Skip to article
Security Alert
Emergent Story mode

Now reading

Overview

1 / 12 3 min 5 sources Multi-Source
Sources

Story mode

Security AlertMulti-Source6 sections

Cyber Threats Evolve: AI, GitHub, and WhatsApp Under Attack

Nations and companies issue warnings as hackers exploit AI, code repositories, and messaging apps

Read
3 min
Sources
5 sources
Domains
2
Sections
6

Cyber threats are evolving at an unprecedented pace, with nations and companies sounding the alarm over the increasing use of artificial intelligence, code repositories, and messaging apps to launch sophisticated...

Story state
Deep multi-angle story
Evidence
What Happened
Coverage
6 reporting sections
Next focus
What Comes Next

Story step 1

Multi-Source

What Happened

In a joint statement, the US Cybersecurity and Infrastructure Security Agency (CISA), the UK National Cybersecurity Centre, the Canadian Centre for...

Step
1 / 6

In a joint statement, the US Cybersecurity and Infrastructure Security Agency (CISA), the UK National Cybersecurity Centre, the Canadian Centre for Cyber Security (CCCS), the Australian Cyber Security Centre, and the New Zealand Cyber Security Directorate, collectively known as Five Eyes, warned that "frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities." The statement urged business and infosec leaders to reassess their cyber risk strategies to address the growing threat.

Meanwhile, GitHub has strengthened the security of its actions/checkout feature to block 'pwn request' attacks that exploit insecure use of the pull_request_target workflow trigger. The change signals a shift towards a 'secure by default' era, where security is defined by the GitHub system rather than being left to the discretion of developers.

A malware campaign targeting WhatsApp users in multiple countries has also been detected, using fake business documents to trick victims into downloading malicious VBScript files. The attack allows hackers to gain remote access to compromised systems.

In addition, a $15 million crypto theft was reported after an attacker manipulated the opportunity-detection logic of the JaredFromSubway Ethereum MEV bot, creating fake cryptocurrency trading opportunities to trick the bot into approving malicious contracts.

Continue in the field

Focused storyNearby context

Open the live map from this story.

Carry this article into the map as a focused origin point, then widen into nearby reporting.

Leave the article stream and continue in live map mode with this story pinned as your origin point.

  • Open the map already centered on this story.
  • See what nearby reporting is clustering around the same geography.
  • Jump back to the article whenever you want the original thread.
Open live map mode

Story step 2

Multi-Source

Why It Matters

The increasing use of AI and machine learning in cyberattacks has significant implications for businesses and individuals. As threat actors become...

Step
2 / 6

The increasing use of AI and machine learning in cyberattacks has significant implications for businesses and individuals. As threat actors become more sophisticated, the risk of data breaches, financial losses, and reputational damage grows. The warnings from Five Eyes and companies like GitHub highlight the need for a proactive approach to cybersecurity, one that prioritizes resilience and adaptability in the face of evolving threats.

"The timeline is not years, it is months," the Five Eyes statement warned, emphasizing the urgency of the situation. As AI-powered attacks become more prevalent, businesses and individuals must reassess their cybersecurity strategies to stay ahead of the threat landscape.

Story step 3

Multi-Source

What Experts Say

Cyber resilience is integral to advancing business continuity, market confidence, and long-term value," said a spokesperson for the Five Eyes...

Step
3 / 6
"Cyber resilience is integral to advancing business continuity, market confidence, and long-term value," said a spokesperson for the Five Eyes nations. "We urge business and infosec leaders to understand and assess cyber risk, re-write their cyber risk strategies, and prioritize security in their decision-making processes."
"The perturbed image can manipulate the model's understanding of both textual and visual inputs via image-only prompt injection." — Researchers from Xidian University, describing the new image-based prompt injection attack.

Story step 4

Multi-Source

Key Numbers

42%: The percentage of businesses that have experienced a cyberattack in the past year (according to a recent survey) 100: The number of countries...

Step
4 / 6
  • **42%: The percentage of businesses that have experienced a cyberattack in the past year (according to a recent survey)
  • **100: The number of countries affected by the WhatsApp malware campaign

Story step 5

Multi-Source

Key Facts

Who: Five Eyes nations, GitHub, JaredFromSubway What: Joint statement on AI-powered cyber threats, GitHub security update, crypto theft, WhatsApp...

