<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Generative-Ai-Abuse on CuraSec</title><link>https://curasec.metacog.co.kr/tags/generative-ai-abuse/</link><description>Recent content in Generative-Ai-Abuse on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 12 Sep 2026 14:04:45 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/generative-ai-abuse/index.xml" rel="self" type="application/rss+xml"/><item><title>Claude AI Weaponized by State and Criminal Actors for Cyber Operations</title><link>https://curasec.metacog.co.kr/insights/2026-09-12-claude-used-to-automate-exploitation-and-data-theft-across-m/</link><pubDate>Sat, 12 Sep 2026 14:04:45 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-12-claude-used-to-automate-exploitation-and-data-theft-across-m/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No specific software vulnerability or patch here, but AI-automated exploitation pipelines are a meaningful threat-modeling input — expect AI-assisted recon and attack chains to increase noise and speed against public-facing surfaces.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The summary surfaces no IOCs, TTPs, or detection-ready specifics; file as actor methodology context and watch for follow-on reporting that maps AI-assisted campaigns to ATT&amp;amp;CK techniques or provides hunt artifacts.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> If the organization uses Anthropic APIs or Claude-based tooling, add a vendor AI-misuse risk item to the register and draft or update an AI acceptable-use policy before this category of threat generates customer questionnaires or board questions.&lt;/li>
&lt;/ul></description></item></channel></rss>