Skip to content Skip to sidebar Skip to footer

Protect AI Gateways and Agent Runtimes: Prevent Credential Theft, Cryptomining and VM Escapes

What Happened Two converging trends in 2026 make AI infrastructure a uniquely valuable attacker target: (1) adversaries are compromising AI gateways, retrieval/orchestration platforms and runtimes to steal provider credentials, establish persistence and monetize compute; and (2) advanced autonomous agents can discover and weaponize zero‑days to escape virtual machines and operate as APTs. Gateways and orchestration…

Read More

Stop Being Outpaced by AI‑Powered Attacks: Build a Network‑Enforced Control Plane to Reduce Exposure

What Happened Security research and vendor reports show two converging trends that change defensive priorities. First, the traditional disclosure → assess → patch cycle is no longer fast enough: attackers and AI tools compress exploitation timelines to hours while defenders still need days or weeks to validate and deploy fixes. That creates a widening asymmetric…

Read More

Why Your Development Toolchain Is the New Attack Surface — and How to Protect Models, Pipelines and SDLC Supply Chains

What Happened Security research and incident response teams report a clear shift in attacker focus: instead of primarily exploiting production application code, adversaries increasingly target the software development lifecycle (SDLC) — CI/CD pipelines, developer tools, artifact registries, and model training pipelines. Compromises in these areas let attackers insert malicious dependencies, steal secrets, backdoor models, or…

Read More

Stop Identity Abuse and Runtime Threats to AI: Practical Controls for Cloud, Kubernetes and LLM Workloads

What Happened Two themes dominate recent defensive research: attackers are exploiting trusted collaboration and identity channels to harvest credentials and tokens, and enterprise runtime gaps across cloud and Kubernetes are increasing exposure for workloads — including AI models and agentic components. Unit 42 documented identity abuse via trusted collaboration channels where impersonation, malicious…

Read More

Why Runtime-Centric Security Prevents AI, Container and Kubernetes Breaches

What Happened Industry research and vendor benchmarking show a clear shift: vulnerabilities become critical only when they are exposed and combined with misconfiguration, over‑permissioned identities and live runtime activity, so defenders are moving security controls down into runtime. Kubernetes now runs in roughly 82% of production environments, driving adoption of a single runtime security model…

Read More

Prevent Large-Scale Credential Theft and AI Model Exploits: Practical Defenses for Enterprises

What Happened Security teams continue to see credential compromises used as the primary vector for large-scale cloud intrusions and downstream attacks on AI systems. In one recent instance, threat actor "TheHatman" claimed to have exfiltrated a large volume of credentials from Microsoft Entra tenants; Unit 42 published an updated mitigation brief with detection, containment and…

Read More

Prevent Split‑View Key Attacks and ENS‑backed Botnets — Practical Defenses for AI, Messaging and IoT

What Happened Two recent pieces of defensive and offensive research illustrate threats that cross messaging, IoT and AI infrastructure: Trail of Bits built and runs one of Signal’s independent auditors that enforces Automatic Key Verification by signing Merkle‑tree heads and limiting a server’s ability to present split views to clients to seven days [1]. Separately,…

Read More

Protecting Enterprises from Blockchain-Based C2 and Modern Ransomware: Detection, Response and AI-Enabled Defenses

What Happened Decentralized C2 using blockchains (Aeternum) Security researchers analyzed Aeternum, a botnet loader that implements command-and-control (C2) and communication channels via smart contracts on the Polygon blockchain. By putting C2 metadata on-chain and using public RPC endpoints, operators gain persistence, redundancy and increased difficulty of takedown compared with traditional centralized C2 infrastructure [1]. Rust-based,…

Read More

Illustration for the Kimbodo News & Research briefing “Protect AI and Cloud Systems by Treating Identity as the Primary Attack Surface” (AI Security & Cybersecurity).

Protect AI and Cloud Systems by Treating Identity as the Primary Attack Surface

What Happened Unit 42's recent analysis shows that identity-based attacks are now the dominant entry vector: attackers exploit identities — user accounts, service principals, API keys, and tokens — as the "front door" into environments, and these attacks account for roughly 90% of incidents [1]. The report outlines common exploitation patterns and recommends SOC detection,…

Read More

Illustration for the Kimbodo News & Research briefing “How Supply‑Chain Worms and Token‑Jacking Steal AI Compute — and Practical Defenses for Your Production AI Stack” (AI Security & Cybersecurity).

How Supply‑Chain Worms and Token‑Jacking Steal AI Compute — and Practical Defenses for Your Production AI Stack

What Happened Recent incident analyses highlight two converging attack trends against AI and cloud development ecosystems: self‑propagating supply‑chain malware that harvests CI/CD credentials, and targeted theft of developer API keys to monetize AI compute. ChainDrop is an npm supply‑chain worm that infects packages and installers, extracts secrets from compromised GitHub Actions runners to…

Read More

Illustration for the Kimbodo News & Research briefing “AI Security & Cybersecurity — August 5, 2026” (AI Security & Cybersecurity).

AI Security & Cybersecurity — August 5, 2026

What Happened Recent defensive research and incident investigations expose three converging trends that matter for cloud, AI and developer security: CNAPP is being reframed as the unified control plane for cloud and AI risk, with risk‑based, multicloud attack‑path analysis and signal correlation across posture, runtime, identity, data, application and AI (Microsoft Defender for…

Read More

Illustration for the Kimbodo News & Research briefing “How to Stop Industrialized Zero‑Day Discovery and C2 Evasion: Practical Zero‑Trust + DevSecOps for AI Systems” (AI Security & Cybersecurity).

How to Stop Industrialized Zero‑Day Discovery and C2 Evasion: Practical Zero‑Trust + DevSecOps for AI Systems

What Happened Four recent findings change the security calculus for AI-driven systems and enterprise infrastructure. Expanded Zero Trust for AI: Microsoft released an AI‑focused Zero Trust Assessment and a DevSecOps Workshop that extends Zero Trust to AI, Security Operations and Infrastructure, adds 15 control groups (91 tasks) and introduces the AI Memory framework…

Read More