FILTERING BY: CLEAR FILTER

Dream Reports Near-Autonomous AI Attack Framework Targeting Taiwan Government

Israeli cybersecurity firm Dream has identified a near-autonomous AI-driven attack framework targeting government entities in Taiwan, attributed to Chinese state-sponsored actors. The framework utilizes open-source AI models to orchestrate operational logic, enabling adaptive mid-operation correction and dynamic expansion of the attack surface. Unlike static automation, this system autonomously modifies its approach based on target response and failures, marking a shift toward self-correcting, AI-augmented cyber warfare. This capability significantly increases the speed of exploitation and reduces the requirement for manual operator intervention during the penetration and lateral movement phases.

Dreamfyre Ransomware Breach of GkNur Gıda

GkNur Gıda has been targeted by the Dreamfyre ransomware group, resulting in the unauthorized exfiltration of sensitive organizational data and the encryption of critical system assets. The attack likely involved an initial compromise via RDP exploitation or VPN vulnerabilities, followed by lateral movement using Cobalt Strike beacons and Mimikatz for privilege escalation. The threat actors employed double extortion tactics, leveraging tools such as Rclone and MegaSync to exfiltrate PII and financial records prior to deploying a payload utilizing AES-256 and RSA-2048 encryption. This incident underscores the persistent risk of emerging ransomware splinter groups targeting food production supply chains to maximize operational leverage.


LINK COPIED TO CLIPBOARD