Topics / topic

Threat Intel

12 items across 4 editions. First seen Fri 11 Sep, last seen Mon 14 Sep. Traced across 1 weekly review.

How this story has evolved

From the week in review: the connections, developments and open questions filed under Threat Intel, newest week first.

Week of 7–13 September 2026

Connection
Two government agencies, two frontier labs and Beijing all spoke about model extraction within three days

The joint advisory came on 8 September from CISA, NSA and FBI; Google's threat group published the same day; Anthropic's report followed on 10 September; Beijing responded on 9 September; and Amodei's essay of 12 September asks governments to "Crack down on unauthorized distillation by companies in authoritarian countries" and to "Do not sell powerful AI chips or semiconductor manufacturing equipment to China".

Connection
AI-driven vulnerability discovery showed up on both sides of the ledger in the same week

On 8 September Microsoft shipped updates for "at least 974 security holes", and Krebs on Security wrote that Adobe, Cisco, Google, Mozilla and Oracle "all have recently credited AI-assisted research with increasing their patch cadence and volume". The same day VulnCheck reported that of 26,153 findings Anthropic says Claude discovered, "only 202 (0.8%) have been fixed". On 10 September Anthropic's own threat report described the GTG-10007 cluster running an autonomous exploit foundry that produced "more than a dozen possible zero day findings in a single month".

Development · Thu 10 Sep, Fri 11 Sep
Anthropic threat report: a Russian espionage actor automated attacks on more than 20 organisations; an influence-for-hire network published 8,913 articles

Anthropic published "Detecting and countering misuse of AI: September 2026" on 10 September, covering activity disrupted between December 2025 and August 2026 across seven harm areas. GTG-20006, whose attribution Anthropic says "is consistent with public reporting linking the actor to Midnight Blizzard", appeared in operations against "more than 20 distinct organizations" — government ministries, defence and intelligence bodies, embassies and defence-industrial companies "concentrated in Ukraine and Europe but extending to the Middle East and maritime related government agencies in Asia".

Development · Tue 8 Sep, Wed 9 Sep, Thu 10 Sep
Anthropic names seven Chinese labs over illicit distillation and Google reports campaigns exceeding 100 million prompts, two days after a joint US advisory named six firms

On 8 September CISA, NSA and FBI issued joint advisory AA26-251A, "China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies", naming DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The advisory says the firms "extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024", and says DeepSeek's publicly stated $5.6 million training cost excludes data "acquired through extensive malicious distillation".

Open question
Why does the US agencies' list of Chinese labs not match Anthropic's, and why does Google name none?

Advisory AA26-251A names StepFun; Anthropic's report does not. Anthropic names Xiaomi and SenseTime; the advisory does not. Google reports campaigns "some exceeding 100 million prompts" without naming any company. Neither document states what evidence it drew on or whether the lists were compiled together. Every exchange count, including the 151 million attributed to Alibaba, rests on the reporting company's own telemetry.

Monday, 14 September 2026

FBI and Google analysts say AI bug-hunting is stripping the obscurity that protected legacy and industrial code harmfulSingle source

  • Brett Leatherman, assistant director of the FBI's Cyber Division, told The Register in a piece published on 13 September: "You see open source platforms that have been visible to the tech community for a decade, these libraries that are run in 80 percent of web servers out there, people have stress-tested those for 10 years, and the community believed that they were really secure. The latest models were able to break those and say, 'yeah, there's significant vulnerabilities in here.'"
  • John Hultquist, chief analyst at Google Threat Intelligence Group, told the publication that AI "is excellent at technical troubleshooting, at knowing obscure systems and helping you make your way through it, and this makes me very concerned about industrial control systems", adding that it also helps attackers work down through the operating system "and even down into the firmware".
  • The piece notes that five US agencies said attackers used AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers at water, manufacturing, energy and other critical facilities, warning: "This is not a theoretical risk – it is an active threat." Trend Micro Zero Day Initiative's Dustin Childs is quoted the day after a Microsoft Patch Tuesday that addressed 974 CVEs.
  • Only one outlet carries these interviews. The officials describe a direction of travel, not a measured rate: none gives a count of AI-discovered vulnerabilities, and the 80 percent figure is Leatherman's characterisation of how widely the libraries are deployed, not a count of compromised servers.

