Top stories.
- Threat actors move toward multi-agent AI frameworks.
- N-able issues emergency fix for maximum-severity flaw.
- Stealthy DPRK toolkit targets South Korean organizations.
Threat actors move toward multi-agent AI frameworks.
Google's Threat Intelligence Group (GTIG) has published a report on adversarial use of AI, finding that attackers "have moved beyond simple prompt-based LLM interactions to integrate AI capabilities into multiple stages of an attack lifecycle." In one incident observed by GTIG, a financially motivated attacker used AI agents to build and launch a mass credential-harvesting campaign in under six hours. The agents scanned for vulnerabilities, collected thousands of credentials, troubleshot failures, rotated IP addresses, and used compromised cloud infrastructure to evade detection.
Separately, researchers at Calif used advanced AI models to construct a self-propagating attack against WeChat in little more than a week, the New York Times reports. The proof-of-concept exploited a zero-day that could compromise an account via a call from a compromised contact, with no interaction required. The worm could then access messages, make calls, control the account, and automatically target saved contacts, potentially spreading exponentially across WeChat's user base. Tencent patched the vulnerability after Calif's responsible disclosure, saying it had no evidence users were affected.

