An AI agent executed a real-world ransomware attack for the first known time, but humans still handled crucial steps including victim selection, infrastructure setup, and credential theft.
Last week's headlines declared the first fully autonomous AI-powered ransomware attack. The details paint a more limited picture.
While an AI agent did carry out the technical execution, humans remained essential to the operation's success. A person selected the target organization, established the necessary infrastructure for the attack, and provided stolen credentials for initial access.
This distinction matters for understanding the actual threat landscape. The achievement demonstrates AI's capability in automating specific technical tasks within an attack chain. However, the operation still required human decision-making, planning, and prior reconnaissance work.
Cybersecurity experts note that relegating humans to preliminary roles still represents a meaningful development. It shows how threat actors could increasingly use AI to scale attacks and reduce the technical expertise needed. Yet calling it "fully autonomous" overstates current AI capabilities in cybercrime.
The reality suggests a hybrid model: humans directing strategy while AI handles execution—a pattern likely to become more common as the technology matures.
A critical remote code execution vulnerability affecting all Chromium versions is currently being exploited in the wild. The flaw bypasses the browser's sandbox protection, allowing attackers to execute arbitrary code with full system access.
Mullvad is discontinuing its public encrypted DNS servers and redirecting resources to sponsor Quad9, an alternative privacy-focused DNS provider. The move consolidates the privacy DNS landscape.
Identity verification company IDScan faces multiple lawsuits after hackers allegedly accessed and attempted to sell driver's license data for over 153 million individuals.
Attackers are actively exploiting a critical authentication bypass vulnerability in Citrix NetScaler, according to Previdian. CVE-2026-19490 allows threat actors to circumvent security controls on the widely-deployed application delivery platform.