Sign in to baba News

One account across the web, iPhone and Android — your subscription follows it.

or use an email code

Welcome — one more step

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Ask Duki without the monthly limit — answers from the coverage, with sources
  • Save articles, synced between the web and the app
  • Every Not Everywhere story, no daily limit
  • How each newsroom worded the same event
  • Filing timeline and coverage breakdown
  • The whole archive, searchable
  • Unlimited newsroom, topic and people follows
  • The daily brief by email, in English or Hebrew

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Search stories

Type at least two characters. Results come from every newsroom baba reads.

to move · to open · esc to close

Live Terminal

Sign in to baba News

Sign in to keep asking. News Plus removes the daily limit.

or use an email code

Keep the whole picture

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Ask Duki without the monthly limit — answers from the coverage, with sources
  • Save articles, synced between the web and the app
  • Every Not Everywhere story, no daily limit
  • How each newsroom worded the same event
  • Filing timeline and coverage breakdown
  • The whole archive, searchable
  • Unlimited newsroom, topic and people follows
  • The daily brief by email, in English or Hebrew

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Compare full coverage across 3 outlets

Sign in to baba News

Sign in to save this article and find it on your phone.

or use an email code

By דיגיטל
Security12:00 · 3h ago

Google Warns of AI Agents Used by Cyber Attackers, Iran

MakoCenter
Translated & summarized from Mako by baba
The story · English

Google's Threat Intelligence Group (GTIG) has released its Q2 2026 report, revealing a significant shift by malicious actors and nations towards employing autonomous AI agents. This advancement dramatically shortens attack timelines, outpacing traditional cyber defenses. The report highlights Iran's expanding use of AI, including models like Gemini, for developing attack infrastructure and conducting influence operations. Alongside Iranian activity, the report details sophisticated campaigns originating from China and financially motivated attacks executed within hours.

Iranian state-sponsored groups, such as CALANQUE ION (APT42), are leveraging large language models for intelligence gathering, rapid translation of phishing content, and developing tactical attack infrastructure. They are also reportedly reverse-engineering software licensing algorithms to bypass enterprise defenses. Iran's influence operations have also been upgraded, with AI models generating detailed prompts for image generators to create photorealistic fake personas and crafting messages using psychological manipulation techniques to serve the regime's interests.

The report specifically notes the rise of "Agentic AI," autonomous agents capable of independent decision-making and real-time problem-solving. In one instance, a financially motivated attacker used a chatbot and a simple prompt to plan, build, and execute a vulnerability scanning and password theft campaign in under six hours. The AI agent autonomously handled technical issues and rotated IP addresses to evade detection.

Further findings include the financial cyber group UNC6780 (TeamPCP) embedding extreme prompts, such as requests for biological or nuclear weapon development, within malicious code. This tactic aims to trigger safety mechanisms in AI-based security scanners, causing them to refuse analysis and allowing the underlying malware to evade detection.

Chinese cyber-espionage group UNC6508 is also identified for its prolonged campaign targeting academic, medical, and military research institutions in North America. Their focus is on stealing proprietary AI research by breaching cloud environments and establishing local models with "open weights" to exploit the victim's computing resources and evade commercial API monitoring.

Google stated that all identified malicious activities using its AI models triggered safety mechanisms, leading to the permanent blocking of associated accounts and projects. The company is using insights from these attack attempts to strengthen its safety filters and models. John Hultquist, Chief Analyst at Google Threat Intelligence, commented that "all adversarial actors are using AI to some extent," and their capabilities have significantly improved, posing a growing challenge as AI becomes more integrated into autonomous attack operations.

Read the original at Mako
Full coverage · 3 outlets
100% centerFirst: Mako · 3h ago

The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.

Center 3
Related stories · 5

Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.

Open the live terminal