DeepSeek is a tool tracked across 28 threat clusters and 35 intelligence report mentions on ThreatCluster. First observed November 11, 2025; most recent activity July 16, 2026.
DeepSeek is a cybersecurity threat tool/component linked to AI chat data exfiltration and abuse of LLM infrastructure. It has appeared in malicious Chrome extensions that steal ChatGPT and DeepSeek chats, and is used in threat groups’ toolkits such as the WormGPT variant KawaiiGPT, indicating a focus on harvesting and monetizing AI chat data.
A Cambridge University study reveals Boko Haram has integrated AI tools into its operations, utilizing US and Chinese chatbots for bomb-making, attack planning, and propaganda. The research, based on interviews with 27…
Zoom has patched a critical vulnerability (CVE-2026-53412) in its Windows desktop client and VDI software that could allow unauthenticated attackers to take over user accounts via network access. The flaw, rated 9.8 out…
Recent reports indicate that state-linked hackers are leveraging artificial intelligence to enhance their cyber capabilities, posing significant risks to national utilities and intellectual property. Additionally, a US…
Anthropic's AI tool, Claude Code, was found to contain hidden tracking mechanisms targeting Chinese users, raising significant privacy concerns. The covert detection logic, embedded since April 2, 2026, identified users…
A coordinated malware campaign has been uncovered involving at least 15 malicious plugins on the JetBrains Marketplace, designed to steal AI API keys from developers. These plugins, masquerading as AI coding assistants,…
A remote code execution vulnerability has been identified in the SGLang framework, specifically affecting the reranking endpoint (/v1/rerank) and tracked as CVE-2026-5760. This flaw allows attackers to exploit…
A threat actor has integrated Anthropic's Claude Code AI into a large-scale credential harvesting operation named Bissa scanner. This operation has successfully exploited over 900 targets since September 2025, utilizing…
Malicious browser add-ons are targeting users of popular AI platforms such as ChatGPT, Claude, Copilot, Gemini, and DeepSeek. These extensions masquerade as helpful tools but are actually harvesting personal data and…
A study by Wake Forest University revealed that 282 out of 444 analyzed iOS applications with AI features are leaking Large Language Model (LLM) API credentials through network traffic. This vulnerability affects apps…
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…