< Back to all clusters
[TECHNOLOGY] · Switzerland, France · 2 sources

AI agents and trusted software abused in new phishing‑based cyber attacks

Varonis Threat Labs demonstrated that an autonomous AI agent, named Pinchy, connected to corporate tools can be deceived by phishing emails and transmit sensitive data such as AWS IAM keys, database credentials and detailed CRM information for 247 clients, amounting to about $1.28 million in monthly recurring revenue. Both a generic productivity profile and a security‑hardened profile failed in several scenarios, though the stricter configuration blocked some phishing attempts. The researchers noted differences between models—Google Gemini 3.1 Pro was more prone to act, while OpenAI Codex GPT‑5.4 displayed greater caution—and recommended architectural safeguards, restricted data access, and human validation for critical actions.

HP’s Threat Insights Report for January–March 2026 found that attackers increasingly exploit legitimate remote‑access utilities such as LogMeIn and ScreenConnect, embedding them in phishing campaigns that include fake installers and AI‑generated malicious scripts. These tools allow full control of compromised machines while appearing benign. The report highlighted that 11 % of email‑borne threats bypass at least one security filter, with executables constituting 39 % of delivered malware, archives 38 % and PDFs 10 %. Both studies underscore growing challenges in detecting sophisticated, trusted‑tool‑based cyber attacks.