Security researchers reported that AI assistants with web-browsing/URL-fetch features can be repurposed as stealthy command-and-control (C2) relays, allowing attackers to proxy commands and exfiltrate data through legitimate-looking enterprise traffic. Check Point’s proof-of-concept, dubbed “AI as a C2 proxy,” demonstrated abuse paths against Microsoft Copilot and xAI Grok, including scenarios that do not require an API key or even a registered account, complicating common mitigations such as key revocation or account suspension.
Separately, organizations are responding to broader AI data security and privacy concerns by restricting AI tooling: the European Parliament reportedly disabled built-in AI features on lawmakers’ work devices due to uncertainty over what data is uploaded to AI vendors’ cloud services and the risk of sensitive correspondence exposure. In healthcare, ECRI Institute researchers flagged AI chatbots as a leading 2026 health-tech hazard, citing safety, security, and privacy risks from unvalidated clinical use, alongside ongoing concerns about IT outages and legacy medical device cybersecurity—reinforcing that AI adoption is increasingly being treated as a governance and risk-management issue, not just a productivity upgrade.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks Unit 42 recently described a related method in which client-side calls to trusted LLM services dynamically generate malicious JavaScript at runtime to assemble phishing pages and evade some security controls.
Check Point researchers showed that Microsoft Copilot and xAI Grok can be manipulated through crafted browsing and summarization prompts to relay command-and-control traffic and support data exfiltration from already-compromised hosts.
The European Parliament reportedly turned off built-in AI features on lawmakers' work devices over cybersecurity and privacy concerns about confidential data being uploaded to cloud AI services. An internal IT assessment said it could not guarantee the security of uploaded data and was still evaluating what information had been shared with AI providers.
ECRI Institute identified AI chatbots as the top health technology hazard for 2026, warning of safety, security, and privacy risks from their use in clinical contexts by patients and clinicians.
A 2024 ransomware attack on UnitedHealth Group's Change Healthcare unit disrupted thousands of U.S. healthcare providers for months, becoming a major reference point for healthcare IT outage risk.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcetechcrunch.com
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.