Two new AI-powered security tools have been introduced to enhance vulnerability detection and threat analysis workflows. BugTrace-AI is an open-source penetration testing suite that leverages generative AI to assist ethical hackers and developers in identifying potential vulnerabilities. It combines static and dynamic analysis, AI-driven reconnaissance, and specialized modules for detecting issues such as SQL injection, XSS, JWT weaknesses, and privilege escalation paths. The tool features a unique methodology that recursively consolidates and refines findings using multiple AI personas, aiming to reduce false positives and improve actionable insights.
Nextron’s RuneAI is an internal service designed to address alert fatigue in artifact scanning by enriching weak signals and highlighting anomalies for further investigation. Integrated with the THOR Thunderstorm scanner, RuneAI prioritizes suspicious packages from sources like npm and PyPI, providing contextual risk assessments to streamline analyst workflows. In a recent case, RuneAI escalated a low-scoring detection to a high-risk alert, leading to the discovery of a package with hardcoded credentials and malicious payload delivery, demonstrating its effectiveness in real-world supply chain threat detection.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Cyber Security News reported on BugTrace-AI, an open-source AI-assisted web security analysis and penetration testing platform that combines static and dynamic analysis, reconnaissance, payload generation, and specialized scanners. The report described the tool's features, deployment model, and early user feedback, but did not indicate a separate dated release event.
Human-led analysis confirmed the package functioned as a multi-stage remote access trojan using hardcoded Dropbox credentials, payload delivery via Dropbox, persistence, remote command execution, DLL side-loading, and a final Cobalt Strike beacon DLL with C2 on Amazon EC2. Nextron also extracted IOCs and put detection signatures in place.
Nextron's internal artifact-scanning pipeline using THOR Thunderstorm detected the malicious npm package @etoroloro/my_node_js_module:1.0.1, and RuneAI escalated it for deeper analysis. The package was identified before widespread impact.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.