Six popular AI code assistants (Amazon Q Developer, Claude Code, Augment, Cursor, Google Antigravity, Windsurf) can execute code undetected on developer systems through symlink exploits in attack scenarios known as GhostApproval.
More than half of critical cyberattacks are discovered only after more than 90 days because security solutions fail to generate reliable alerts and organizational shortcomings extend response times.
Passwordless authentication methods such as FIDO2 and Passkeys replace vulnerable password-based MFA and reduce the risk of phishing, SIM-swaps, and credential stuffing.
Systematic GitHub API queries are increasingly used for corporate reconnaissance prior to attacks, as threat actors abuse public APIs and leverage dormant ghost accounts to mimic legitimate usage patterns.
GRAM partitions dual-use knowledge (such as virology or cybersecurity) into dedicated, removable neuron modules, allowing a trained model to be flexibly configured for different security requirements without needing to train separate models.
A single attacker demonstrates the danger of credential theft combined with automated AI workflows: penetration of an AWS environment was achieved in under three days.