Urgent.News

What's breaking now, across thousands of outlets.

AI

Criminals have moved AI out of testing and into daily use, Flashpoint finds

A new report from threat intelligence company Flashpoint has found that criminals now use artificial intelligence in day-to-day operations, well past the experimental stage. The 2026 Global Threat Intelligence Report: Midyear Edition covers the first six months of the year. Flashpoint’s analysts worked through 3.9 petabytes of material for it, most of it lifted from […] The post Criminals have…

Criminals have moved AI out of testing and into daily use, Flashpoint finds

Flashpoint, a threat intelligence company, has released a report indicating that criminals have transitioned artificial intelligence (AI) from experimental phases to everyday operations. The 2026 Global Threat Intelligence Report: Midyear Edition examined the first half of 2026. The report analyzed 3.9 petabytes of data, largely sourced from illicit online forums and secure channels connected to cybercriminals.

The findings show that criminal AI toolkits were referenced in over 22 million posts. Criminals now utilize custom language models with the safety features disabled, deployed on personal infrastructure they manage. This development makes their activities more challenging to detect and hampers defensive measures.

Josh Lefkowitz, Flashpoint's co-founder and chief executive, explained that AI significantly reduces the time between opportunity and exploitation. What once required considerable expertise to build can now be achieved with minimal effort. In the six-month period covered by the report, an infostealer malware infected 7.4 million hosts worldwide, resulting in the theft of 1.7 billion credentials and identity artifacts.

The most prolific malware included Vidar, StealC, and Lumma, which offered subscription services to surreptitiously harvest active browser session tokens from compromised machines. Session tokens provide unauthorized access without the need for passwords. A quarter of vulnerability disclosures included ready-to-use exploit code attached, numbering 21,667 in total.

Flashpoint logged 4,015 exploit codes, with 6,808 blocked before reaching the National Vulnerability Database. Over 34% of vulnerabilities were classified as critical or high on the Common Vulnerability Scoring System (CVSS) scale. Fifty-five percent of these vulnerabilities were targeted by attackers. Ransomware victimization increased by 45% from the first half of 2025 to 6,256 cases, with 2,669 of them occurring in the U.S. manufacturing sector.

Qilin led the list with 901 victims, followed by Akira, 0APT, The Gentlemen, and Dragon Force, accounting for 44% of all ransomware activity during the period. Despite the rise in ransomware, total ransom payments on the blockchain decreased by approximately 8% to $820 million, according to Chainalysis data cited in the report. The proportion of victims who paid ransom dropped to 28%, potentially marking an all-time low.

The report also linked recent military conflict in the Middle East to an increase in state-sponsored cyber operations targeting supply chains, financial institutions, and industrial control systems. Flashpoint identified several wiper families associated with these campaigns, some of which were traced back to the Handala Hack group and APT39.

The data underscores that cybercrime remains an ecosystem economy, with each stage specializing further. Understanding the relationships between these actor ecosystems provides a stronger indication of emerging threats. Flashpoint's vice president of intelligence, Ian Gray, emphasized the importance of disrupting individual campaigns while highlighting the significance of comprehending the interconnectedness of threat actors.

Written by urgent.news from SiliconANGLE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at siliconangle.com →

More in AI

What Is Free on ChatGPT in 2026?

ChatGPT Free includes far more than basic chat. Here's what you can use without paying, where the limits apply, and when an upgrade makes sense. The post What Is Free on ChatGPT in 2026?

More from Thursday 13 August →