APT28 uses LLM-powered malware LAMEHUG against Ukraine's security and defence sector
CERT-UA reports that the threat group UAC-0001 (APT28) distributed phishing emails to Ukrainian executive bodies, impersonating a ministry representative. The emails contained a malicious attachment that deployed LAMEHUG, a Python-based tool which uses the Qwen 2.5-Coder-32B-Instruct large language model via Hugging Face to generate commands for data collection and exfiltration. The malware gathered system information and searched for Microsoft Office, TXT and PDF documents in common user directories, exfiltrating them via SFTP or HTTP POST requests.
- Company involved
- UAC-0001 (APT28)
- AI system involved
- LAMEHUG
2 source articles · read the reporting →
AI voice impersonation of WCPO meteorologist used in Facebook scam
A scammer created a fake Facebook account impersonating WCPO meteorologist Jennifer Ketchmark. The account uses AI voice impersonation software to send voice messages that sound like her, asking for money. WCPO warns the public not to engage with the account and to report it to Meta. No financial losses have been reported, but the scam poses a potential hazard.
1 source article · read the reporting →
341 Malicious ClawHub Skills Found Stealing OpenClaw User Data
Security researchers discovered 341 malicious skills on ClawHub, a marketplace for the OpenClaw AI assistant. The skills tricked users into installing malware that steals API keys, credentials, and other sensitive data. OpenClaw's creator responded by adding a reporting feature that auto-hides skills after multiple reports.
- Company involved
- OpenClaw
- AI system involved
- OpenClaw
4 source articles · read the reporting →
Fake Luma Dream Machine AI sites deliver Noodlophile infostealer
Cybercriminals set up Facebook pages impersonating Luma Dream Machine and linked to fake AI video generation websites. Users who uploaded images received an archive containing a malicious executable instead of a video. The executable launched a multi-stage attack that installed Noodlophile, which harvests browser credentials, cookies and cryptocurrency wallet information. Morphisec reported the campaign.
8 source articles · read the reporting →
AkiraBot spammed 80,000 websites with AI-generated messages
A Python framework called AkiraBot has spammed over 80,000 websites since September 2024, targeting small and medium-sized businesses. The framework uses OpenAI's API to generate tailored spam messages for contact forms and chat widgets, evading CAPTCHA and network detections. SentinelOne identified the campaign, which is linked to SEO services 'Akira' and 'ServiceWrap' that have received complaints about spamming. The campaign is expected to continue evolving.
- Company involved
- Akira
- AI system involved
- AkiraBot
4 source articles · read the reporting →
Companies face AI deepfake job candidates for remote roles
US companies report a surge in fake job seekers using generative AI tools to fabricate identities, employment histories, and conduct deepfake video interviews for remote positions. Cybersecurity firms Pindrop and CAT Labs, along with BrightHire, describe incidents where scammers, including North Korean operatives, attempted to gain employment to install malware, demand ransoms, steal data, or collect salaries fraudulently. One candidate, 'Ivan X', was detected by Pindrop's video authentication tool after a recruiter noticed his facial expressions were out of sync with his words.
- Company involved
- Pindrop Security
- AI system involved
- video authentication program
1 source article · read the reporting →
Facebook hired contractors to transcribe Messenger voice calls
Facebook hired contractors to listen to and transcribe select voice conversations made through its Messenger platform, without users' knowledge, in order to improve artificial intelligence. The practice was exposed by Bloomberg, prompting Facebook to pause the program. The Irish Data Protection Commission stated it was seeking details from Facebook on compliance with GDPR.
- Company involved
- Facebook
- AI system involved
- Messenger
10 source articles · read the reporting →
Stanford Researchers Find Over 1,000 LinkedIn Profiles Using AI-Generated Faces for Spam
Renée DiResta and Josh Goldstein of the Stanford Internet Observatory discovered over 1,000 LinkedIn accounts using AI-generated profile images to send sales pitches, bypassing LinkedIn's message limits. The fake accounts, which appeared to be real people, were used for corporate spamming rather than political disinformation. LinkedIn investigated and removed the violating accounts, stating that all profiles must represent real people.
