惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
大猫的无限游戏
大猫的无限游戏
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 叶小钗
月光博客
月光博客
Last Week in AI
Last Week in AI
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
人人都是产品经理
人人都是产品经理
阮一峰的网络日志
阮一峰的网络日志
罗磊的独立博客
IT之家
IT之家
美团技术团队
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Hugging Face - Blog
Hugging Face - Blog
博客园_首页
S
SegmentFault 最新的问题
宝玉的分享
宝玉的分享
博客园 - Franky
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Jina AI
Jina AI
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
The Cloudflare Blog
博客园 - 司徒正美
爱范儿
爱范儿

ThreatDown by Malwarebytes

This SonicWall bug is 2 years old. Akira ransomware is still exploiting it. | ThreatDown AI threat so great that security “takes precedence over everything except critical business operations”  | ThreatDown How Grok unknowingly powers cybercrime | ThreatDown 74% of organizations exposed to shadow AI | ThreatDown The guardrails problem just played out on both sides of the same incident | ThreatDown Prinz Eugen ransomware: a deep dive into a new Go-based encryptor - ThreatDown by Malwarebytes GachiLoader adopts AI skill lure - ThreatDown by Malwarebytes The Attacks Hiding in Your Identity Logs - ThreatDown by Malwarebytes The identity nobody is watching - ThreatDown by Malwarebytes Weaponizing autonomy: The rise of malicious AI agent skills Why identity-based threats are the new battleground for cybersecurity CastleRAT attack first to abuse Deno JavaScript runtime to evade enterprise security 100% malware detection at 1.7% CPU: how ThreatDown stops Mac info stealers Machine-scale cybercrime: The 2026 State of Malware report How to prevent a rootkit attack The anatomy of an Akira ransomware attack AI-orchestrated cyberattacks Tracking remote ransomware attacks at their source Inside EDR-Freeze: How ThreatDown stops the attack before it spreads
The AI era of cybercrime has arrived: The 2026 Cybercrime...
Luke T. · 2026-07-21 · via ThreatDown by Malwarebytes

New research reveals how AI is rewiring cybercrime today, and how you can prepare for what’s coming tomorrow.

In early 2026, an attacker with no background in industrial control systems set their sights on a municipal water utility’s control systems in Monterrey, Mexico. They didn’t find the target themself. While they directed Claude through a broader reconnaissance operation, it identified the utility’s control interface without being asked, correctly flagged it as critical infrastructure, and recommended a targeted attack against it.

The attack ultimately failed, but it shouldn’t have gotten that far. It’s one thread in a much larger report we’re publishing today: Cybercrime in the age of AI.

Last year, we said this was coming—this year, it’s arrived. Three findings that prove it:

1. Criminals use the same frontier models as you. Some of the most active malicious AI tools now operate like ordinary software companies: pricing pages, login buttons, and checkout flows, all indexed by Google and available on the clearnet. When our researchers traced the infrastructure underneath them, a pattern emerged: these tools don’t build their own intelligence. They rent it, from providers already sitting on your own vendor list.

2. Malicious AI is moving offline. In July 2026, our researchers found over 6,000 models published openly on Hugging Face under self-declared guardrail-free labels: “abliterated,” “uncensored,” “heretic,” “decensored,” and “unfiltered,” implying they no longer refuse unsafe or harmful requests. These models were downloaded more than 22 million times in a single 30-day window, and run locally, they leave nothing to monitor, log, intercept, or restrict.

3. In April, a frontier AI model proved so good at finding vulnerabilities that its maker held it back rather than releasing it broadly. It’s exactly the kind of capability our report tracks moving toward criminal marketplaces next.

That’s what AI-powered cybercrime looks like today. What comes next is where it gets uncertain: the gap between organizations that are ready and organizations that aren’t is widening. There’s six months left to close it, and the clock favors the ones who move.

The full findings are live now. Read the report, then ask yourself the question we asked ourselves:

Which side of that six-month gap is your organization actually on?

Download the report