AI News selected for Professionals and Decision Makers
AI Security And Privacy Updates

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

19:29 · July 20, 2026 · Hacker News AI Section

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV. What makes it more than a

Summary

An exposed server belonging to a malware operator yielded a complete 1,048-file toolkit that Rapid7 recovered in full. The contents included lure templates, filename-spoofing experiments, execution tests, droppers, builder notes, and two active campaign directories. One campaign was already operational, using a typosquatted Mexican government site to deliver an infostealer through WebDAV shares to Windows endpoints.

The artifacts revealed an operator actively developing and refining delivery methods rather than simply reusing existing tools. README files, test matrices, and documentation exhibited the structured, verbose, and emoji-laden formatting typical of large-language-model output. Rapid7 traced hardcoded paths to an open-source AI coding agent, indicating that the operator relied on commodity generative tools to generate, test, and document phishing infrastructure at scale.

The primary technique under development centered on CVE-2025-33053, a WebDAV working-directory hijack. The method uses a .url shortcut to launch a legitimate signed binary while redirecting its working directory to an attacker-controlled share, causing Windows to load a malicious executable in place of a system binary. The operator expanded a single proof-of-concept into a 59-file test suite targeting additional signed binaries and LOLBAS entries, explicitly adapting the approach after the original iediagcmd.exe vector became unavailable on Windows 11 24H2.

Live operations included a campaign spoofing Mexico’s CURP national-ID portal. Victims received a .scr executable disguised through right-to-left override characters; the file installed an in-memory .NET infostealer that harvested wallets, credentials, and session data. A second directory, DlrtyGames, tested DLL sideloading via a signed Ubisoft binary to deploy a modular RAT. Over five and a half days the delivery panel recorded roughly 77,000 requests from nearly 4,000 IPs, with the majority originating in Mexico during local working hours.

Rapid7 published indicators of compromise and behavioral detections, such as WebClient service activity reaching remote shares and child processes launched from UNC paths. The June 2025 patch addressed the original iediagcmd.exe vector, yet the test kit demonstrates continued exploration of alternative signed binaries. The episode illustrates how readily available AI coding assistants can accelerate the full cycle of malware delivery development, from initial research to operational deployment.

Why it matters

Directly addresses AI misuse for generating phishing and malware at scale, offering actionable IOCs and detection guidance for security teams. Highlights emerging LLM-driven attack workflows relevant to EU threat landscapes and compliance needs.

More in this beat
coding-agentsincident-response-playbooksopen-source-securityphishingrapid7threat-and-vulnerability-updates
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

18:47 · August 11, 2026

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

This article demonstrates the practical application of AI agents in discovering complex vulnerability chains in widely used enterprise software. It provides crucial insights into how AI is accelerating offensive security capabilities, which Dutch enterprises must understand to defend against increasingly sophisticated cyberattacks.

Relevance 85 · Audience 95

IBM and Red Hat Move Project Lightwell to Commercial Launch, Warning AI Security Risks are a “Wake Up Call” for CX Leaders

18:23 · July 13, 2026

IBM and Red Hat Move Project Lightwell to Commercial Launch, Warning AI Security Risks are a “Wake Up Call” for CX Leaders

This article is highly relevant for security professionals as it highlights a critical shift in the threat landscape where AI accelerates both attacks and remediation. It offers actionable insights into managing technical debt and introduces a major new enterprise tool for securing open-source dependencies, which is vital for Dutch organizations deploying AI.

Relevance 85 · Audience 95

Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

15:03 · July 13, 2026

Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

This article highlights the weaponization of AI by cybercriminals to scale and enhance phishing attacks against widely used enterprise platforms like Microsoft 365. It provides actionable threat intelligence and mitigation strategies crucial for Dutch security professionals defending corporate networks against AI-augmented threats.

Relevance 85 · Audience 95

AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload

15:19 · June 8, 2026

AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload

This article is highly relevant for security professionals as it highlights a critical, AI-driven threat vector that directly impacts SOC efficiency and enterprise security. Dutch organizations must adapt their defensive strategies to handle the increased volume and sophistication of AI-generated phishing attacks.

Relevance 85 · Audience 95

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

19:23 · August 20, 2026

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

The article provides crucial updates on privacy-enhancing technologies for AI that are vital for GDPR compliance in the Netherlands. It also alerts security professionals to emerging AI-driven threats, such as uncensored LLMs and AI models capable of autonomous vulnerability exploitation, which require immediate defensive consideration.

Relevance 85 · Audience 95

Phishing 3.0: The Fight Moves to Agent Versus Agent

13:30 · August 19, 2026

Phishing 3.0: The Fight Moves to Agent Versus Agent

This article is highly relevant for security professionals as it highlights the emerging threat of AI-driven phishing agents. Dutch enterprises must adapt their cybersecurity strategies to counter AI-generated attacks, making this crucial for maintaining robust organizational security.

Relevance 85 · Audience 95