In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years
SecurityWeek’s weeklycybersecurity news roundupoffers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape.
This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers stay well-informed about the evolving cybersecurity environment.
Here are this week’s highlights:
PoeLLM malware finds its C&C server hidden in a GitHub poem
Black Lotus Labs has detailed PoeLLM, a malware active since at least April 2026 that targets exposed AI and open-source services (mainly LiteLLM, Ollama, Gotenberg and Gitea) to mine cryptocurrency and expand its botnet. Infected machines extract four keywords from a poem hosted on GitHub and convert them into the IP address of the current C&C server, so the operator can switch servers by changing those words. The operator, assessed to be Italian-speaking, has updated the...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE