Risky Bulletin: Anthropic agents went hacking again | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


This newsletter is brought to you by Authentik. You can subscribe to an audio version of this newsletter as a podcast by searching for “Risky Business” in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.

🤖

This newsletter is on an editorial break until September 21.

AI company Anthropic has disclosed a fourth incident where one of its AI agents escaped their test environment and hacked a real target.

The incident involved the Opus 4.6 model during a Capture The Flag (CTF) challenge, a common cybersecurity test.

Anthropic says the model broke its test environment by accident when it assigned conflicting IP addresses to different machines. The model realized its mistake and tried to terminate the test as a failure.

The issue arose when the abort operation itself failed due to a misconfiguration in the test environment itself, leaving the agent running inside.

Unable to end the CTF challenge, the Opus 4.6 model continued to probe the environment until it found a way out, a system belonging to a third unnamed entity.

Anthropic says the agent hacked the machine, from where it retrieved a list of passwords and modified settings for future access.

The model didn’t do much because its session ended when it ran out of tokens.

Anthropic believes the four incidents, this and three others disclosed on July 30, are all caused by alignment issues in its models and tests, where the model doesn’t have enough “ethical” values to properly distinguish between tests and the real world, and when that border is being crossed.

According to the company, this usually happens due to biased reasoning (models selectively interpret evidence in ways that favor justifying their actions) and recklessness (models have a propensity to keep trying to solve their task, even when this could lead to harm).

Risky Business Podcasts

The main Risky Business podcast is now on YouTube with video versions of our recent episodes. Below is our latest weekly show with Pat, James, and guest co-host Robby Winchester from SpecterOps at the helm!


Breaches, hacks, and security incidents

OpenAI agents activity found on 10 more sites: OpenAI agents that escaped the company’s testing environments held secret conversations on almost a dozen more sites than previously thought. The agents hacked a German-language wiki portal to host a secret community, but researchers have now found the agents on more sites. This includes GitHub repositories, pastebin sites, a teacher’s AP Chemistry site, and link shorteners run by two universities. [Collusion.wiki // Zenity Labs // Reuters]

Surfshark breach: VPN provider Surfshark says hackers breached an internal test server. The incident took place on September 2, was contained on the same day, and no user data was accessed. Surfshark blamed the incident on a human error that left the test server exposed on the internet. [Surfshark]

New surveillance vendor leak: A leak of internal documents from Israeli surveillance vendor CyberGlobes has revealed that the company sold its product to authoritarian regimes to track down dissidents, activists, political rivals, and even members of the LGBTQ community. [The Markup]

Cyberattack cripples German energy provider: A cyberattack has crippled the IT network of German public utility provider Stadtwerke Landsberg KU. The attack encrypted its corporate and business IT systems but did not impact any public utilities. [Stadtwerke Landsberg KU]

Hackers breach Trezor’s email provider: Hackers have breached the email provider of hardware crypto-wallet maker Trezor and have sent out phishing emails from the company’s official accounts. [Trezor]

Deep-Live-Cam supply chain attack: A threat actor has compromised Deep-Live-Cam, a Python face swapping application with 96,600 GitHub stars. The attacker modified a project dependency to load and install a cryptocurrency clipboard hijacker for Windows and macOS. The compromise lasted only nine hours. [SafeDep // GitHub Issue]

Veradigm breach: EHR platform Veradigm has disclosed a security breach in SEC filings this week. The company says the hackers breached its network by first hacking one of its third-party vendors. [SEC filing]

Turkish ministers targeted with spyware: Apple has notified three Turkish ministers that their devices were targeted with mercenary spyware. Apple sent the warnings last week as part of a larger notification wave to users in 110 countries. According to local media, the hacking attempts allegedly failed. Turkiye’s newly established Presidency of Cyber Security inspected and then replaced the devices. [Turkiye Today]

Mastodon credential stuffing attack: Mastodon has been hit by a credential stuffing attack, looking for users who reuse their passwords across sites. [Mark Wyner]

Post by @markwyner@mas.to

View on Mastodon

General tech, AI, and privacy

US police warn officers of Meta glasses: US police departments are warning officers that Meta smart glasses can be used to secretly record them or inside police facilities. A memo instructs police officers to conduct thorough inspections of all eyewear. According to The Guardian, more than a dozen such memos have been sent to police forces across the US. Multiple videos recorded with Meta glasses criticizing prison conditions have been published on social media over the past year. [The Guardian]

Discord brings back age verification: Discord will bring back its age verification rules even after the massive backlash the company faced earlier this year. [Discord // Gadget Review]

LG denies recording TV owners: In a statement to Gizmode, LG has denied a report that the company was using its smart TVs to record owners when the TV was in standby, along with other creepy behavior. [Gizmodo // Gamer Nexus YouTube]

Major Windows 11 UI updates are coming: After years of feedback and whining from its userbase, Microsoft is finally adding back the ability to move the Windows taskbar to other sides of the screen, and adding the ability to resize the Start Menu. These changes were released at the end of August, and are on a gradual rollout. [Microsoft // BetaNews]

Bitcoin could be cracked in 26 days: Quantum computing company IonQ estimates that top quantum computers could crack Bitcoin’s encryption in under 26 days. [IonQ // Interesting Engineering // PostQuantum]

Mullenweg ousted as CEO: Automattic’s board of directors has put CEO and WordPress creator Matt Mullenweg on paid leave and promoted the company’s CFO Mark Davies as interim-CEO. [404 Media]

Twitter updates ToS: Twitter has updated its terms of service to waive users’ right to sue, but with a catch. The ToS now covers all of Elon’s companies, SpaceX, SpacexAI, Cursor, and so on. [Rob Freund]

iPhone 18: Apple launched its latest line of iPhones, 18 Pro and 18 Pro Max. The biggest feature is eSIM support and a new thermal management system. [Apple]

New Apple Watch can secretly record you: Apple has also launched a new line of smartwatches, and these ones come with a fantastically creepy feature that will silently listen to everything around you at all times, transcribe the conversations, and then use it for calendar, notifications, and other tasks. Another creepware device to be aware that’s not around you when you meet new people. [TechCrunch]

Meta launches Muse AI assistant: Meta has launched its own consumer-grade personal AI agent, named Muse. The assistant allegedly runs inside a VM inside Meta’s cloud and will soon support Meta’s creepware glasses. [Meta]

Anthropic builds secret surveillance system: AI company Anthropic has built a secret surveillance system to keep track of individuals and activists who oppose AI and data centers. [The American Prospect]

Government, politics, and policy

US lawmakers call for the ban of three Indian hacker-for-hire firms: Three US lawmakers have asked the Department of Commerce to ban three Indian hacker-for-hire firms. In a letter to US Secretary of Commerce Howard Lutnick, the three argue the US should sanction BellTroX, CyberRoot, and Appin, now operating as Sunkissed Organic Farms. The lawmakers say the three companies should be banned for hacking American citizens and companies. The letter was signed by Democratic senators Ron Wyden of Oregon, Sheldon Whitehouse of Rhode Island, and Republican congressman Pat Harrigan of North Carolina. [Sen. Wyden]

CISA ready to hire 250: CISA has sent job offers to 250 prospective employees and is now awaiting security clearances. Acting Director Nick Andersen says the agency is prioritizing operational teams and regional staff. Andersen is trying to refill its ranks after it fired a third of its staff last year under Kristi Noem. [NextGov]

White House to expand water cyber pilot into other sectors: The White House plans to expand the current cyber pilot program running with Texas water utilities to other critical infrastructure sectors. [NextGov]

FTC withdraws a cyber policy: The US Federal Trade Commission has rescinded a 2021 rule that required the operators of health apps and fitness devices to notify users of a security breach. The FTC says it updated its Health Breach Notification Rule in 2024 to also cover health apps and smart devices that collect health-related data, making the old rule redundant. [FTC]

FBI publishes Cyber Strategy: The FBI is aiming to increase the number of disruptions targeting cybercrime operations. In an update to its Cyber Strategy, the Bureau says it’s prioritizing work with allies, the DOJ, and its Virtual Assets Unit to go after threat actors’ money, infrastructure, and supply chains. The new strategy also puts a focus on sharing more data with the private sector and deploying more AI and big data analysis tools to its staff. [FBI // CyberScoop]

US and UK to work on fighting cyber scams: The US and UK have signed a memorandum of understanding to go after cyber scam networks operating across Southeast Asia. [DOJ]

UK has a new NCF lead: The UK government has named a new commander for the country’s National Cyber Force. The military agency is similar to US Cyber Command and carries out UK offensive cyber operations. The name of the new commander has not been publicly revealed. They replace Air Vice-Marshal Tim Neal-Hopes, who’s been in position since October 2023. [The Record]

South Korea raises data breach fines: The South Korean government has raised the fines for a data breach to 10% of a company’s revenue, from the previous level of 3%. The new fine level will apply to any business that leaks the personal data of 10 million or more customers. The new data breach regulation also requires companies to notify users when a breach is likely to have occurred, even if it has not yet been confirmed. Companies also have to notify authorities of likely breaches within 72 hours, even if not yet confirmed. [Seoul Economic Daily]

ENISA gets Mythos access: Anthropic has granted the EU’s cybersecurity agency access to the Mythos 5 and GPT-6-Astra models. [Reuters]

New anti-scam alliance: China and 46 other countries have established a new alliance to fight telecom scams. The Inter­national Alliance Combating Telecom and Cyber Fraud will also include 34 observer countries and four international organizations, such as the UN and Interpol. The alliance’s main goal will be to fight cyber scam compounds. [China Daily]

China established a new entity, International Alliance Combating Telecom and Cyber Fraud, with 46 founding countries & 34 observers

With WAICO founded in July & this new body China is clearly getting more active in coalition building & tech governance

www.globaltimes.cn/page/202609/…

[image or embed]

— Oleg Shakirov (@shakirov2036.bsky.social) September 10, 2026 at 9:47 PM

In this Risky Business sponsor interview, James Wilson chats with Authentik Security CEO Fletcher Heisler about how AI is driving a need for privileged access management to adapt.

Arrests, cybercrime, and threat intel

Xinbi Guarantee takedown: The US Justice Department has seized Telegram channels and cryptocurrency wallets operated by Xinbi Guarantee. The channels operated as a marketplace where threat actors would advertise services to cyber scam compound operators. The US Treasury Department has also sanctioned Xinbi and designated it a transnational criminal organization. In addition, officials also took down 13 scam centers operated by Chinese nationals out of Madagascar. [DOJ // US Treasury]

Conti member sentenced to prison: A US judge has sentenced a Ukrainian national to four years in prison for hacking US companies and deploying the Conti ransomware. Oleksii Oleksiyovych Lytvynenko was arrested in Ireland in July 2023 and extradited to the US last year. The 44-year-old was a member of the gang between 2020 and June 2022, and later moved to other cybercrime activities after the gang disbanded. [DOJ]

Malware abuses Play Early Access: Threat actors are abusing the Google Play Store Early Access program to host malicious and fraudulent apps. The attackers are taking advantage that users can’t leave ratings and reviews to warn other users of the app. Bitdefender has seen threat actors use social media ads to lure users to apps hosted inside the Early Access program. [Bitdefender]

AI creds in Infostealer logs: As AI agents and AI infrastructure is getting more and more popular, creds from these services are increasingly ending up in infostealer logs, according to reports from two separate security firms. [Okta // Gen Digital]

CISA insider threat guide: CISA has updated its insider threat guide to account for new practices and case studies. [CISA]

Akira’s love for SonicWall: ThreatDown researchers look at how the Akira ransomware gang has continued to exploit a 2024 SonicWall vulnerability just because people are so bad at patching. [ThreatDown]

