The rapid adoption of AI agents and large language models (LLMs) by software developers is transforming the software development pipeline, increasing productivity but also introducing significant security risks. As organizations integrate AI tools for code generation, debugging, and architectural design, the quality and security of code have become inconsistent, with vulnerabilities in legacy code often being propagated. Experts warn that while AI can enhance bug detection and triage, the sheer volume and complexity of AI-generated code may outpace human oversight, making it easier for insecure code to reach production. Additionally, the use of AI in privileged access management is expected to shift from passive monitoring to proactive, autonomous governance, with machine learning models enforcing real-time policies and detecting anomalous behavior to prevent insider threats and account takeovers.
The evolving threat landscape is further complicated by attackers leveraging AI-powered tools and deepfakes to conduct sophisticated scams and social engineering campaigns. For example, the Nomani investment scam has surged by 62%, using AI-generated video testimonials and deepfake ads on social media to deceive victims. Security researchers also highlight the abuse of legitimate open-source tools and the use of synthetic data in cyber deception, as well as the need for organizations to address the growing trust gap in AI technologies. As AI becomes more deeply embedded in both offensive and defensive cybersecurity operations, organizations must prioritize secure development practices, adaptive authentication, and continuous monitoring to mitigate emerging risks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
The 2025 Thinkers360 AI Trust Index found that public concern about AI remained high, with an overall trust score of 307 that was nearly unchanged from 2024. The report also identified a persistent gap between optimistic AI providers and more skeptical end users.
After identifying the actor's infrastructure, Resecurity collaborated with law enforcement and internet service providers by providing abuse data and indicators of compromise. The information supported further investigation and a subpoena request.
Over several weeks, the targeted actor tried to automate data exfiltration through residential proxies while interacting with Resecurity's deception environment. Operational security mistakes ultimately revealed the actor's real IP addresses and supporting infrastructure.
Resecurity used synthetic data, honeytrap accounts, and emulated applications to detect and study a threat actor that began by conducting reconnaissance from Egyptian and VPN IP addresses. The operation was designed to lure the actor into interacting with realistic but non-sensitive data.
As the campaign evolved in 2025, operators used Europol- and INTERPOL-themed recovery scams to target people who had already lost money. These lures falsely promised help recovering funds while extracting more money or personal information.
During 2025, ESET blocked over 64,000 unique URLs tied to the Nomani scam, with the highest detection volumes in Czechia, Japan, Slovakia, Spain, and Poland. The infrastructure included phishing templates hosted on GitHub and increasingly realistic AI-generated content.
Nomani detections fell by 37% in the second half of 2025, which ESET said was likely due to increased law enforcement pressure. This marked a notable shift after the scam's earlier growth during the year.
ESET reported that the Nomani fraudulent investment scheme grew by 62% in 2025 and broadened from Facebook to additional platforms such as YouTube. The campaign used AI deepfake videos, malvertising, and branded social media posts to lure victims into fake investments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcedarkreading.com
Open sourcecio.com
Open sourcethehackernews.com
Open sourcethehackernews.com
Open sourceresecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.