惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recent Commits to openclaw:main
Recent Commits to openclaw:main
P
Palo Alto Networks Blog
C
Cybersecurity and Infrastructure Security Agency CISA
C
Cisco Blogs
Cyberwarzone
Cyberwarzone
S
Schneier on Security
T
Threatpost
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Scott Helme
Scott Helme
T
Tor Project blog
P
Privacy & Cybersecurity Law Blog
V
Vulnerabilities – Threatpost
L
Lohrmann on Cybersecurity
T
The Exploit Database - CXSecurity.com
Know Your Adversary
Know Your Adversary
The Hacker News
The Hacker News
Security Latest
Security Latest
A
Arctic Wolf
P
Proofpoint News Feed
Google DeepMind News
Google DeepMind News
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Vercel News
Vercel News
WordPress大学
WordPress大学
美团技术团队
C
Cyber Attacks, Cyber Crime and Cyber Security
罗磊的独立博客
Microsoft Security Blog
Microsoft Security Blog
量子位
H
Help Net Security
Webroot Blog
Webroot Blog
月光博客
月光博客
S
SegmentFault 最新的问题
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Schneier on Security
Schneier on Security
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
IT之家
IT之家
H
Hacker News: Front Page
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Jina AI
Jina AI
云风的 BLOG
云风的 BLOG
J
Java Code Geeks
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Last Week in AI
Last Week in AI
C
CXSECURITY Database RSS Feed - CXSecurity.com
Spread Privacy
Spread Privacy
S
Security @ Cisco Blogs
博客园 - Franky
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
D
Darknet – Hacking Tools, Hacker News & Cyber Security

Threat Intelligence – ThreatDown by Malwarebytes

Prinz Eugen ransomware: a deep dive into a new Go-based encryptor - ThreatDown by Malwarebytes CastleRAT attack first to abuse Deno JavaScript runtime to evade enterprise security Machine-scale cybercrime: The 2026 State of Malware report How to prevent a rootkit attack AI-orchestrated cyberattacks Inside EDR-Freeze: How ThreatDown stops the attack before it spreads EDR vs MDR vs XDR – What’s the Difference? KMSpico explained: No, KMS is not “kill Microsoft” When you shouldn’t trust a trusted root certificate - ThreatDown by Malwarebytes Ransomware in April 2025—RansomHub is gone Ransomware in March 2025
The AI era of cybercrime has arrived: The 2026 Cybercrime in the age of AI report | ThreatDown
Luke T. · 2026-07-21 · via Threat Intelligence – ThreatDown by Malwarebytes

New research reveals how AI is rewiring cybercrime today, and how you can prepare for what’s coming tomorrow.

In early 2026, an attacker with no background in industrial control systems set their sights on a municipal water utility’s control systems in Monterrey, Mexico. They didn’t find the target themself. While they directed Claude through a broader reconnaissance operation, it identified the utility’s control interface without being asked, correctly flagged it as critical infrastructure, and recommended a targeted attack against it.

The attack ultimately failed, but it shouldn’t have gotten that far. It’s one thread in a much larger report we’re publishing today: Cybercrime in the age of AI.

Last year, we said this was coming—this year, it’s arrived. Three findings that prove it:

1. Criminals use the same frontier models as you. Some of the most active malicious AI tools now operate like ordinary software companies: pricing pages, login buttons, and checkout flows, all indexed by Google and available on the clearnet. When our researchers traced the infrastructure underneath them, a pattern emerged: these tools don’t build their own intelligence. They rent it, from providers already sitting on your own vendor list.

2. Malicious AI is moving offline. In July 2026, our researchers found over 6,000 models published openly on Hugging Face under self-declared guardrail-free labels: “abliterated,” “uncensored,” “heretic,” “decensored,” and “unfiltered,” implying they no longer refuse unsafe or harmful requests. These models were downloaded more than 22 million times in a single 30-day window, and run locally, they leave nothing to monitor, log, intercept, or restrict.

3. In April, a frontier AI model proved so good at finding vulnerabilities that its maker held it back rather than releasing it broadly. It’s exactly the kind of capability our report tracks moving toward criminal marketplaces next.

That’s what AI-powered cybercrime looks like today. What comes next is where it gets uncertain: the gap between organizations that are ready and organizations that aren’t is widening. There’s six months left to close it, and the clock favors the ones who move.

The full findings are live now. Read the report, then ask yourself the question we asked ourselves:

Which side of that six-month gap is your organization actually on?

Download the report