The AI agent swarm that attacked Hugging Face is a warning for the future
An army of AI agents was responsible for the Hugging Face incident. What does it mean for the future of AI?
Threat actors are targeting the AI attack surface to deliver malware and steal data. See how trusted AI tools are being exploited today.
Read full article at Huntress Blog ↗An army of AI agents was responsible for the Hugging Face incident. What does it mean for the future of AI?
During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files? A couple of months ago, I shared some stats about the trend in 64bits VS. 32bits malware[1]. Can we go a bit further? I (vibe-)coded a Python script based on the pefile library[2] to extract some info from the PE headers. Indeed, the PE file format contains a lot of metadata! They can be accessed using a lot of tools, like Detect It Easy:
It's 'built to be operated by a human with no technical background'
Dark Caracal has deployed GoCaracal, an upgraded variant of the Bandook toolkit, targeting a communications organization in Venezuela with novel command-and-control capabilities. The malware incorporates an Ethereum-based C2 fallback mechanism designed to maintain resilient communications even if primary command channels are disrupted. Arctic Wolf Labs researchers attribute the June 2026 intrusion to the Lebanon-linked espionage group, marking a continuation of their targeting of Venezuelan entities.