🤖 Kaspersky Warns of Rising Cyber Threats Disguised as AI Services
At the Kaspersky APAC Cyber Security Weekend in Guangzhou, security experts highlighted growing risks as enterprises prioritize development speed over AI verification. • Threat Overview: Kaspersky identified 92,000 malicious attacks in 2026 disguised as popular AI platforms. Fake ChatGPT apps accounted for 49%, while Claude and Gemini each comprised 18%. • Agentic AI & Malware: Over 15,000 malware samples—including trojans, spyware, and backdoors—were found disguised as agentic AI software capable of stealing internal data. • Open-Source Supply Chain Risks: Cyberattackers are increasingly targeting open-source ecosystems like npm and PyPI. At least 10 major campaigns occurred since mid-2025, including a March 2026 attack on the widely used Axios library. • Enterprise Impact: 31% of enterprise businesses were affected by supply chain attacks last year, highlighting vulnerability in the ICT/BPM and software development pipeline. Additionally, an audit revealed over 250,000 potential CI/CD misconfigurations in GitHub Actions workflows. • Mitigation Strategies: Kaspersky urges organizations to harden development environments, establish clear trusted zones, and verify external code before execution to secure software creation without sacrificing productivity.