4 source articles · read the reporting →
Deepfake video of Sam Bankman-Fried used in crypto phishing scam
A verified Twitter account posted a deepfake video of FTX founder Sam Bankman-Fried claiming to offer compensation to users of the collapsed exchange. The video directed viewers to a phishing website, ftxcompensation.com, that asked them to connect their crypto wallets and send funds with the promise of doubling them. The site's Ethereum address reportedly received over $1,000 in ETH. The account was later suspended.
10 source articles · read the reporting →
UIUC researchers use OpenAI API to automate phone scams for under a dollar
Researchers at the University of Illinois Urbana-Champaign used OpenAI's Realtime API to create AI agents that can autonomously execute phone scams. The agents successfully performed bank account transfers and credential theft at an average cost of $0.75 per scam. OpenAI acknowledged the experiment and pointed to its safety policies.
- Company involved
- University of Illinois Urbana-Champaign
- AI system involved
- GPT-4o Realtime API
6 source articles · read the reporting →
Gradient app charges users unexpected subscription fees after free trial
The Gradient app, a celebrity lookalike app promoted by the Kardashians, charges users $19.99 per month after a three-day free trial without clear disclosure. Users complained on social media about unexpected credit card charges. The app's developer, Ticket to the Moon, has not addressed the billing complaints but denied collecting user data.
- Company involved
- Ticket to the Moon, Inc.
- AI system involved
- Gradient
9 source articles · read the reporting →
Finnish recruitment company Digital Minds used AI to analyze job applicants' messages, prompting data protection investigation
Digital Minds, a Finnish recruitment company founded by psychologists, used IBM Watson AI to analyze job applicants' social media and email messages for personality assessments. The company obtained written consent but the Finnish Data Protection Ombudsman launched an investigation, suspecting violations of data protection laws and the secrecy of correspondence. The service was used on fewer than ten applicants and has been paused pending the investigation.
- Company involved
- Digital Minds
- AI system involved
- IBM Watson
9 source articles · read the reporting →
Attempted deepfake CEO voicemail fraud against an unnamed technology company
An attacker used synthetic audio deepfake to leave a voicemail impersonating the CEO of a technology company, asking an employee to call back to finalize an urgent business deal. The employee found it suspicious and referred the matter to the legal department, avoiding any loss. Nisos analyzed the audio and found inconsistencies in pitch and tone.
10 source articles · read the reporting →
ChatGPT falsely tells users OpenCage offers phone lookup service
OpenCage, a geocoding API provider, says ChatGPT has been telling people it offers a reverse phone number lookup service, which it does not. Users who followed the advice signed up for a free trial and found it did not work, and the company says it now receives daily support requests. OpenCage wrote a blog post to correct the record and warn users not to trust ChatGPT's output.
- AI system involved
- ChatGPT
7 source articles · read the reporting →
Company fires HR team after ATS auto-rejects manager's CV due to filtering error
A company's applicant tracking system (ATS) auto-rejected qualified candidates' resumes for three months because it was filtering for the outdated framework AngularJS instead of the required Angular framework. The manager discovered the flaw by submitting his own CV under a pseudonym and found it was rejected within seconds. After the manager reported the issue to upper management, the company investigated and dismissed half of its HR team. No legal action or regulatory involvement is reported.
4 source articles · read the reporting →
Facebook algorithm amplified troll farm content to 140 million US users before 2020 election
An internal Facebook report from October 2019 revealed that troll farms based in Kosovo and Macedonia were reaching 140 million US users per month through Facebook's content recommendation system. The algorithm pushed content from these pages to users who had not followed them, primarily targeting Christians, Black Americans, and Native Americans. Facebook acknowledged the issue but the underlying algorithm remained unchanged, and some troll farm pages were still active as of September 2021.
