New cyberattack reveals vulnerability in AI security analysis

A recent cyber attack has highlighted a structural disconnection between the HTML text and what users actually see in their browsers, allowing attackers to send malicious instructions that go unnoticed by artificial intelligence assistants. This finding was presented by LayerX, a cybersecurity company, which demonstrated its technique through a fake fanfiction site for Bioshock. By using a custom font, the attackers were able to hide a malicious message in seemingly harmless content. Hidden threats in HTML The attack revealed that, although AI assistants like ChatGPT and Claude were examining the […]

A recent cyber attack has highlighted a structural disconnection between the HTML text and what users actually see in their browsers, allowing attackers to send malicious instructions that go unnoticed by artificial intelligence assistants. This finding was presented by LayerX, a cybersecurity company, which demonstrated its technique using a fake Bioshock fanfiction site. By using a custom font, the attackers were able to hide a malicious message in seemingly harmless content.

Hidden Threats in HTML

The attack revealed that, although AI assistants like ChatGPT and Claude were examining the underlying HTML for threats, they lacked the ability to identify hidden content that appeared safe at first glance. In this case, the malicious text urged users to execute a reverse shell on their machines, while the visible text was a set of unreadable characters.

LayerX has pointed out that this vulnerability does not require the use of JavaScript or exploit kits, revealing a flaw in how AI tools analyze the security of web pages. While browsers present information in a designed manner, AIs treat the text of the DOM as the complete representation of what is shown to the user, leaving a gap that attackers can exploit.

In response to this threat, LayerX recommends that AI providers implement dual rendering analysis and treat custom fonts as potential threat surfaces. Additionally, it is vital that these tools avoid making security judgments without having verified the full context of the page. So far, Microsoft has stood out as the only provider that has fully addressed the issue following LayerX’s responsible disclosure in December 2025.

The FBI confirms a cybersecurity incident affecting its networks

The FBI has confirmed that its networks were the subject of a cybersecurity incident, although it has not provided additional details about the exact nature of the attack. According to a statement from the agency, suspicious activities were identified and addressed in its systems, specifically in a digital system used to manage surveillance and procedures related to foreign surveillance orders. Clear responses In 2024, it was revealed that the Chinese hacker group known as ‘Salt Typhoon’ had exploited the United States’ phone tapping system, protected under the Communications Assistance for Law Enforcement Act. […]

The FBI has confirmed that its networks were the subject of a cybersecurity incident, although it has not provided additional details about the exact nature of the attack. According to a statement from the agency, suspicious activities were identified and addressed in its systems, specifically in a digital system used to manage surveillance and processes related to foreign surveillance orders.

Clear Answers

In 2024, it was revealed that the Chinese hacker group known as ‘Salt Typhoon’ had exploited the United States’ phone tapping system, under the Communications Assistance for Law Enforcement Act. However, it is unclear whether there is any connection between the recent cybersecurity incidents and the activities of this group. The lack of clarity regarding the exact timing of the attack, as well as the identity of those responsible, has raised concerns both within and outside the organization.

The FBI, which has been targeted by cyberattacks multiple times, reported in 2023 an incursion in its New York office, in addition to an incident in 2021 where hackers exploited a misconfigured server to send phishing emails.These situations have led to growing skepticism about the FBI’s ability to respond to cyber threats, especially in the context of budget cuts and staff reductions during the Trump administration.

Former agents and members of Congress have expressed their concerns about the FBI’s cyber preparedness. Despite these concerns, Brett Leatherman, director of the FBI’s cyber division, stated in recent remarks to CyberScoop that the agency has not diminished its capacity to respond to threats and incidents. However, the FBI itself continues to struggle with the repercussions of its recent cyber challenges.

Bumble and Match are victims of a cyberattack that reveals internal data

The dating apps Bumble and Match have been attacked by the cybercriminal group known as ShinyHunters, responsible for compromising internal data from multiple large companies. According to reports, the group has added both companies to its data leak site, claiming the theft of thousands of documents classified as restricted and confidential, primarily sourced from Google Drive and Slack. Dating sometimes doesn’t go well Bloomberg notes that Bumble, which also operates Badoo and BFF, contacted authorities after one of its contractors’ accounts was compromised in a phishing incident

The dating apps Bumble and Match have been attacked by the cybercriminal group known as ShinyHunters, responsible for compromising internal data from multiple large companies. According to reports, the group has added both companies to its data leak site, claiming the theft of thousands of documents classified as restricted and confidential, primarily sourced from Google Drive and Slack.