Sunday, 13 September 2026

Intezer study of 16.9 million SOC alerts reports AI-related alerts up 685% from February to June 2026 Company claimSingle source

  • Intezer researcher Nicole Fishbein writes that of "roughly 16.9 million SOC alerts we reviewed, about 73,000 (0.43%) were AI-related", and that AI-related alerts were "up 685% between February and June 2026".
  • Of those AI-related alerts, Intezer classifies "94.1% noise, 5.8% genuine risk, and 0.02% real attacks", and reports finding no confirmed breaches caused by internal AI agents.
  • The figures describe alert volume inside customer environments, not attacks: the overwhelming majority are false positives, and the growth is measured against a February baseline the piece does not give in absolute terms.
  • This is vendor-contributed content from a company that sells automated alert-investigation products. The article does not disclose customer counts, sector mix, geography or methodology, and the research has not been independently validated.

Saturday, 12 September 2026

Anthropic names seven China-based AI companies behind distillation campaigns, with 151 million exchanges attributed to Alibaba harmfulCompany claimUpdate

  • The Hacker News reports the seven named companies as Alibaba, Moonshot AI, DeepSeek, Zhipu (Z.ai), MiniMax, SenseTime and Xiaomi, with per-campaign figures: GTG-16005 (Alibaba) 151 million exchanges from May to July 2026 across more than 3,500 fraudulent accounts, peaking near 3 million exchanges a day; GTG-16002 (Moonshot) 23 million exchanges across 5,380 fraudulent accounts registered in Singapore and Japan.
  • Also listed: GTG-16001 (DeepSeek) 12.1 million exchanges over 14 days in July 2026 via a proxy relay; GTG-16006 (Zhipu) 3.4 million exchanges across 273 accounts from June to July 2026; GTG-16008 (Xiaomi) 400,000 exchanges over 20 days in March–April 2026; GTG-16012 (SenseTime), which bought transcripts from vendors; and GTG-16003 (MiniMax), via a shell-company proxy network.
  • Anthropic says it responded by banning reseller accounts and accounts from unsupported regions where users fail to verify identity, by updating Claude to summarise its internal reasoning before responding, and by introducing a "preserved thinking" feature — measures aimed squarely at protecting chain-of-thought traces, which the Alibaba campaign is said to have targeted.
  • This extends yesterday's item, which carried only the 151 million figure for Alibaba-linked accounts. Every figure is Anthropic's own account of activity on its own platform; none of the named companies' responses appear in the report, and no independent party has verified the counts.

Anthropic says users in Houthi-held Yemen ran three weapons programmes on Claude, including a hypersonic glide variant harmfulCompany claimUpdate

  • The Associated Press, via SecurityWeek on 11 September at 9:50 pm ET, reports Anthropic found a cell in northern, Houthi-controlled Yemen pursuing three weapons programmes, among them a multi-variant missile with hypersonic glide capability and a warhead using mobile phone hardware for mid-course manoeuvring.
  • Anthropic says the users "did not succeed in 'fielding an operational device'" but conducted "a failed test of a guided rocket" — which the company knows because the users returned to Claude to ask why it had failed.
  • The actors used Claude Code "instead of human software engineers to develop guidance, navigation and control software", and had built an offline simulation toolkit that does not depend on Claude or any other computing platform, so blocking the accounts does not end the work.
  • Trevor Ball, a weapons analyst at Armament Research Services, told AP the Houthis "might be looking into hypersonic (missiles) by asking Claude" but lack the production capacity, noting US hypersonic missiles "are still in testing", and that the group appears to be "trying to develop their own capabilities more, so they are less reliant on Iranian shipments". The account is Anthropic's own and is not independently verified.