- Company involved
- Facebook
- AI system involved
- Facebook News Feed algorithm
9 source articles · read the reporting →
ScaleFactor reportedly failed to deliver promised automated bookkeeping software
ScaleFactor, an Austin-based startup, is reported to have failed to deliver the automated, real-time bookkeeping tools it promised customers, instead relying on human bookkeepers and a Filipino contract accounting firm. The company told Forbes in June that it was shutting down, initially blaming the pandemic, but Forbes later reported that its problems predated Covid-19. Investors reportedly came to see the company as more of a services business than a software platform, and pulled funding after a pivot to a marketplace model. No legal or regulatory action is reported.
- Company involved
- ScaleFactor
10 source articles · read the reporting →
Answer.AI tests Devin and reports 14 failures in 20 tasks
Answer.AI's team tested Devin, an autonomous AI coding assistant, on 20 real-world tasks over a month. Devin succeeded in only 3 tasks, failed 14, and was inconclusive in 3. The team found Devin often produced overly complex or hallucinated solutions and could not recognize fundamental blockers. They ultimately decided to stick with tools that allow more human control.
- AI system involved
- Devin
5 source articles · read the reporting →
WebinarTV secretly records Zoom calls and turns them into AI podcasts
WebinarTV, a company that bills itself as a search engine for webinars, is secretly scanning the internet for Zoom meeting links, recording the calls, and turning them into AI-generated podcasts for profit. People only found out their calls were recorded when WebinarTV contacted them to promote its services. The recordings may put call participants at risk.
- Company involved
- WebinarTV
4 source articles · read the reporting →
Presto Automation uses off-site human agents to double-check AI drive-thru orders
Presto Automation Inc, which markets an AI voice assistant for drive-thru ordering, used off-site human agents in countries including the Philippines to double-check orders in more than 70% of customer interactions, according to SEC filings reported by Bloomberg. The company told Bloomberg that the process helps train its system and should reduce human intervention over time. Presto's drive-thru AI is used in more than 400 restaurants, including Del Taco, Carl's Jr and Checkers, and its stock fell more than 10% after the reports.
- Company involved
- Presto Automation Inc.
8 source articles · read the reporting →
Chattr.ai exposed job applicant data due to insecure Firebase rules
A security researcher discovered that Chattr.ai, an AI hiring system used by many fast food chains, had a Firebase database with insecure security rules. By registering a new user, the researcher gained full read/write access to the database, exposing personal data of job applicants and employees, including names, phone numbers, emails, and some plaintext passwords. The vulnerability was reported to Chattr.ai on 9 January and patched the next day, but the company did not provide further contact or thanks.
- Company involved
- Chattr.ai
- AI system involved
- Chattr.ai
6 source articles · read the reporting →
N-Tech.lab's FindFace used to identify St Petersburg metro passengers without consent
Egor Tsvetkov photographed passengers on the St Petersburg metro without their permission and used N-Tech.lab's facial recognition service FindFace to match their faces to public Vkontakte profiles. He published the results in an art project called 'Your Face is Big Data', saying he wanted to show how 'digital narcissism' can lead to stalking. Privacy advocates said the project was ethically problematic because the subjects had not consented and their identities were exposed. FindFace had been launched by N-Tech.lab in February 2016.
- Company involved
- N-Tech.lab
- AI system involved
- FindFace
8 source articles · read the reporting →
EvenUp AI errors in personal injury demand letters lead to scrutiny
EvenUp, a legal tech startup valued at $1 billion, uses AI to draft personal injury demand letters. Former employees revealed that the AI system frequently makes errors, including missing injuries and fabricating medical conditions. The company defends its hybrid approach with human oversight, but critics allege overpromised AI capabilities.
- Company involved
- EvenUp
6 source articles · read the reporting →
Slack trains AI features on user messages and files by default
Slack uses user messages, files, and data to train its machine learning features such as channel recommendations and emoji suggestions. Users are opted in by default and cannot individually opt out; only workspace administrators can request exclusion via email. A user publicly criticized the practice, and Slack acknowledged the policy but did not change it.
- Company involved
- Slack
10 source articles · read the reporting →