AIDARK / OBSERVER● MODE: ACTIVE

The next threat is already here.

AI is changing the attack surface in real time. AIDARK maps what is emerging and turns the noise into signals you can act on.

Open the threat labExplore the signals
01prompt injection02synthetic identity03agentic exposure04data provenance
APPLICATION-LAYER ATTACKS · LAST 24H · RELATIVE TRENDSAMPLE DATA
Source: Cloudflare Radar · sample snapshot
TOP ATTACK SOURCEUnited States
AUTOMATED TRAFFIC31%
MALICIOUS EMAIL4.2%
INTERACTIVE THREAT LAB

Pause. Verify. Then act.

Pick a scenario and make the call. Each ends with what actually happens and the habit that would have helped. Nothing leaves this page.

SIGNALS TO WATCH

New surface. New rules.

Three pressure points changing how teams build, defend and trust AI systems.

SIGNAL_001↗
⌁

Prompt injection

Instructions hidden in untrusted content can steer an AI system away from its intended task. Treat every retrieved document, page and tool result as input, not authority.

SIGNAL_002↗
◈

Synthetic identity

Voice and video clones make familiar verification weaker. A known voice is not proof. Confirm sensitive requests through a second, previously established channel.

SIGNAL_003↗
⌘

Agentic exposure

Agents act across tools and data. Scope permissions to the task, require human approval for consequential actions, and keep an auditable record of tool calls.

LEAKED CREDENTIALS · EMAIL SECURITY

Stolen logins don't expire on their own.

Attackers replay passwords from old breaches against new accounts, and Radar now tracks trends in login attempts that use known-leaked credentials. Few people ever check whether theirs are in those lists. It takes five minutes.

CHECK_001↗
◈

Check your email address

See which breaches included your addresses. Check work and personal ones, plus old addresses you still use.

haveibeenpwned.com ↗
CHECK_002↗
⌁

Check a password safely

Pwned Passwords uses k-anonymity: only the first five characters of a password's hash are sent, never the password. Any match means retire it everywhere.

Pwned Passwords ↗
CHECK_003↗
⌘

Then close the door

Replace reused passwords, use a password manager, and turn on phishing-resistant multi-factor authentication so a leaked password alone isn't enough.

✉

Email is where it starts

Without SPF, DKIM and DMARC, anyone can send mail that appears to come from your domain. Radar tracks how widely they're adopted and how much email is malicious. Check your own domain's records, and set DMARC to enforce once reports look clean.

FIELD GUIDE

Useful beats unafraid.

Habits that hold up whether the threat is a person, a model or a convincing imitation.

⌁

Verify out of band

For money, access or sensitive data, use a contact method you already trust. Never use the callback number or link in the unexpected request.

◈

Give AI tools the least access they need

Limit connected data and permissions. Require a human checkpoint before an AI system sends, changes, buys or deletes anything important.

⌘

Assume pasted content can mislead

Documents and web pages may carry hidden instructions aimed at AI assistants. Keep system instructions separate from retrieved content.

↺

Make recovery boring

Use phishing-resistant multi-factor authentication where you can. Keep recovery codes offline, and rehearse how to revoke sessions and rotate keys.