✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Artificial Intelligence
Breach intelligence, attack campaigns, and threat reports targeting the Artificial Intelligence sector.
Explore Other Sectors
Artificial Intelligence Threat Reports
Cybercriminals Exploit Google Ads and Claude.ai to Target Mac Users
In May 2026, attackers exploited Google Ads and legitimate Claude.ai shared chats to distribute malware targeting macOS users. By searching for 'Claude mac download,' users encountered sponsored search results that appeared to link to the official Claude.ai website but redirected them to malicious instructions. These instructions guided users to execute terminal commands that downloaded and ran malware on their systems, leading to unauthorized access and potential data exfiltration. This incident underscores a growing trend where cybercriminals leverage trusted platforms and search engine advertisements to disseminate malware. The use of legitimate AI-generated content to host malicious instructions highlights the evolving sophistication of social engineering tactics, emphasizing the need for heightened vigilance and robust security measures among users and organizations.
1 month ago
Kill Chain
Vercel's 2026 Security Breach: Lessons in Third-Party Integration Risks
In April 2026, Vercel, a cloud development platform, experienced a security breach originating from a compromised third-party AI tool, Context.ai. An attacker exploited OAuth tokens to access a Vercel employee's Google Workspace account, leading to unauthorized access to certain internal systems and exposure of non-sensitive customer environment variables. Vercel promptly notified affected customers and recommended immediate credential rotation. The company engaged incident response experts and law enforcement to investigate and remediate the incident. ([vercel.com](https://vercel.com/kb/bulletin/vercel-april-2026-security-incident?utm_source=openai)) This incident underscores the growing threat of supply chain attacks targeting interconnected cloud services and the critical importance of securing third-party integrations. Organizations are urged to review their OAuth permissions and implement robust access controls to mitigate similar risks.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports