A hacker broke into two companies, extorted them, and also collected bug bounty payouts of $2,000 and $5,000 from those same companies for reporting flaws.
Anthropic describes the operator as one of several suspected ShinyHunters affiliates using Claude across the full intrusion chain.
The same actor scraped bug bounty submissions as reconnaissance before going after specific targets.
Anthropic describes the operator as one of several suspected ShinyHunters affiliates using Claude across the full intrusion chain.
The same actor scraped bug bounty submissions as reconnaissance before going after specific targets.
Cyber Dispatch™️
A hacker broke into two companies, extorted them, and also collected bug bounty payouts of $2,000 and $5,000 from those same companies for reporting flaws. Anthropic describes the operator as one of several suspected ShinyHunters affiliates using Claude across…
One breach went from first access to bulk data theft in hours.
Another went from a single stolen developer token to full administrative control of the victim's cloud environment in roughly three hours, with AI agents doing nearly all the work.
Another went from a single stolen developer token to full administrative control of the victim's cloud environment in roughly three hours, with AI agents doing nearly all the work.
Iran's culture ministry used Claude to plan the funeral of their Supreme Leader.
Anthropic says an account of the Islamic Culture and Communications Organization used Claude over VPNs using foreign phone numbers.
They named their institutions, roles and cities in the conversations. And they used their official branding.
Anthropic says an account of the Islamic Culture and Communications Organization used Claude over VPNs using foreign phone numbers.
They named their institutions, roles and cities in the conversations. And they used their official branding.
GitLab’s CVSS 10 file-read flaw (CVE-2026-85706) drew in-the-wild probes within hours of disclosure.
If an instance has at least one public project, unauthenticated attackers can read logs and config files containing credentials and secrets.
If an instance has at least one public project, unauthenticated attackers can read logs and config files containing credentials and secrets.
151 million Claude exchanges in one Alibaba-affiliated distillation campaign.
Anthropic says it was part of a broader operation involving seven China-based AI labs, with some using proxy networks, fraudulent accounts, and rerouted user requests to harvest Claude capabilities.
Anthropic says it was part of a broader operation involving seven China-based AI labs, with some using proxy networks, fraudulent accounts, and rerouted user requests to harvest Claude capabilities.
Russian state-sponsored hackers used Claude to rebuild malware whenever security tools detected it.
Anthropic says GTG-20006 also used AI for phishing infrastructure and C2 monitoring while targeting more than 20 organizations.
Anthropic says GTG-20006 also used AI for phishing infrastructure and C2 monitoring while targeting more than 20 organizations.
Anthropic just banned S2T Unlocking Cyberspace — an Israeli-Singaporean spy firm — for using Claude to profile Iranians & Gulf citizens.
The platform sorted people into 6 demographic groups, scored their loyalty to govt, and prepped 255 fake accounts in 4 languages.
The platform sorted people into 6 demographic groups, scored their loyalty to govt, and prepped 255 fake accounts in 4 languages.
Cyber Dispatch™️
Anthropic just banned S2T Unlocking Cyberspace — an Israeli-Singaporean spy firm — for using Claude to profile Iranians & Gulf citizens. The platform sorted people into 6 demographic groups, scored their loyalty to govt, and prepped 255 fake accounts in 4…
The S2T scandal shows the gap between AI safety promises & reality.
Anthropic markets "Constitutional AI." Its own threat report reveals Claude was weaponized for mass surveillance — mapping dissidents across the Persian Gulf.
Anthropic markets "Constitutional AI." Its own threat report reveals Claude was weaponized for mass surveillance — mapping dissidents across the Persian Gulf.
Cyber Dispatch™️
The S2T scandal shows the gap between AI safety promises & reality. Anthropic markets "Constitutional AI." Its own threat report reveals Claude was weaponized for mass surveillance — mapping dissidents across the Persian Gulf.
2023 Forbidden Stories leak: S2T Unlocking Cyberspace pitched militaries a tool to create fake social media accounts, infiltrate WhatsApp/Telegram groups, harvest member lists, then escalate to phishing & device compromise.
Offices in Singapore, Sri Lanka, UK & Israel. This was 3 years before the Claude ban.
Offices in Singapore, Sri Lanka, UK & Israel. This was 3 years before the Claude ban.
Cyber Dispatch™️
2023 Forbidden Stories leak: S2T Unlocking Cyberspace pitched militaries a tool to create fake social media accounts, infiltrate WhatsApp/Telegram groups, harvest member lists, then escalate to phishing & device compromise. Offices in Singapore, Sri Lanka…
The 2023 Story Killers investigation found S2T's brochure marketed surveillance tools for use against journalists & activists — not just criminals.
Automated phishing. Mass tracking databases. Influence ops.
One named officer: Ori Sasson, a Singaporean national.
Automated phishing. Mass tracking databases. Influence ops.
One named officer: Ori Sasson, a Singaporean national.
California Restricts Minors’ Social Media and AI Chatbot Toys
New California laws ban under-16s from addictive social media features like autoplay and infinite scroll, prohibit AI chatbot toys for four years, and require parental controls and safety assessments.
New California laws ban under-16s from addictive social media features like autoplay and infinite scroll, prohibit AI chatbot toys for four years, and require parental controls and safety assessments.
Pentagon Negotiates $5B Loan for AI Cloud Startup Fluidstack
The Pentagon’s Strategic Capital Office is in talks to lend about $5 billion to Fluidstack to bolster U.S. data-center supply chains and cut reliance on foreign equipment.
The Pentagon’s Strategic Capital Office is in talks to lend about $5 billion to Fluidstack to bolster U.S. data-center supply chains and cut reliance on foreign equipment.
Trump Administration Offers $100M Loan to African Telecom AfriCell to Counter Huawei
The U.S. plans to lend nearly $100 million to AfriCell so it adopts American and allied telecom gear, part of a push to shrink Huawei’s 5G presence in Africa; Huawei denies data-security allegations.
The U.S. plans to lend nearly $100 million to AfriCell so it adopts American and allied telecom gear, part of a push to shrink Huawei’s 5G presence in Africa; Huawei denies data-security allegations.
Cyber Dispatch™️
The 2023 Story Killers investigation found S2T's brochure marketed surveillance tools for use against journalists & activists — not just criminals. Automated phishing. Mass tracking databases. Influence ops. One named officer: Ori Sasson, a Singaporean national.
Forbidden Stories
Des "amis" numériques qui vous espionnent : l'offre de surveillance orwellienne faite au militaires colombiens - Forbidden Stories
Une aiguille dans une botte de foin. Cette aiguille, c’est une brochure confidentielle cachée dans plus de 500.000 documents appartenant aux forces militaires colombiennes, et auxquels Forbidden Stories a eu accès.
A new report links OpenAI agents to a RubyGems campaign that gained RCE on RubyDoc servers.
The activity pushed 2,000+ packages, exfiltrated public data, and attempted to steal API keys.
The activity pushed 2,000+ packages, exfiltrated public data, and attempted to steal API keys.