A threat actor is deploying open-source AI agent frameworks to compromise hundreds of online retailers at scale, harvesting over 600,000 credit card records through payment skimmers.
Cybersecurity researchers have identified a financially motivated threat actor leveraging AI agent technology to automate large-scale attacks against e-commerce platforms. The campaign uses open-source AI frameworks to scan and compromise more than 100 websites, injecting payment skimmers that capture credit card data during checkout.
The attackers have successfully stolen 600,000+ credit card records, making this one of the largest automated retail card theft operations documented. The use of AI agents significantly amplifies the attack surface by enabling the threat actor to identify vulnerabilities and deploy malware across multiple targets with minimal manual intervention.
Open-source AI agent frameworks—tools designed to automate complex tasks and decision-making—have been repurposed for malicious reconnaissance and exploitation. These systems scan target websites, identify payment processing systems, and deploy skimming code without requiring extensive manual configuration for each victim.
Retailers affected span multiple industries and geographic regions. The skimmers intercept payment card information at the point of transaction, before encryption occurs, allowing attackers to harvest data in real-time. Victims typically remain unaware until fraudulent charges appear or payment processors detect anomalies.
Security researchers recommend retailers implement robust intrusion detection systems, conduct regular security audits, and monitor for unauthorized code injection. Payment processors advise monitoring for unusual transaction patterns and implementing additional fraud detection measures.
The incident highlights growing threats posed by accessible AI tools being weaponized for cybercrime. As AI agent frameworks become more sophisticated and widely available, defenders face escalating challenges in securing infrastructure against automated, adaptable attacks. Organizations are urged to update security protocols and increase incident response capabilities to address threats leveraging AI-driven exploitation techniques.
A limited-permission Kubernetes user can potentially gain full control of a Google Cloud organization by exploiting the Google Kubernetes Config Connector. The vulnerability represents a classic confused deputy problem in cloud infrastructure.
Enterprise infrastructure management systems are under sustained attack, with critical vulnerabilities being exploited before or immediately after vendor patches become available, according to a new InfraTrust report.
Comma's hands-off driving technology is being investigated following at least two fatal crashes. The inquiry involves instances where drivers were operating modified versions of Comma's software.
Sweden's data privacy regulator IMY has fined IT systems provider Miljödata $183,000 for inadequate security measures that led to a data breach in August 2025. The incident exposed personal information of 2.2 million individuals.