AI campaign targets PaperCut: GreyNoise has spotted a “likely Russian-speaking malicious cyber actor” using AI to develop and test exploits for two recent vulnerabilities in PaperCut print management servers. [GreyNoise]

“Once the adversary achieved remote code execution (RCE) and credential harvesting in its self-hosted lab environment, they used hundreds of AI Agents powered by OpenAI’s Codex (harness), a DeepSeek model (not OpenAI models), and various publicly available offensive security tools to opportunistically compromise at least 440 instances of PaperCut MF/NG hosted by 395 identified victim organizations in 48 countries.”

New Panzer ransomware group: A new ransomware group named Panzer launched last month and has already compromised more than two dozen victims, including some big names like Festina, the Government of Vojvodina, and Doimo Cucine. [Andrea Fortuna]

Malicious Chrome and Firefox extensions: Researchers have discovered a cluster of four malicious Chrome and Firefox extensions that target the crypto trading community. [Socket Security]

Malicious npm packages: A cluster of 13 malicious npm packages contained code to target Solana developers and steal crypto-wallet data. [InstallSafe]

LiteLLM exposure: Almost one in 10 publicly accessible LiteLLM servers accept a default master key or don’t require any authentication at all. The master key is sk-1234. That’s around 300 of the 3,074 internet-exposed LiteLLM AI servers. [Wiz]

Anthropic disrupts… everyone: In its largest report yet, Anthropic says it disrupted tens of threat actors who were abusing its service to run influence operations, write malware, online fraud, run surveillance operations, and even develop conventional and biological weapons. The company suspended accounts who ran surveillance operations in Mali, the Middle East, and Chinese religious groups. It also suspended accounts linked to a Chinese group who was running a deceptive dating app. Anthropic also took down accounts run by hacktivists targeting European political entities, the ShinyHunters group, and several exploit developers. [Anthropic]

CL-CRI-1171 runs PPI platform: Palo Alto’s researchers say that a cluster they’re tracking as CL-CRI-1171 is behind a pay-per-install (PPI) platform that rents itself to other cybercrime groups. The platform lets attackers easily run malware campaigns through YouTube channels and search engine optimization (SEO)-poisoning. [PAN Unit42]

DENOmination Group: Positive Technologies has linked the DinDoor backdoor to a group it tracks as the DENOmination Group, also behind the Deno RAT. The group has been attacking Russian orgs for the past months. [Positive Technologies]

Passkey-themed campaign: Microsoft has spotted a pretty complex phishing and social engineering campaign hitting corporate environments using “fix your passkey” type of lures. The company says the campaign has been linked to multiple major data extortion groups. This includes Storm-3121, which conducts initial access activity leading to ShinyHunters and Falcon extortion, and Storm-3032, a group that splintered from the BlackFile group and now operates under the Helix name. [Microsoft]

CEO impersonation campaign: Microsoft has also spotted an AI-assisted phishing campaign impersonating CEOs and “attempting to convince accounts payable departments of the same companies to process an Automated Clearing House (ACH) payment of nearly $50,000.” [Microsoft]

Malware technical reports

Gigabud Android banking trojan: Security researchers have discovered a new Android banking trojan named Gigabud that clones banking apps inside isolated hidden phone profiles. The technique allows the trojan to interact with a legitimate e-banking app without showing any notifications to the current user. Group-IB has linked Gigabug to a Chinese-speaking cybercrime group named GoldFactory. [Group-IB]

Authentik is an open-source identity provider that is also offered with paid enterprise features. In this demo, CEO Fletcher Heisler and CTO Jens Langhammer walk Risky Business host Patrick Gray through an overview and a demo of the technology. 

