Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Bentley launches Torcal as luxury rivals pull back on electric cars

    September 24, 2026

    No Kings But King Dollar

    September 24, 2026

    Ukraine: Russia welcomes U.S. invite for possible Trump-Putin meeting

    September 24, 2026
    Facebook X (Twitter) Instagram
    Addison Markets Addison Markets
    • Home
    • USA
    • Europe
    • Business
    • Investing
    • Tech
    • Politics
    • Contact Us
    Addison Markets Addison Markets
    Home»Tech»Hackers can use 9 of the most popular AI tools to assemble massive botnets
    Tech

    Hackers can use 9 of the most popular AI tools to assemble massive botnets

    franperez66q@protonmail.comBy franperez66q@protonmail.comJuly 8, 2026No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    In the brief history of AI security, the prompt injection has quickly become the top threat. Large language models are inherently unable to distinguish between legitimate instructions provided by users and malicious ones sneaked into emails, source code, and other third-party content the models are processing. This makes it trivial to surreptitiously inject malicious commands that the LLM readily follows.

    With no way to enforce this crucial boundary between trusted and untrusted sources, AI engine developers are left to erect elaborate guardrails designed to mitigate the damage rather than solve the root cause.

    To date, most prompt injections have fallen into a class known as push, in which each potential victim is targeted. For example, the adversary injects malicious instructions into an individual email or calendar invitation. Because the injection must then be sent (or pushed) to each specific target, the scale of the attack is limited, hampering mass exploits that hit the Internet at large.

    Meanwhile, pull-based attacks, in which an LLM actively seeks out the adversarial prompts planted on websites, remain limited. With no way to lure large numbers of LLMs to a malicious site, these sorts of attacks don’t scale either.

    Enter HalluSquatting

    Now, researchers have devised a pull-based attack that changes all that. A new attack the researchers have named HalluSquatting has the potential to assemble massive botnets, perform large-scale DDoSes, and infect devices at scale, a first for prompt-injection attacks. The attack works against AI coding assistants and agents, including Cursor, Cursor CLI, Gemini CLI, Windsurf, GitHub Copilot, Cline, OpenClaw, ZeroClaw, and NanoClaw, which are all susceptible. In the normal course of performing day-to-day activities, these assistants and agents routinely pull code and other resources from repositories and registries.



    The HalluSquatting threat model.

    Credit:
    Spira et al.

    The HalluSquatting threat model.


    Credit:

    Spira et al.

    Short for adversarial hallucination squatting, HalluSquatting is built on an LLM’s inherent tendency to hallucinate the resource identifiers hosted in repositories and registries. It works against coding agents and assistants, which commonly access high-privilege command lines to run code from third-party resources. By predicting the identifiers LLMs are most likely to hallucinate and then registering and seeding them with instructions to install reverse shells or other malicious wares, the attack can indiscriminately infect massive numbers of devices without having to target each one.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    franperez66q@protonmail.com
    • Website

    Related Posts

    Ukrainian drones overwhelm Russian tanks’ new active protection system—for now

    August 19, 2026

    Jim Cramer says the market is too negative — and that’s creating buying opportunities

    August 19, 2026

    “Sabotage”: Experts, lawmakers blast RFK Jr. for destroying healthcare research

    August 18, 2026

    OpenAI rolls out ChatGPT for Teens with more safety protections

    August 18, 2026

    Against all odds, SpaceX finally tugs Starship into port after 24 days at sea

    August 18, 2026

    Economists warn AI-driven market rally is due a sharp correction

    August 18, 2026
    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Bentley launches Torcal as luxury rivals pull back on electric cars

    September 24, 2026

    No Kings But King Dollar

    September 24, 2026

    Ukraine: Russia welcomes U.S. invite for possible Trump-Putin meeting

    September 24, 2026

    Swiss National Bank holds rates at 0% as inflation stays low

    September 24, 2026
    © 2026 All right reserved
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.