惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
V
V2EX
小众软件
小众软件
WordPress大学
WordPress大学
Apple Machine Learning Research
Apple Machine Learning Research
Recent Announcements
Recent Announcements
有赞技术团队
有赞技术团队
MongoDB | Blog
MongoDB | Blog
C
Check Point Blog
S
Schneier on Security
C
Cybersecurity and Infrastructure Security Agency CISA
The Cloudflare Blog
V
Vulnerabilities – Threatpost
The Hacker News
The Hacker News
T
Threatpost
T
Tenable Blog
aimingoo的专栏
aimingoo的专栏
IT之家
IT之家
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
C
CERT Recently Published Vulnerability Notes
U
Unit 42
Spread Privacy
Spread Privacy
博客园 - 司徒正美
Hacker News: Ask HN
Hacker News: Ask HN
C
CXSECURITY Database RSS Feed - CXSecurity.com
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
阮一峰的网络日志
阮一峰的网络日志
SecWiki News
SecWiki News
云风的 BLOG
云风的 BLOG
The Register - Security
The Register - Security
AWS News Blog
AWS News Blog
月光博客
月光博客
Security Latest
Security Latest
H
Heimdal Security Blog
S
Secure Thoughts
博客园 - 聂微东
PCI Perspectives
PCI Perspectives
博客园 - 叶小钗
Scott Helme
Scott Helme
O
OpenAI News
Google DeepMind News
Google DeepMind News
Google DeepMind News
Google DeepMind News
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
S
Security @ Cisco Blogs
NISL@THU
NISL@THU
S
Securelist
Latest news
Latest news
P
Proofpoint News Feed
博客园 - 【当耐特】

Threat Intelligence – ThreatDown by Malwarebytes

Prinz Eugen ransomware: a deep dive into a new Go-based encryptor - ThreatDown by Malwarebytes CastleRAT attack first to abuse Deno JavaScript runtime to evade enterprise security Machine-scale cybercrime: The 2026 State of Malware report How to prevent a rootkit attack AI-orchestrated cyberattacks Inside EDR-Freeze: How ThreatDown stops the attack before it spreads EDR vs MDR vs XDR – What’s the Difference? KMSpico explained: No, KMS is not “kill Microsoft” When you shouldn’t trust a trusted root certificate - ThreatDown by Malwarebytes Ransomware in April 2025—RansomHub is gone Ransomware in March 2025
The AI era of cybercrime has arrived: The 2026 Cybercrime in the age of AI report | ThreatDown
Luke T. · 2026-07-21 · via Threat Intelligence – ThreatDown by Malwarebytes

New research reveals how AI is rewiring cybercrime today, and how you can prepare for what’s coming tomorrow.

In early 2026, an attacker with no background in industrial control systems set their sights on a municipal water utility’s control systems in Monterrey, Mexico. They didn’t find the target themself. While they directed Claude through a broader reconnaissance operation, it identified the utility’s control interface without being asked, correctly flagged it as critical infrastructure, and recommended a targeted attack against it.

The attack ultimately failed, but it shouldn’t have gotten that far. It’s one thread in a much larger report we’re publishing today: Cybercrime in the age of AI.

Last year, we said this was coming—this year, it’s arrived. Three findings that prove it:

1. Criminals use the same frontier models as you. Some of the most active malicious AI tools now operate like ordinary software companies: pricing pages, login buttons, and checkout flows, all indexed by Google and available on the clearnet. When our researchers traced the infrastructure underneath them, a pattern emerged: these tools don’t build their own intelligence. They rent it, from providers already sitting on your own vendor list.

2. Malicious AI is moving offline. In July 2026, our researchers found over 6,000 models published openly on Hugging Face under self-declared guardrail-free labels: “abliterated,” “uncensored,” “heretic,” “decensored,” and “unfiltered,” implying they no longer refuse unsafe or harmful requests. These models were downloaded more than 22 million times in a single 30-day window, and run locally, they leave nothing to monitor, log, intercept, or restrict.

3. In April, a frontier AI model proved so good at finding vulnerabilities that its maker held it back rather than releasing it broadly. It’s exactly the kind of capability our report tracks moving toward criminal marketplaces next.

That’s what AI-powered cybercrime looks like today. What comes next is where it gets uncertain: the gap between organizations that are ready and organizations that aren’t is widening. There’s six months left to close it, and the clock favors the ones who move.

The full findings are live now. Read the report, then ask yourself the question we asked ourselves:

Which side of that six-month gap is your organization actually on?

Download the report