

Extreme TLDR: 2025 Cloudflare Radar reveals global Internet traffic rose 19%, driven by AI growth, Starlink doubling its traffic, and notable DDoS attacks. Key trends included 52% of Web traffic being post-quantum encrypted, 40% of bot traffic from the US, and Googlebot as the top traffic source. The Year in Review highlights shifts in popular services and connectivity issues, with significant growth in mobile and AI traffic.

https://blog.cloudflare.com/radar-2025-year-in-review/

Robot Safety Monitoring AI Market Reflects Growth at 21.2%

Robot Safety Monitoring AI market projected to grow from $2.7B in 2025 to $15.3B by 2034 (CAGR 21.2%). Norte America leads with >36.3% share. Enhances productivity, reduces workplace injuries, and creates jobs. Businesses face upfront costs but benefit from standardized safety solutions. Key sectors: manufacturing, logistics, automotive, healthcare. Future trends include predictive safety systems and increased automation. Strong demand for AI solutions in diverse industries, creating new business opportunities.

https://scoop.market.us/robot-safety-monitoring-ai-market-news/

AI Poisoning: Black Hat SEO Is Back

Black Hat SEO, once diminished by advancements in Google algorithms, is resurfacing through AI manipulation. Research shows just 250 malicious documents can contaminate large language models (LLMs), enabling bad actors to distort AI responses about brands. This “AI poisoning” risks misrepresenting companies in comparisons and could damage reputations. Brands must maintain vigilance by monitoring AI outputs related to their name and addressing suspicious online activity to prevent potential poisoning. Despite the temptation to exploit loopholes for a competitive edge, ethical content creation remains essential for long-term success.

https://www.searchenginejournal.com/ai-poisoning-black-hat-seo-is-back/561217/

New Advanced Phishing Kits Use AI and MFA Bypass Tactics to Steal Credentials at Scale

TLDR: New phishing kits like BlackForce, GhostFrame, InboxPrime AI, and Spiderman use advanced tactics, including AI and MFA bypass, to steal credentials at scale. BlackForce targets brands, GhostFrame hides in iframes, InboxPrime automates email campaigns, and Spiderman replicates bank pages for European targets. These innovations make phishing attacks easier to execute and more difficult to detect.

https://thehackernews.com/2025/12/new-advanced-phishing-kits-use-ai-and.html

Fighting Payment Fraud With AI

AI combats rising payment fraud effectively, adapting rapidly to evolving threats. Traditional fraud defenses struggle against sophisticated attacks, leading to increased false declines that harm customer loyalty. Businesses are turning to AI for more accurate, real-time fraud detection, which boosts legitimate transactions and reduces losses. AI-enabled systems analyze vast data for nuanced risk scoring, transforming fraud prevention into a strategic growth tool. Investing in AI is essential for safeguarding revenue and enhancing customer experience.

https://www.independent.co.uk/news/business/business-reporter/payment-fraud-ai-cyber-attacks-security-b2881360.html

‘Botnets in Physical Form’ Are Top Humanoid Robot Risk

Humanoid robots are becoming mainstream, prompting security concerns regarding potential botnets. With predictions of over 3 billion robots by 2060, experts warn of vulnerabilities, including exploits already identified in existing models. As these robots integrate into various sectors, the emergence of a new industry dedicated to their security is anticipated, emphasizing the need for robust protective measures against cyber threats.

https://www.theregister.com/2025/12/09/humanoid_robot_security/

Scroll to Top