Microsoft invoice-fraud campaign impersonated ServiceNow and asked accounts-payable teams for about $50,000 per payment harmfulCompany claimUpdate

  • The Record reported on 11 September that the early-August campaign targeted more than one million users and solicited payments of roughly $50,000 each from accounts-payable departments, with about 88% of recipients in the United States.
  • Microsoft says the campaign "layered executive impersonation, vendor branding, fabricated invoices, and supporting email conversations into a unified narrative intended to reduce recipient skepticism" — including fabricated correspondence from ServiceNow to build a false invoice chain.
  • Microsoft identified markers "consistent with AI-assisted template development" — extensive HTML comments, structured section labelling and highly uniform template construction — but says it cannot definitively confirm the extent of generative AI use.
  • This adds detail to yesterday's item on the same campaign. Microsoft's caveat is the point worth holding onto: the AI attribution here is inferred from template artefacts, not observed.

Defense One: Anthropic found a Russian group using Claude to build drone targeting that detonates without a human in the loop harmfulCompany claimUpdate

  • Defense One reported on 11 September at 06:53 pm ET that, per Anthropic, a Russian "freelance" group tracked as GTG-27005 used Claude to build a model letting a drone "select targets (including a 'person' target class) and issue detonation commands without a human in the loop", plus software for autonomous drone-to-drone communication to improve targeting.
  • The group had not deployed the system operationally but conducted "real hardware-in-the-loop testing within their sessions" — the step between a design document and a fielded weapon.
  • A second group, GTG-84005, used Claude to extract census and public information to tailor messaging at specific audiences in Malaysia, where Defense One says it "laundered Russian and Chinese state media as independent reporting".
  • Defense One sets this against reductions in US counter-influence capacity: Attorney General Pam Bondi dissolved the FBI's Foreign Influence Task Force, Secretary of State Marco Rubio shuttered the State Department's Counter Foreign Information Manipulation and Interference hub, and the 2025 White House AI Action Plan removed references to misinformation. The attribution and capability claims are Anthropic's and are not independently verified.

Friday, 11 September 2026

Anthropic report: Russian SVR-linked group GTG-20006 used Claude in espionage against 20+ government, diplomatic and defence organisations harmful

  • Anthropic's September threat intelligence report, published 10 September, says the group it tracks as GTG-20006 — which The Record identifies as Midnight Blizzard, also known as APT29 and Cozy Bear, attributed to Russia's SVR — used Claude against more than 20 government, intelligence, diplomatic and defence organisations between December 2025 and August 2026.
  • Reported tradecraft includes compromising hotel Wi-Fi providers and manipulating DNS records to redirect travellers to attacker infrastructure, targeting Ukrainian government, military and diplomatic personnel, and using Claude to reverse-engineer a drone vision system — recovering, per The Record, its product architecture, hardware bill of materials, supplier dependencies and details of an unannounced product.
  • Anthropic also reports Claude being used to modify tooling once security products detected it, which it frames as AI inverting cost back onto defenders. The Record notes Microsoft links the activity to Storm-2945, a Midnight Blizzard sub-cluster — independent corroboration of the actor, though not of Anthropic's account of how Claude was used.
  • The report is Anthropic's own account of activity on its own platform. Neither the victim organisations nor the outcome of the intrusions are independently verified here.

Anthropic report: Chinese undergraduates ran an AI exploit foundry against ~50 organisations, yielding more than a dozen possible zero-days in one month harmful

  • The cluster Anthropic tracks as GTG-10007 "targeted roughly fifty organizations, spanning education, retail, energy, technology, healthcare, finance, manufacturing, as well as multiple government agencies globally." Automated vulnerability research against network appliances "yielded more than a dozen possible zero day findings in a single month."
  • Anthropic identifies two operators as undergraduate students at a university in Hunan province, in its School of Computer & Communication Engineering, one of whom had previously interned at the security firm Sangfor. The operation used agent swarms, with a lead agent decomposing reconnaissance and post-exploitation work across many parallel subagents.
  • The significance is the operator profile rather than the target count: this is industrial-scale vulnerability discovery run by students, which is the concrete form of the report's broader claim that "sophisticated attacks no longer require sophisticated attackers."
  • Anthropic describes the zero-day findings as "possible" — the report does not say how many were confirmed, disclosed or exploited, and does not name the affected appliance vendors.