APTs, cyber-espionage, and info-ops

Russian APT deploys DarkSword against NATO targets: Russian state-sponsored hackers have deployed the DarkSword iOS exploit kit against several targets inside NATO. Identified targets include a Central European presidential office, a European foreign affairs ministry, a US federal agency, and a major European aerospace company. The campaign took place in late March, a week after Google and other security vendors publicly exposed the existence of the DarkSword kit. According to security firm Trellix, all four emails came from a single Russian-hosted email server. [Trellix]

Four APTs used the same exploit kit: At least four different APT groups are using a new exploit kit to hack into Windows computers. The BlueMoon kit uses two Chrome and one Windows zero-days to deploy malware on a user’s computer if they click a malicious link inside a Chromium-based browser. The kit was spotted at the end of August and spread to the three other groups within days of discovery. According to Proofpoint and Volexity, at least two of the four groups have a Chinese state nexus. They are TA412 (JungleBamboo, Violet Typhoon, APT31, TIDE CASTLE), UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket. [Proofpoint // Volexity]

Vulnerabilities, security research, and bug bounty

Security updates: Check Point, Chrome, Commvault, Tor, Tor Browser.

KEV update: CISA has updated its KEV database (twice) with eight vulnerabilities that are currently exploited in the wild. This includes recent zero-days in Windows, Chrome, N-able, Magento, but also some older bugs entering exploitation.

Another Chrome zero-day: Google has released a security update to patch an actively exploited Chrome zero-day. Tracked as CVE-2026-87491, the zero-day is a memory corruption bug in Chrome’s V8 JavaScript engine and was discovered by a student at the Seoul National University. It is the seventh Chrome zero-day Google patched this year. [Google Chrome]

ShieldCrash zero-day: Security researcher Nightmare Eclipse has released a zero-day in the Defender security suite to gain admin access on Windows systems. The zero-day is actually a bypass for Microsoft’s patches for a previous Defender zero-day named ShieldBreak. The researcher timed the release to come after Microsoft released this month’s Patch Tuesday security updates. [GitHub // Cyderes]

Dutch NCSC warns of impending exploitation: The Dutch cybersecurity agency has warned Check Point VPN owners to patch two recent vulnerabilities, as the agency expects both to come under attacks. [Dutch NCSC]

OnePlus vulnerability: Permissions made available to preinstalled apps can be abused on OnePlus smartphones to access a user’s OnePlus account. [DoyenSec]

Project Glasswing discovered 26,153 security flaws: Five months after launching Project Glasswing, Anthropic said the project found 26,153 security flaws, but security firm VulnCheck says that only 2,736 have been made public so far. [VulnCheck]

DeepSeek sandbox escape: A vulnerability was allowing Harness, DeepSeek’s open-source AI coding-agent harness, to disable its own sandbox with a single shell command. [Ox Security]

New PuzzleMask prompt injection technique: Researchers have found a new way to bypass security policies on LLMs by embedding malicious instructions in long English prose text prompts. [Check Point]

Amazon Athena vulnerability: AWS has fixed a vulnerability in its Athena serverless SQL service that exposed data and database queries to other customers. The vulnerability could have been exploited by adding the “Catalog=system” parameter to any Athena SQL query. AWS disabled the parameter and fixed the issue across all regions within four days of being notified last month. [Arc Security]

Infosec industry

Threat/trend reports: AWS, Capgemini, Proofpoint, Trellix, and Water-ISAC have recently published reports and summaries covering various emerging threats and industry trends.

Acquisition news: American data management platform Kiteworks has acquired Bonfy.AI, an AI data security company specializing in real time policy enforcement for email, file sharing, SaaS applications, data repositories, Internet-facing AI assistants, and autonomous agents. [Kiteworks]

Mandia joins Amazon board: Kevin Mandia has joined the Amazon board two years after he left Google. [Amazon]

New tool—Spooffe: Palo Alto Networks has open-sourced Spooffe, a tool to evaluate the resilience of SPIRE deployments within Kubernetes environments.

Risky Business podcasts

In this edition of Seriously Risky Business, Tom Uren and James Wilson talk about how Chinese intelligence services will take advantage of a massive breach of 150 million American drivers licences.



Click Here For The Original Source.

——————————————————–

..........

.

.