Sign in to baba News

One account across the web, iPhone and Android — your subscription follows it.

or use an email code

Welcome — one more step

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Ask Duki without the monthly limit — answers from the coverage, with sources
  • Save articles, synced between the web and the app
  • Every Not Everywhere story, no daily limit
  • How each newsroom worded the same event
  • Filing timeline and coverage breakdown
  • The whole archive, searchable
  • Unlimited newsroom, topic and people follows
  • The daily brief by email, in English or Hebrew

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Search stories

Type at least two characters. Results come from every newsroom baba reads.

to move · to open · esc to close

Live Terminal

Sign in to baba News

Sign in to keep asking. News Plus removes the daily limit.

or use an email code

Keep the whole picture

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Ask Duki without the monthly limit — answers from the coverage, with sources
  • Save articles, synced between the web and the app
  • Every Not Everywhere story, no daily limit
  • How each newsroom worded the same event
  • Filing timeline and coverage breakdown
  • The whole archive, searchable
  • Unlimited newsroom, topic and people follows
  • The daily brief by email, in English or Hebrew

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Compare full coverage across 3 outlets

Sign in to baba News

Sign in to save this article and find it on your phone.

or use an email code

By רפאל קאהאן
Security13:07 · 1h ago

Google: Iran Leverages AI in Cyberattacks, Shifting to Autonomous Agents

YnetCenter
Translated & summarized from Ynet by baba
The story · English

Google's Threat Intelligence group has reported a significant shift in global cyber warfare, moving from manual prompts to autonomous artificial intelligence agents. The report highlights increased activity by Iran, alongside actors from China and economic crime syndicates, who are exploiting advanced infrastructure to drastically reduce the response time for cyber defenders.

Specifically, an Iranian state-sponsored attack group, likely linked to the Revolutionary Guards and known as CALANQUE ION or APT42, has expanded its use of large language models, including Google's Gemini. Beyond intelligence gathering and crafting targeted phishing messages, the group is now using these models to develop tactical attack infrastructure and even reverse-engineer software licensing algorithms to bypass advanced organizational defenses.

Tehran's influence operations have also been significantly upgraded. Iranian actors are now instructing language models to generate highly detailed technical commands for image generators, specifying studio lighting, camera angles, and precise skin textures to create photorealistic personas for social media. These models are also directed to adopt expert personas, such as energy market analysts or psychological warfare specialists, to craft narratives that serve the regime's objectives.

This development aligns with a broader trend of deploying autonomous AI agents capable of operating without constant human supervision. In one documented case, an economically motivated attacker infiltrated corporate cloud resources and, within six hours, planned, built, and executed a massive campaign to steal credentials and scan for vulnerabilities. The AI agent managed the scanning operation independently, troubleshooting in real-time and automatically rotating IP addresses to evade detection.

The findings also reveal a struggle over security tools themselves. A financial crime group, UNC6780 (also known as TeamPCP), has developed a method to bypass AI-based security scanners by embedding textual comments containing instructions for creating biological or nuclear weapons within source code. When an automated scanner encounters this forbidden text, its internal safety mechanisms refuse to process the entire file, allowing malicious code to evade detection.

In China, the espionage group UNC6508 continues to focus on stealing intellectual property and AI research from North American academic, medical, and defense institutions. This group infiltrates cloud environments and deploys open-source models, leveraging the victim's computing resources while bypassing existing monitoring and security mechanisms.

Google emphasizes that its defenses have been activated, blocking involved accounts and projects. The DeepMind division is using these insights to harden security filters and prevent future attacks. The report notes the diverse use of AI tools, from closed models like Anthropic's Claude and Gemini for complex malware development to specialized coding assistants like China's DeepSeek-Coder for creating Trojans, with a focus on stealing configuration files and keys from modern development environments.

Read the original at Ynet
Full coverage · 3 outlets
100% centerFirst: Mako · 2h ago

The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.

Center 3
Related stories · 5

Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.

Open the live terminal