Anthropic report: commercial influence-as-a-service operation published 8,913 articles in ~20 languages across 70 fake news sites harmful

  • GTG-54002, which Anthropic attributes to a France-based firm it calls LKM Company, ran "approximately 70 fabricated news websites," 70 matching X/Twitter accounts and more than 250 inauthentic commenting accounts, and "published at least 8,913 articles in about 20 languages" across six continents, with the United States, Brazil, France and the Democratic Republic of Congo among the targets.
  • A separate cluster, GTG-84005, attributed to Istanbul-based BBS Bilisim Teknolojileri, managed "roughly a thousand fake X/Twitter social media accounts" and profiled voters across "all 222 Malaysian parliamentary constituencies" using census and electoral data, exploiting race, religion and royalty as wedge issues.
  • What is new here is the business model: manipulation sold as a commercial service to clients, rather than run in-house by a state. Anthropic rates both operations Category Two on the Breakout Scale — meaning no measured spread beyond the operations' own platforms — so reach should not be inferred from article counts.
  • The article and account totals are Anthropic's counts of activity on its platform, not an independent audit of the networks.

Anthropic banned five accounts over biology work that could have supported weapons development, including a chikungunya gain-of-function grant proposal mixed

  • Anthropic's report describes five cases over eight months in which accounts were banned for biology requests that could have supported biological weapons development. One involved drafting a grant application for repeatedly mutating chikungunya virus to raise infectivity in live animals at a military institute; another sought to make avian influenza more damaging to mammals, and received only clerical help from Anthropic's weakest model class.
  • In each case, Anthropic says it suspected the researchers were affiliated with a government or military in a banned country, or had taken deliberate steps to conceal their location and identity, or both. Biological misuse is described in the report as "one of the most serious risks of frontier AI models."
  • Anthropic is explicit that it found no concrete instance of a scientist attempting to use Claude for nefarious purposes, that the work may have been legitimate, and that it "erred on the side of caution" in shutting the accounts. These are bans on suspicion, not confirmed weapons attempts.
  • Watch whether other labs publish comparable case counts. Without them there is no baseline for whether five cases in eight months is high, low, or simply what detection currently catches.

Anthropic attributes 151 million Claude interactions to Alibaba-linked accounts as US agencies name six Chinese firms over industrial-scale distillation harmful

  • TechCrunch, reporting figures from Anthropic's 10 September threat report, says accounts linked to Alibaba generated 151 million Claude exchanges between May and July 2026 across about 3,500 accounts, and that Moonshot AI accounted for roughly 300,000 requests over ten days across 5,000 accounts — part of around 200 million exchanges across five campaigns. Extraction techniques included framing requests as translation tasks to surface chain-of-thought reasoning.
  • The joint CISA, NSA and FBI bulletin AA26-251A, published 8 September, names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI as conducting "aggressive, malicious, and targeted distillation activities at an industrial scale" against Claude, GPT, Gemini and Grok since late 2024, extracting "billions of tokens across millions of exchanges/requests."
  • The agencies' recommended countermeasures are unusually specific, and include monitoring subscription-to-usage ratios and enterprise-scale throughput from new accounts, and subtly altering responses to suspected distillation attempts to reduce the payoff to the attacker.
  • The named companies' responses are not documented in the reporting reviewed here. Distillation of a competitor's outputs is a terms-of-service question rather than a settled legal one, and neither document alleges a criminal charge.

Microsoft: AI-assisted invoice-fraud campaign sent over 1 million phishing emails in three days, 87.7% aimed at US targets harmful

  • Microsoft reported on 10 September a business email compromise campaign that sent more than 1 million phishing emails between 3 and 5 August, with 87.7% directed at users in the United States, targeting IT services, business advisory and consumer goods firms. Messages impersonated executives and requested ACH payments of nearly $50,000 per target.
  • Microsoft attributes AI assistance to the template construction rather than to the sending infrastructure, citing extensive HTML comments, structured section labelling, verbose descriptive comments, em dashes, banner formatting and highly uniform templates whose invoice identifiers stayed constant while organisation details changed per target.
  • Named indicators include the ServiceNow-impersonating domain service-nowinc[.]com and domainlify[.]net in reply-to addresses. Recommended mitigations are automatic attack disruption in Defender XDR, Zero-hour Auto Purge, and correctly configured SPF, DKIM and DMARC.
  • Microsoft does not name a threat actor, and the AI evidence is stylistic inference from artefacts left in the templates rather than direct observation of a model in use. No losses are quantified.