started · updated
AI-driven attacks and ad‑based surveillance expose new cyber threats
Cato Networks published a study demonstrating that an AI‑driven agentic attack chain, built on a public large‑language model (GPT‑5) and a structured operational context, can compromise a corporate Active Directory environment and obtain Domain Administrator privileges in just 40 minutes. The autonomous agent performed reconnaissance, exploitation, lateral movement and data exfiltration with minimal human prompting.
Separately, Sekoia released research on Advertising‑based Intelligence (ADINT), showing how the real‑time bidding advertising infrastructure can be hijacked to collect location, device IDs and browsing behavior for surveillance purposes. The technique has evolved to deliver spyware via malicious ads without any user interaction (zero‑click), enabling detailed profiling and remote compromise of smartphones.