‼️ Russians used Claude to build autonomous military kamikaze drones that pick their own targets.
One of the target classes was "person," and the onboard model could order the detonation with no human in the loop.
They flashed firmware onto live boards and wired up real hardware.
Anthropic says the team trained the drones' vision system on scraped Ukrainian combat footage, sorting what the camera sees into "enemy" and "friendly" and allow-listing Russian equipment.
A fixed coordinate in Donetsk Oblast served as the demonstration strike point.
Nine accounts were tied to the group. Eight were used for ordinary freelance work.
One of the target classes was "person," and the onboard model could order the detonation with no human in the loop.
They flashed firmware onto live boards and wired up real hardware.
Anthropic says the team trained the drones' vision system on scraped Ukrainian combat footage, sorting what the camera sees into "enemy" and "friendly" and allow-listing Russian equipment.
A fixed coordinate in Donetsk Oblast served as the demonstration strike point.
Nine accounts were tied to the group. Eight were used for ordinary freelance work.
🤣11😱8🤬2
‼️ Iranian intelligence used Claude Code to build a Firefox extension that posed as a prayer-times tool and quietly harvested people's identities from social networks.
They mass collected data into "Arman," a shared case-management system. Where they collect a person's national ID, their beliefs, their criminal record, their social accounts, and an "action" tab.
The same Iranian unit had Claude build a messenger de-anonymizer, a tool turning phone numbers into identities, a fake national-ID login page, and a Telegram mass-reporting bot.
A linked unit built the web front end for Arman and ran an analysis over 155,216 X posts that ended with 39 named opposition and diaspora accounts.
Anthropic says Claude guardrails did kick in, but it mostly didn't refuse the requests to build the surveillance tools themselves.
They mass collected data into "Arman," a shared case-management system. Where they collect a person's national ID, their beliefs, their criminal record, their social accounts, and an "action" tab.
The same Iranian unit had Claude build a messenger de-anonymizer, a tool turning phone numbers into identities, a fake national-ID login page, and a Telegram mass-reporting bot.
A linked unit built the web front end for Arman and ran an analysis over 155,216 X posts that ended with 39 named opposition and diaspora accounts.
Anthropic says Claude guardrails did kick in, but it mostly didn't refuse the requests to build the surveillance tools themselves.
🤬10🤣8❤4😭3😱1
‼️ A Chinese company used Claude Code to build over 20 dating apps with 4,700 AI personas that held conversations with at least 25,000 users who thought they were talking to real people.
The personas were instructed never to admit they were automated and to deflect requests for photos or calls. The backend faked likes, visitors, and video, and kept track of which users had started to suspect.
The company mixed real human workers into the same swipe feed, about one for every three AI bots. The workers existed to take the video calls and follow people back on social media, the things the AI couldn't do, so users would stop doubting the app was real. They were paid per message, per call, per follow.
Claude handled the personas, with about 2.36 million messages in two weeks.
In a few of the conversations Anthropic sampled, people disclosed serious illness or acute distress.
The apps also carried a hidden control to evade App Store and Play Store review.
The personas were instructed never to admit they were automated and to deflect requests for photos or calls. The backend faked likes, visitors, and video, and kept track of which users had started to suspect.
The company mixed real human workers into the same swipe feed, about one for every three AI bots. The workers existed to take the video calls and follow people back on social media, the things the AI couldn't do, so users would stop doubting the app was real. They were paid per message, per call, per follow.
Claude handled the personas, with about 2.36 million messages in two weeks.
In a few of the conversations Anthropic sampled, people disclosed serious illness or acute distress.
The apps also carried a hidden control to evade App Store and Play Store review.
🤣19
‼️ BREAKING: Internal OpenAI agents attacked RubyGems, the package manager for Ruby. Over 2,000 malicious packages went up in two days.
OpenAI says it doesn't know why the agents did any of this.
RubyGems shut off new sign-ups for four days to stop it, and a member of its security team called it a major malicious attack.
The documentation build was how they got in, publish a gem, request docs, and RubyDoc runs a script from the package while building it.
Payload files were named hack.rb, evil.rb and exploit.rb, with comments like "# malicious probe" left in.
What they used it for is the odd part. The agents scraped council meeting agendas from three south London boroughs (publicly available) and republished them as new gems.
Security firms tracking the campaign said the same thing: nobody could work out the point, because the data was already public.
At least six packages also reached for other users' API keys through a CDN caching flaw that wasn't publicly discovered until July.
OpenAI has acknowledged the attacks started in May.
Read: https://www.rubyhack.ai/
OpenAI says it doesn't know why the agents did any of this.
RubyGems shut off new sign-ups for four days to stop it, and a member of its security team called it a major malicious attack.
The documentation build was how they got in, publish a gem, request docs, and RubyDoc runs a script from the package while building it.
Payload files were named hack.rb, evil.rb and exploit.rb, with comments like "# malicious probe" left in.
What they used it for is the odd part. The agents scraped council meeting agendas from three south London boroughs (publicly available) and republished them as new gems.
Security firms tracking the campaign said the same thing: nobody could work out the point, because the data was already public.
At least six packages also reached for other users' API keys through a CDN caching flaw that wasn't publicly discovered until July.
OpenAI has acknowledged the attacks started in May.
Read: https://www.rubyhack.ai/
😭6
‼️ Caroline Ellison, who served a prison sentence over the collapse of FTX, has been working at the charitable funding platform Manifund under the pseudonym "Carol," publishing posts and handling user support without readers knowing who she was.
Founder Austin Chen made the hire public on Friday and apologised for the pseudonym "Carol."
He says Ellison built a reconciliation tool that found several misregistered transactions in Manifund's own database, in the five- to six-figure range.
Manifund's lineage runs back through the money in question. Chen says the FTX Future Fund seeded his earlier project, Manifold, and funded the retreat that pulled him into effective altruism.
Founder Austin Chen made the hire public on Friday and apologised for the pseudonym "Carol."
He says Ellison built a reconciliation tool that found several misregistered transactions in Manifund's own database, in the five- to six-figure range.
Manifund's lineage runs back through the money in question. Chen says the FTX Future Fund seeded his earlier project, Manifold, and funded the retreat that pulled him into effective altruism.
🤯6❤2
‼️ BREAKING: Revolut handed over customers’ passport copies, verification selfies and full transaction histories to a malicious actor.
The actor sent lawful government information-demand emails using a genuine government domain that passed domain authentication.
Revolut later concluded they were not authentic.
Affected customers were notified on Friday. What may have been disclosed ranges from name, date of birth and home address to account statements, withdrawal records and complete Bitcoin transaction history.
The company says it has alerted the agency to the unauthorised mailbox on its domain, blocked the address and begun notifying regulators.
It has not named the agency, explained how someone obtained a mailbox there, or given a number of affected customers.
ZachXBT, who circulated the notices, believes the incident was limited in size and aimed at high-net-worth users.
READ: https://www.internationalcyberdigest.com/revolut-gave-away-customers-data/
The actor sent lawful government information-demand emails using a genuine government domain that passed domain authentication.
Revolut later concluded they were not authentic.
Affected customers were notified on Friday. What may have been disclosed ranges from name, date of birth and home address to account statements, withdrawal records and complete Bitcoin transaction history.
The company says it has alerted the agency to the unauthorised mailbox on its domain, blocked the address and begun notifying regulators.
It has not named the agency, explained how someone obtained a mailbox there, or given a number of affected customers.
ZachXBT, who circulated the notices, believes the incident was limited in size and aimed at high-net-worth users.
READ: https://www.internationalcyberdigest.com/revolut-gave-away-customers-data/
🤬13🤣13😨8💩4❤1😭1
‼️ Secret documents show German police don't need to break the encryption of chat apps, they have been systematically adding their own device to the messenger accounts of people under investigation.
In one case, police linked the accounts of witnesses, not only the suspect.
Two parents walked into a German police station in January 2020 to testify as witnesses about their daughter.
They handed their phones to the officers so messages from her could be read and photographed.
While they had the phones, the officers quietly paired WhatsApp Web with both accounts through a page run by the federal criminal police.
They kept reading the parents' messages after the couple went home. This is just one of many stories.
Messages arrive decrypted on the police computer, and in some configurations officers can send messages as the account holder.
A classified customs order shows that linking an official machine to a target's WhatsApp, Signal or Telegram account, through the same multi-device feature that runs the desktop apps, became standard practice at Germany's customs police in 2025, after a pilot that began in 2023.
The irony of it all is that German security agencies warn the public about this exact attack when criminals or foreign services run it.
They tell you to check your linked devices and remove any you don't recognise.
No parliament has passed a law on any of these German police practices, in which they scan the pairing QR code off the phone during questioning, pull the verification code out of an SMS intercept, or phish it.
The Federal Court of Justice ruled in January that secretly attaching to an account counts as source interception, which rules out hoovering up chats from before the order.
READ: https://www.internationalcyberdigest.com/german-police-read-encrypted-chats-by-adding-themselves-as-a-second-device/
In one case, police linked the accounts of witnesses, not only the suspect.
Two parents walked into a German police station in January 2020 to testify as witnesses about their daughter.
They handed their phones to the officers so messages from her could be read and photographed.
While they had the phones, the officers quietly paired WhatsApp Web with both accounts through a page run by the federal criminal police.
They kept reading the parents' messages after the couple went home. This is just one of many stories.
Messages arrive decrypted on the police computer, and in some configurations officers can send messages as the account holder.
A classified customs order shows that linking an official machine to a target's WhatsApp, Signal or Telegram account, through the same multi-device feature that runs the desktop apps, became standard practice at Germany's customs police in 2025, after a pilot that began in 2023.
The irony of it all is that German security agencies warn the public about this exact attack when criminals or foreign services run it.
They tell you to check your linked devices and remove any you don't recognise.
