ChatGPT and Claude are casually recommending malware while Linux leaks root
Cybersecurity is currently a giant dumpster fire, as AI assistants turn into unwitting malware distributors and decade-old operating system bugs wake up from their sleep.
Security researchers at Island uncovered a campaign named AgentBaiting, where attackers deployed 7,600 fake GitHub repositories to trick smart coding assistants. When users asked ChatGPT, Claude, or Gemini for tools, the bots happily pointed them toward fake AI skills containing hidden droppers that fetch the StealC malware.
Meanwhile, Qualys and Anthropic exposed a nine-year-old race condition in the XFS file system of the Linux kernel. Dubbed RefluXFS, this flaw lets unprivileged users overwrite protected system files on the disk to gain full root access on standard enterprise distributions like Red Hat Enterprise Linux and Fedora.
On the enterprise front, Check Point rushed out fixes for a critical authentication bypass in SmartConsole that exposed management servers directly to the web. Simultaneously, the Cl0p ransomware gang began exploiting a zero-day chain in PTC Windchill software, while EvilProxy phishing campaigns hijacked active Microsoft 365 sessions through compromised domain networks.
Modern cybersecurity infrastructure seems to rely entirely on pure optimism, as automated AI tools now hand system access over to attackers before human administrators even finish drinking their morning coffee.
Source: Island
Comments
This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.