Sometimes dates don’t go well

Bloomberg reports that Bumble, which also operates Badoo and BFF, contacted authorities after one of its contractors’ accounts was compromised in a phishing incident. A spokesperson for Bumble stated that the attackers were able to unauthorizedly access a small portion of their network, but they do not believe that member data, including accounts, direct messages, or profiles, has been affected.

For its part, Match confirmed that it suffered a cyber incident on January 28, which impacted a limited amount of user data. The company is notifying the affected individuals and assured that there is no evidence that access credentials, financial information, or private communications have been compromised.

ShinyHunters has been in the spotlight recently for its successful attacks on several large companies and for its focus on data exfiltration, having abandoned the practice of ransomware. This group has been targeting single sign-on platforms like Okta and Microsoft, and there are warnings for organizations, especially in the United States, about phishing attempts by individuals impersonating technical support staff.

The EvilAI campaign exploits trusted applications to spread malicious software

Threat actors have begun to use seemingly legitimate artificial intelligence tools to distribute malware, affecting various industries such as manufacturing, government, and healthcare in countries like the U.S., India, and several European nations. This campaign, known as EvilAI, is an active and evolving effort in which attackers disguise malicious software as productivity tools or AI-enhanced applications. The great danger for all types of organizations Cybercriminals use professional interfaces and valid digital signatures to make these applications appear legitimate, making it difficult for users and security tools to detect them. Among the […]

Threat actors have begun using seemingly legitimate artificial intelligence tools to distribute malware, affecting various industries such as manufacturing, government, and health in countries like the U.S., India, and several European nations. This campaign, known as EvilAI, is an active and evolving effort in which attackers disguise malicious software as productivity tools or AI-enhanced applications.

The great danger for all types of organizations

Cybercriminals use professional interfaces and valid digital signatures to make these applications appear legitimate, making it difficult for users and security tools to detect them. Among the distributed programs are AppSuite, Epi Browser, and PDF Editor, which act as vehicles to conduct extensive reconnaissance and exfiltrate sensitive data from the victims’ browsers.

The propagation techniques are diverse and include the use of newly registered websites that mimic provider portals, malicious advertising, and SEO manipulation to promote download links on forums and social media. Some attacks have been facilitated with certificates from companies in Panama and Malaysia, and it has been documented that malware developers have used multiple certificates to make their software appear legitimate over the years.

Recent investigations have revealed that the actors behind applications like OneStart and ManualFinder share the same server infrastructure, suggesting a malware-as-a-service model. Additionally, advanced techniques such as Unicode encoding and the use of the NeutralinoJS framework are being employed to conceal malicious activities and evade detection.

This remarkable approach to camouflage and evasion capabilities has allowed attackers to gain access to systems, raising alarms about the increasing sophistication of digital threats and the exploitation of user trust.

The attack on the Npm registry exposes confidential credentials of developers

A targeted attack on the npm registry has raised significant concerns in the software development community, affecting more than 40 packages and allowing the injection of malicious scripts. According to cybersecurity researchers, the attack focuses on compromised versions that contain a function that downloads and modifies packages, then injects a local script called ‘bundle.js’. This script is designed to download and execute TruffleHog, a legitimate secret scanning tool, with the aim of searching for tokens and credentials on developers’ machines. Auditing the environments The attack is capable of executing on both Windows and […]

A targeted attack on the npm registry has raised significant concerns in the software development community, affecting more than 40 packages and allowing the injection of malicious scripts. According to cybersecurity researchers, the attack focuses on compromised versions that contain a function that downloads and modifies packages, then injects a local script called ‘bundle.js’. This script is designed to download and execute TruffleHog, a legitimate secret scanning tool, with the aim of searching for tokens and credentials on developers’ machines.

