< Back to situations

We’ll email you as it develops, and you can follow the whole thread from day one.

[SITUATION] · [ACTIVE]

2 clusters · 2 sources · 23 days · First seen · Last updated

Categories: TECHNOLOGY

AI‑driven cyber attack methods

Entities: Windows PowerToys · Check Point Software Technologies · AI mail agents · Proofpoint · Bogdan X

Overview

In early July 2026, Check Point reported a novel ransomware technique that leverages artificial intelligence within web browsers to encrypt victims’ files. By the end of the month, Proofpoint identified additional AI‑enabled abuse vectors. Researchers described “indirect prompt injection,” where invisible commands hidden in emails, documents, calendar invites and online ads are read by AI‑based mail filters, potentially triggering unsafe actions. The same report detailed a parallel campaign that mimics popular Windows utilities (e.g., PowerToys, EasyBCD, CrystalDiskMark). These spoofed sites initially present legitimate download pages before swapping the links for malware that installs remote‑access tools. Together, the findings illustrate a widening landscape of AI‑mediated threats that expand from in‑browser ransomware to hidden command injection and malicious software distribution through compromised Windows‑utility sites.

Timeline

  1. 3 days ago

    [TECHNOLOGY] 2 sources
    Proofpoint flags hidden AI command injections in emails and fake Windows app sites delivering malware

    Proofpoint warns of hidden AI prompts in emails that could hijack mail filters, while researchers expose look‑alike Windows‑app sites distributing malware.

  2. 26 days ago

    [TECHNOLOGY] 2 sources
    Check Point uncovers AI‑driven in‑browser ransomware technique

    Check Point reports an AI‑crafted in‑browser ransomware that uses legitimate browser APIs, while AI Guard Gateway offers open‑source protections against AI endpoint hijacking and prompt injection.

Sources

cybersecuritynews.com · sf-encyclopedia.com