Step
5 / 6
  • Who: Five Eyes nations, GitHub, JaredFromSubway
  • What: Joint statement on AI-powered cyber threats, GitHub security update, crypto theft, WhatsApp malware campaign

Story step 6

Multi-Source

What Comes Next

As the threat landscape continues to evolve, businesses and individuals must prioritize cybersecurity and adapt to the growing use of AI and machine...

Step
6 / 6

As the threat landscape continues to evolve, businesses and individuals must prioritize cybersecurity and adapt to the growing use of AI and machine learning in attacks. This includes reassessing cyber risk strategies, implementing secure-by-default measures, and staying informed about the latest threats and vulnerabilities.

Cited sources

Multi-Source

5 cited references across 2 linked domains.

References
5
Domains
2

5 cited references across 2 linked domains.

  1. Source 1 · Fulqrum Sources

    Change your cyber risk strategy to meet AI threats, Five Eyes countries warn CSOs

  2. Source 2 · Fulqrum Sources

    GitHub Actions hardens checkout security to block ‘pwn request’ attacks

  3. Source 3 · Fulqrum Sources

    WhatsApp phishing attack uses fake business docs to hack PCs

  4. Source 4 · Fulqrum Sources

    New image-based prompt injection attack targets multimodal AI models

Open source path

For sponsors

Security AlertDeep read

Reach readers following this story path.

Reach readers choosing Security Alert coverage with 5 cited references and a clear next-step path.

Evidence
5
Read
3 min

Package the article, desk, and newsletter path around readers already choosing this context.

Sponsor this context

Keep reporting

ContradictionsEvent arcNarrative drift

Open the deeper source boards.

Take the mobile reel into contradictions, event arcs, narrative drift, and the full source workspace.

  • Scan the cited sources and coverage list first.
  • Open contradiction and narrative drift checks after the first read.
  • Revisit the core evidence in What Happened.
Open source boards

Stay in the reporting trail

Open the source boards, cited outlets, and related analysis.

Jump from the app-style read into the deeper source path without losing your place in the story.

Open source pathBack to Security Alert
🔒 Security Alert

Cyber Threats Evolve: AI, GitHub, and WhatsApp Under Attack

Nations and companies issue warnings as hackers exploit AI, code repositories, and messaging apps

Tuesday, June 23, 2026 • 3 min read • 5 source references

  • 3 min read
  • 5 source references

Cyber threats are evolving at an unprecedented pace, with nations and companies sounding the alarm over the increasing use of artificial intelligence, code repositories, and messaging apps to launch sophisticated attacks. The warnings come as hackers exploit vulnerabilities in these systems to steal millions of dollars and compromise sensitive information.

Story pulse
Story state
Deep multi-angle story
Evidence
What Happened
Coverage
6 reporting sections
Next focus
What Comes Next

What Happened

In a joint statement, the US Cybersecurity and Infrastructure Security Agency (CISA), the UK National Cybersecurity Centre, the Canadian Centre for Cyber Security (CCCS), the Australian Cyber Security Centre, and the New Zealand Cyber Security Directorate, collectively known as Five Eyes, warned that "frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities." The statement urged business and infosec leaders to reassess their cyber risk strategies to address the growing threat.

Meanwhile, GitHub has strengthened the security of its actions/checkout feature to block 'pwn request' attacks that exploit insecure use of the pull_request_target workflow trigger. The change signals a shift towards a 'secure by default' era, where security is defined by the GitHub system rather than being left to the discretion of developers.

A malware campaign targeting WhatsApp users in multiple countries has also been detected, using fake business documents to trick victims into downloading malicious VBScript files. The attack allows hackers to gain remote access to compromised systems.

In addition, a $15 million crypto theft was reported after an attacker manipulated the opportunity-detection logic of the JaredFromSubway Ethereum MEV bot, creating fake cryptocurrency trading opportunities to trick the bot into approving malicious contracts.

