recent cyberattacks exploiting large language models. Fetches incidents where attackers used or targeted LLMs to breach systems. Keeps security professionals alert.

Recent LLM-related cyberattack sources

A curated reading list of official incident reports, threat-intelligence posts, and defensive advisories on attackers using LLMs or targeting LLM and agent systems. I kept the most relevant, primary sources and dropped broad or clearly off-target results.

Primary threat-intelligence reports on attacker use of LLMs

Use these first for documented or near-primary reporting on adversary tradecraft involving AI tools, including reconnaissance, phishing, vulnerability exploitation, and intrusion support.

anthropic.com
anthropic.com
We examine 832 accounts that were banned for malicious cyber activity between March 2025 and March 202...
google.com
By integrating LLMs into malware operations, attackers can enable payloads to act autonomously, independently ...
google.com
google.com
Google DeepMind also develops threat models for generative AI to identify potential vulnerabilities, and creat...
google.com
This includes the use of fake Zoom meetings and a known use of AI tools by the threat actor for editing images...
google.com
google.com
GTIG identified a novel campaign where threat actors are leveraging the public sharing feature of generative A...

Incidents and guidance for attacks on AI apps, copilots, and agent systems

These are the most relevant sources for prompt injection, exfiltration, AI app compromise, and incident-response guidance for AI systems.

cisa.gov
cisa.gov
The KEV catalog is also available in these formats: CSVJSON Print View JSON Schema (updated 06-25-2024) Licens...
cisa.gov
cisa.gov
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence...
cisa.gov
cisa.gov
High Vulnerabilities PrimaryVendor -- Product Description Published CVSS Score Source Info
cisa.gov
cisa.gov
High Vulnerabilities PrimaryVendor -- Product Description Published CVSS Score Source Info
cisa.gov
cisa.gov
This guidance discusses cybersecurity challenges and risks associated with the introduction of agentic AI into...
cisa.gov
cisa.gov
WASHINGTON – Today, the Cybersecurity and Infrastructure Security Agency (CISA), Australian Signals Directorat...
nist.gov
nist.gov
This is a potential security issue, you are being redirected to https://nvd.nist.gov · Official websites use ....
nist.gov
nist.gov
This is a potential security issue, you are being redirected to https://nvd.nist.gov · Official websites use ....
nist.gov
nist.gov
This is a potential security issue, you are being redirected to https://nvd.nist.gov · Official websites use ....
cisa.gov
cisa.gov
Embed Safety and Security: Maintain oversight, ensure transparency, and integrate AI into incident response pl...

Frameworks and technique references

Useful supporting references for analysts mapping AI-enabled operations to ATT&CK or validating terminology around public AI service abuse and related tactics.

anthropic.com
Today, we’re sharing a new analysis ... onto the MITRE ATT&CK® framework, a database of tactics an...
mitre.org
mitre.org
From Reconnaissance to Control: The Operational Blueprint of Kimsuky APT for Cyber Espionage. Retrieved April ...
mitre.org
mitre.org
Adversaries may query publicly accessible artificial intelligence (AI) services, such as large language models...
mitre.org
mitre.org
Anthropic. (2025, November). Disrupting the first reported AI-orchestrated cyber espionage campaign.
mitre.org
mitre.org
North Korean attackers use malicious blogs to deliver malware to high-profile South Korean targets. Retrieved ...
mitre.org
mitre.org
Kirill Boychenko. (2026, January 31). GlassWorm Loader Hits Open VSX via Developer Account Compromise.