Artificial intelligence is rapidly transforming the cyber threat landscape, introducing new risks and amplifying existing ones. Recent research revealed that 65% of top AI firms have leaked verified secrets such as API keys and credentials on GitHub, exposing sensitive data and private models to potential compromise. The prevalence of shadow AI—unauthorized or unmonitored AI tools used within organizations—has become a significant blind spot for security teams, as employees increasingly adopt generative AI tools like ChatGPT and Gemini without official oversight. This unregulated use heightens the risk of data leakage and undermines established security controls.
Simultaneously, threat actors are leveraging AI to enhance spear phishing campaigns, targeting IT leaders with highly convincing, context-aware messages that are difficult to detect. Security teams are also adopting generative AI to improve open-source intelligence (OSINT) gathering, using these tools to expand keyword searches and identify evolving threat actor slang. The convergence of AI-driven attack techniques and the widespread exposure of credentials underscores the urgent need for organizations to implement robust secret scanning, monitor shadow AI usage, and adapt defenses to counter increasingly sophisticated, AI-enabled threats.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Initial story creation
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcearcticwolf.com
Open sourcewelivesecurity.com
Open sourceflashpoint.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.