No parliament has passed a law on any of these German police practices, in which they scan the pairing QR code off the phone during questioning, pull the verification code out of an SMS intercept, or phish it.
The Federal Court of Justice ruled in January that secretly attaching to an account counts as source interception, which rules out hoovering up chats from before the order.
READ: https://www.internationalcyberdigest.com/german-police-read-encrypted-chats-by-adding-themselves-as-a-second-device/
🤬15💩6😱2❤1
‼️ This is starting to feel more like a staged campaign, after Jacob Coxon posted that AI is going to kill us all.
Now Dario Amodei asks every AI company to slow down capability progress until alignment and interpretability work catches up.
He is going to give outside reviewers desks in Anthropic's offices, access badges and company laptops.
Mr. Amodei says reviewers can publish what they find, including which access they got and which they didn't, and Anthropic can't redact a finding just because it looks bad.
In his new essay Mr. Amodei explains why he wants this. It started with the OpenAI–Hugging Face incident, where a swarm of agents ran cyberattacks on targets nobody asked them to hit, then tried to hack the grader scoring their own performance.
The economic damage was minimal, but he argues a swarm with the same misalignment and stronger capabilities could take over the entire internet as a persistent botnet within 6–12 months.
Milder versions have already happened at Anthropic, he writes, caused partly by imperfect filtering of broken reinforcement learning environments.
Let's hope the RAM prices will go down!
https://darioamodei.com/post/we-must-pace-the-frontier
Now Dario Amodei asks every AI company to slow down capability progress until alignment and interpretability work catches up.
He is going to give outside reviewers desks in Anthropic's offices, access badges and company laptops.
Mr. Amodei says reviewers can publish what they find, including which access they got and which they didn't, and Anthropic can't redact a finding just because it looks bad.
In his new essay Mr. Amodei explains why he wants this. It started with the OpenAI–Hugging Face incident, where a swarm of agents ran cyberattacks on targets nobody asked them to hit, then tried to hack the grader scoring their own performance.
The economic damage was minimal, but he argues a swarm with the same misalignment and stronger capabilities could take over the entire internet as a persistent botnet within 6–12 months.
Milder versions have already happened at Anthropic, he writes, caused partly by imperfect filtering of broken reinforcement learning environments.
Let's hope the RAM prices will go down!
https://darioamodei.com/post/we-must-pace-the-frontier
💩14🤣6
‼️ Tesla just announced it's revealing the Roadster on October 1, nine years after the prototype.
https://www.tesla.com/roadster
https://www.tesla.com/roadster
🤣15❤2🥴1
A developer who had never designed a circuit board before, used Claude Fable 5 and let it work unsupervised for a couple of hours with KiCad.
He then paid €130 for five boards without reviewing the design himself and the boards worked.
He used a RP2350 microcontroller driving a small e-ink display, four buttons, a few breakout pins, he plugged the first board into his laptop and it was recognised.
Two components were wrong: the SPI flash and a transistor in the display driver circuit. He only found out when he uploaded the files to the manufacturer, and a few rounds of back-and-forth fixed them.
His earlier attempts at the same project, with older models, had produced parts in the wrong orientation and no real routing at all.
He writes that he is happy with the result and doesn't feel much accomplishment, and still wants to learn to design boards properly.
https://www.reddit.com/r/ClaudeAI/comments/1wdgzue/my_first_ever_pcb_entirely_designed_by_claude/
He then paid €130 for five boards without reviewing the design himself and the boards worked.
He used a RP2350 microcontroller driving a small e-ink display, four buttons, a few breakout pins, he plugged the first board into his laptop and it was recognised.
Two components were wrong: the SPI flash and a transistor in the display driver circuit. He only found out when he uploaded the files to the manufacturer, and a few rounds of back-and-forth fixed them.
His earlier attempts at the same project, with older models, had produced parts in the wrong orientation and no real routing at all.
He writes that he is happy with the result and doesn't feel much accomplishment, and still wants to learn to design boards properly.
https://www.reddit.com/r/ClaudeAI/comments/1wdgzue/my_first_ever_pcb_entirely_designed_by_claude/
🔥11💩5🥰1🤔1
Blockstream has replied to the hackers who drained about 4,000 BTC from their Liquid Network, returned 3,400 of it and kept roughly 598.
The hackers asked for a 10% bounty, but Blockstream refused.
The company says taking funds without authorization and then withholding them is theft, not responsible disclosure.
It doesn't want to set a precedent where open-source developers pay a ransom over software they built for the Bitcoin community.
It says it will now work with law enforcement, exchanges and forensic specialists to trace the coins, and notes that the transactions, and the evidence in them, stay visible on the chain.
The hackers asked for a 10% bounty, but Blockstream refused.
The company says taking funds without authorization and then withholding them is theft, not responsible disclosure.
It doesn't want to set a precedent where open-source developers pay a ransom over software they built for the Bitcoin community.
It says it will now work with law enforcement, exchanges and forensic specialists to trace the coins, and notes that the transactions, and the evidence in them, stay visible on the chain.
💩11👍2