CYBERSECURITY
AI-Assisted Hacker Breached 600+ FortiGate Firewalls in 55 Countries in 5 Weeks
Amazon Threat Intelligence / BleepingComputer — Russian-speaking financially motivated actor with limited technical skills used commercial GenAI tools across the full attack lifecycle — tool development, credential stuffing, lateral movement. No CVEs exploited. Pure credential abuse + AI amplification. This is the democratization-of-cyberattack story in its clearest form yet.
AI / MALWARE
PromptSpy: First Known Android Malware to Use Generative AI at Runtime
BleepingComputer — PromptSpy calls Google's Gemini model during execution to adapt persistence behavior to the specific device it's running on. This is not AI-generated malware — the malware itself is AI-powered at runtime. First of its kind. Watch for copycat variants across iOS and desktop platforms.
VULNERABILITY
BeyondTrust CVE-2026-1731 (CVSS 9.9) Now Confirmed in Active Ransomware Campaigns
CISA / Palo Alto Unit 42 — Unit 42 tracked the exploitation chain from initial access through web shells, C2 deployment, lateral movement, and data exfiltration. Sectors hit: financial, legal, healthcare, higher education across US, France, Germany, Australia, Canada. Full ransomware pivot now confirmed by CISA.
CYBERCRIME
FBI: ATM Jackpotting Surge Cost Americans $20M+ in 2025
FBI / BleepingComputer — Malware-driven ATM cash-out attacks spiked significantly in 2025. Physical infrastructure crime is resurging alongside cyber extortion. Not a headline grab — signals organized crime diversifying revenue streams.
DATA BREACH
French Ministry of Finance Breach Exposes 1.2 Million Bank Registry Accounts
BleepingComputer — French government bank registry compromised. 1.2 million accounts. Government financial infrastructure is a tier-1 target — this breach's downstream identity fraud potential is high given the financial sensitivity of the data.