Audit the environments

The attack is capable of executing on both Windows and Linux systems, which increases the severity of the situation. Among the elements that TruffleHog searches for are sensitive credentials such as GITHUB_TOKEN, NPM_TOKEN, AWS_ACCESS_KEY_ID, and AWS_SECRET_ACCESS_KEY. According to the security firm Socket, the script also validates npm tokens and can interact with GitHub APIs, facilitating the exfiltration of data to an external server controlled by the attackers.

The developer community has been urged to audit their environments and rotate npm tokens, as well as other exposed secrets, if affected packages are found. Additionally, malicious emails have been reported coming from a fake domain attempting to steal GitHub credentials. These messages warn of a supposed breach of the crates.io infrastructure and suggest that users click on links to rotate their login information.

The team at the Rust Security Response Working Group has confirmed that these emails are fraudulent and come from a domain not controlled by the Rust Foundation. Measures are being taken to monitor suspicious activity on crates.io and work is underway to eliminate the phishing domain.

Improving cybersecurity practices reduces the costs of data breaches

According to a recent report from IBM, the global average cost of a data breach has decreased by 9% compared to the year 2024. This decline marks a significant change in the trend of costs associated with security breaches, which could indicate important advancements in data management and protection globally. More informed and trained This report highlights that improvements in detection and containment capabilities have been key factors in cost reduction. Companies are investing in more effective technologies and in training of […]

According to a recent report from IBM, the global average cost of a data breach has decreased by 9% compared to the year 2024. This decline marks a significant shift in the trend of costs associated with security breaches, which could indicate important advancements in data management and protection on a global scale.

More informed and trained

This report highlights that improvements in detection and containment capabilities have been key factors in cost reduction. Companies are investing in more effective technologies and training their staff, which allows them to identify and respond to threats more swiftly. The implementation of options such as artificial intelligence and data analysis has enabled organizations to tackle security breaches more strategically.

The reduction in costs associated with data breaches also reflects progress in cybersecurity practices. With the growing proliferation of information online, the need to protect data has become an essential priority for companies across all sectors. This has led to greater awareness of security threats and a stronger commitment to implementing protective measures.

Despite these advances, experts warn that cybersecurity remains a field in constant evolution, full of new challenges. The decrease in cost does not mean that threats have disappeared; rather, it symbolizes that organizations are better equipped to deal with breaches when they occur. Continuous investment in security technologies is crucial to maintain this downward trend in the cost of data breaches in the future.

A new malware threatens the security of WordPress

Cybersecurity researchers have revealed a serious vulnerability in WordPress sites, related to a hidden backdoor in the ‘mu-plugins’ directory. This type of plugin, known as must-use, is automatically activated in all WordPress installations and does not appear in the usual plugin list, making it an attractive target for attackers. What to do to avoid it The malicious PHP script, discovered by the web security company Sucuri, acts as a loader that retrieves a remote payload and stores it in the WordPress database. This payload allows for code execution […]

Cybersecurity researchers have revealed a serious vulnerability in WordPress sites, related to a hidden backdoor in the ‘mu-plugins’ directory. These types of plugins, known as must-use, are automatically activated in all WordPress installations and do not appear in the usual plugin list, making them an attractive target for attackers.

What to do to avoid it

The malicious PHP script, discovered by the web security company Sucuri, acts as a loader that retrieves a remote payload and stores it in the WordPress database. This payload allows for remote PHP code execution, facilitating persistent access for attackers, who can manage files and reinstall the infection if it is removed.

The malware injects a hidden administrator user called ‘officialwp’, allowing attackers to control the site and perform malicious actions without other administrators being aware. Additionally, the malicious code has the ability to change the passwords of administrative accounts to a default value, blocking access to other administrators and ensuring total control of the site.

The threat is amplified by the ability of the malware to steal data and redirect visitors to fraudulent sites, which significantly impacts web security. According to experts, this backdoor allows attackers to perform a variety of actions, from installing more malware to defacing the site.

To mitigate these risks, site owners must periodically update WordPress, themes, and plugins, use two-factor authentication, and regularly audit all sections of the site, including theme and plugin files. Maintaining security is crucial to prevent attacks that could compromise the integrity and trust of the website.