Multiple sources highlighted how AI is reshaping security work and risk. One article promoted AI-assisted bug hunting and reconnaissance, arguing that AI can reduce triage noise and help prioritize likely attack paths across modern, complex attack surfaces (APIs, microservices, cloud, and third-party dependencies). A separate Talos newsletter echoed the theme at a higher level, describing AI adoption as a paradigm shift while emphasizing that outcomes still depend on skilled practitioners using these tools responsibly and learning through experimentation.
Other items were not about AI security tooling so much as trust, governance, and abuse. A Vulnu newsletter reported the U.S. Pentagon taking early steps consistent with potentially treating Anthropic/Claude as a supply-chain risk—asking major defense contractors to assess reliance on Claude—amid tensions over Anthropic’s refusal to relax safeguards. Separately, a Smashing Security podcast recap described allegations that the operator of the Archive.today/Archive.is archiving service weaponized a CAPTCHA page to conduct a DDoS against a Finnish blogger and manipulated archive content to smear the blogger, prompting reactions including Wikipedia considering restrictions; the episode also mentioned a ransomware gang error that reportedly corrupted decryption keys, undermining victims’ ability to recover files.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
In the same 2026-02-26 publication, Talos said it was tracking active exploitation of CVE-2026-20127 in Cisco Catalyst SD-WAN Controller. The vulnerability was described as enabling unauthenticated authentication bypass and administrative privilege gain.
On publication, Cisco Talos disclosed technical details of the ongoing campaign, describing Dohdoor's stealthy DoH-based C2, process injection behavior, and infrastructure masking behind services such as Cloudflare. Talos warned of elevated risk to sensitive U.S. education and healthcare organizations and recommended updated detections and monitoring guidance.
Cisco Talos said an intrusion campaign attributed to UAT-10027 has been active since December 2025. The activity uses a newly identified backdoor called Dohdoor, delivered through phishing, PowerShell, and DLL sideloading, with command-and-control over DNS-over-HTTPS.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 10 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.