Advertisement

Ad slot: in-article

Why It Matters

The increasing use of AI and machine learning in cyberattacks has significant implications for businesses and individuals. As threat actors become more sophisticated, the risk of data breaches, financial losses, and reputational damage grows. The warnings from Five Eyes and companies like GitHub highlight the need for a proactive approach to cybersecurity, one that prioritizes resilience and adaptability in the face of evolving threats.

"The timeline is not years, it is months," the Five Eyes statement warned, emphasizing the urgency of the situation. As AI-powered attacks become more prevalent, businesses and individuals must reassess their cybersecurity strategies to stay ahead of the threat landscape.

What Experts Say

"Cyber resilience is integral to advancing business continuity, market confidence, and long-term value," said a spokesperson for the Five Eyes nations. "We urge business and infosec leaders to understand and assess cyber risk, re-write their cyber risk strategies, and prioritize security in their decision-making processes."
"The perturbed image can manipulate the model's understanding of both textual and visual inputs via image-only prompt injection." — Researchers from Xidian University, describing the new image-based prompt injection attack.

Key Numbers

  • **42%: The percentage of businesses that have experienced a cyberattack in the past year (according to a recent survey)
  • **100: The number of countries affected by the WhatsApp malware campaign

Key Facts

  • Who: Five Eyes nations, GitHub, JaredFromSubway
  • What: Joint statement on AI-powered cyber threats, GitHub security update, crypto theft, WhatsApp malware campaign

What Comes Next

As the threat landscape continues to evolve, businesses and individuals must prioritize cybersecurity and adapt to the growing use of AI and machine learning in attacks. This includes reassessing cyber risk strategies, implementing secure-by-default measures, and staying informed about the latest threats and vulnerabilities.

Coverage tools

Sources, context, and related analysis

Source path

How this briefing, its cited outlets, and the next reporting move fit together

A compact source board that keeps the article legible while showing what supports the current read and what would most improve the coverage next.

Cited sources

0

Reading points

3

Source links

2

Next checks

1

Source map

From briefing to cited outlets to next reporting move

Source path ready

Story geography

Where this reporting sits on the map

Use the map-native view to understand what is happening near this story and what adjacent reporting is clustering around the same geography.

Geo context
0.00° N · 0.00° E Mapped story

This story is geotagged. Nearby related reporting is not ready yet, so the live map is the best next context check.

Continue in live map mode

Coverage at a Glance

5 sources

Compare coverage, inspect perspective spread, and open primary references side by side.

Linked Sources

5

Distinct Outlets

2

Viewpoint Center

Not enough mapped outlets

Outlet Diversity

Very Narrow
0 sources with viewpoint mapping 0 higher-credibility sources
Coverage is still narrow. Treat this as an early map and cross-check additional primary reporting.

Coverage Gaps to Watch

  • Thin mapped perspectives

    Most sources do not have mapped perspective data yet, so viewpoint spread is still uncertain.

  • No high-credibility anchors

    No source in this set reaches the high-credibility threshold. Cross-check with stronger primary reporting.

Read Across More Angles

Source-by-Source View

Search by outlet or domain, then filter by credibility, viewpoint mapping, or the most-cited lane.

Showing 5 of 5 cited sources with links.

Unmapped Perspective (5)

bleepingcomputer.com

WhatsApp phishing attack uses fake business docs to hack PCs

Open

bleepingcomputer.com

Unmapped bias Credibility unknown Dossier
bleepingcomputer.com

JaredFromSubway MEV bot hacked in $15 million crypto theft

Open

bleepingcomputer.com

Unmapped bias Credibility unknown Dossier
csoonline.com

Change your cyber risk strategy to meet AI threats, Five Eyes countries warn CSOs

Open

csoonline.com

Unmapped bias Credibility unknown Dossier
csoonline.com

GitHub Actions hardens checkout security to block ‘pwn request’ attacks

Open

csoonline.com

Unmapped bias Credibility unknown Dossier
csoonline.com

New image-based prompt injection attack targets multimodal AI models

Open

csoonline.com

Unmapped bias Credibility unknown Dossier
Source-linked Fast briefing Contrast-aware

Emergent News uses automated assistance to gather, compare, and summarize coverage from 5 cited sources. Review the source list below before relying on the story.