<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ai-Abuse on CuraSec</title><link>https://curasec.metacog.co.kr/tags/ai-abuse/</link><description>Recent content in Ai-Abuse on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 06 Aug 2026 13:03:19 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/ai-abuse/index.xml" rel="self" type="application/rss+xml"/><item><title>OpenAI Disrupts Cambodia-Based Scam Network Using ChatGPT</title><link>https://curasec.metacog.co.kr/insights/2026-08-06-openai-disrupts-poipet-scam-network-using-chatgpt-across-mul/</link><pubDate>Thu, 06 Aug 2026 13:03:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-06-openai-disrupts-poipet-scam-network-using-chatgpt-across-mul/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Documents how AI-assisted fraud operations leverage LLM accounts for scalable scam content generation; no IOCs or detection surface provided, but useful context for understanding AI-enabled social engineering at scale.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Illustrates the emerging risk of AI platforms being weaponized by organized fraud networks; useful context for board-level discussions on AI usage policies and third-party AI tool risk.&lt;/li>
&lt;/ul></description></item><item><title>Gemini CLI weaponized as hacking agent and botnet operator</title><link>https://curasec.metacog.co.kr/insights/2026-07-16-google-gemini-cli-abused-as-a-hacking-agent-malware-botnet-o/</link><pubDate>Thu, 16 Jul 2026 12:18:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-16-google-gemini-cli-abused-as-a-hacking-agent-malware-botnet-o/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Demonstrates that open-source AI CLI tools can be weaponized as autonomous hacking agents without any vulnerability in the tool itself — worth factoring into how you restrict or monitor AI tooling in build and dev environments.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> This TTP — using legitimate AI CLI processes as attack orchestrators — is worth adding to your behavioral detection backlog; consider hunting for anomalous Gemini CLI process invocations, unusual network calls from AI tool processes, or AI binaries spawning unexpected child processes.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A real-world example of AI tools being weaponized at small scale; useful context for AI governance policy discussions and for framing acceptable-use controls around AI developer tooling.&lt;/li>
&lt;/ul></description></item></channel></rss>