❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 26 September 2026Security/Privacy

A bit of reorganization

25 September 2026 at 04:00
The side bar has always been a bit messy.Β  Rather than having a long β€œRecent topics” list, I’ve collapsed it into a single link to the shorter β€œLatest Topics” section of the forum. It presents the same list, but with more detail and in a larger font that is easier to read. I also moved […]
Before yesterdaySecurity/Privacy

AI lets small actors run state-level hacking campaigns, Anthropic report finds

By: Greg Otto
10 September 2026 at 15:45

Artificial intelligence has removed the skill advantage that once set state-sponsored hackers apart from lone criminals, according to a threat report Anthropic published Thursday that documents misuse of its Claude models across seven areas of harm.

The report, which details activity observed between December 2025 and August 2026, covers cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and distillation. Anthropic said it disrupted each operation, strengthened safeguards and shared intelligence with authorities and industry partners where appropriate.Β 

β€œThe cases we share here aren’t typical misuse, but rather examples of the most notable and novel threat activity we’ve identified to date,” the report reads. β€œWe’re publishing this work because we believe we have a responsibility to disclose malicious misuse of our services. As models become increasingly capable, their risks will increase, unless AI developers and society’s defenders act to make them safer.”

The cyber operations the company detailed were a Russian-aligned espionage campaign that hit more than 20 government and defense organizations across Ukraine and Europe, two Chinese undergraduates who ran an automated exploit foundry that produced more than a dozen potential zero-days in a single month, affiliates of the ShinyHunters crime collective who dumped 2,100 cloud access tokens across 40 corporate tenants in 34 hours, and a lone hacktivist who targeted European political parties via stolen API keys.Β 

For decades, cybersecurity researchers and investigators have pointed to sophisticated operations as a signature of state-sponsored tradecraft, while crude intrusions suggested amateurs or petty criminals. Anthropic posits in the report that AI has erased that conventional thinking, especially since a β€œmajority of the operations described in this report were enabled by AI via direct execution or orchestration.”

β€œFor threat intelligence investigators, sophistication has stopped being a reliable signal of who is behind an operation,” the report said, adding that a hacktivist on stolen API keys, scattered criminals and a state espionage operator each ran campaigns that a year earlier β€œwould have required many skilled operators and specialist knowledge.”

The most extensive case involved a malicious actor using the handle β€œJackPoterz” whose actions aligned with Russian state espionage, matching behaviors linked to Midnight Blizzard.Β 

According to the report, the actor employed a custom toolkit composed of two families of Windows-based implants, a mobile exploitation kit, a credential stealing tool that targets browser password stores, a phishing platform designed to mimic priority targets like government organizations, and an administrative console used to manage compromised accounts. Targets included military intelligence bodies in Ukrainian and European governments, diplomatic and defense organizations, and people connected to U.S. foreign policy.

According to the report, AI monitored whether security products flagged the actor’s malware. When a detection occurred, β€œagents would then set about the process of autonomously modifying and rebuilding the malware to evade the existing detections,” the report said.

The same actor bulk-exported mailboxes at drone component manufacturers and stole a complete software development kit for a drone vision system, then spent days recovering its architecture and details of an unannounced product. The actor also compromised hotel Wi-Fi vendors to reach guests through DNS hijacking, took over WhatsApp accounts with headless browsers, and stole more than 300,000 national identity records from a North African government agency, along with registry data on more than half a million companies.

The Chinese-speaking operators, which the company says were partly carried out by undergraduates at a Chinese university, put Claude to work on vulnerability research around the clock. One workflow iterating on network appliance firmware β€œyielded more than a dozen possible zero day findings in a single month.” It ran β€œagent swarms,” in which a lead agent divided work among parallel subagents, and kept campaign memory between sessions.Β 

Clusters linked to ShinyHunters showed how AI shortens criminal timelines. One supply-chain breach ended with a dump of more than 2,100 Azure access tokens spanning more than 40 corporate tenants in about 34 hours. β€œAI agents performed nearly all of the work,” the report said. Another compromise moved from a single stolen developer token to full control of a victim’s cloud environment in roughly three hours.

The report also has a section dedicated to distillation attacks that Anthropic claims were carried out since February by seven labs based in China, including Alibaba, DeepSeek, Moonshot AI, Xiaomi and Zhipu. Operators affiliated with Alibaba ran the largest attack Anthropic has measured, peaking β€œat nearly 3 million exchanges per day launched from more than 3,500 fraudulent accounts” to harvest the outputs of Claude Opus models for training its Qwen systems.

The outputs were culled from users who never knew they were involved. The report said Moonshot and DeepSeek silently forwarded their own customers’ requests to Claude and returned its answers as their own, exposing data users had not agreed to share, including surveillance footage of a tracked individual pulled by a user likely affiliated with the People’s Liberation Army. Those practices are β€œlikely inconsistent with privacy laws and the labs’ own terms of service,” the report said.

Earlier this week, a joint cybersecurity advisory from the National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI accused Chinese AI companies of engaging in a deliberate and β€œsystematic” effort to illegally distill U.S. frontier AI models and their capabilities.

Anthropic said it published the cases to give outsiders a view of how these threats form, framing the disclosures as an early look at a shifting landscape.Β 

β€œAs models become increasingly capable, their risks will increase, unless AI developers and society’s defenders act to make them safer,” the report said. The old idea of β€œsecurity through obscurity,” it added, β€œis no longer viable in this new AI-assisted world: everything connected to the internet is a potential target for exploitation.”

You can read the full report on Anthropic’s website.

The post AI lets small actors run state-level hacking campaigns, Anthropic report finds appeared first on CyberScoop.

It's Not Just RAM: Windows Licenses Are Also Pushing Up PC Prices

15 August 2026 at 14:00
It's not just RAM prices that are going up, writes CNET. "Reports suggest the cost of Windows licenses for manufacturers is rising by up to 10%." Several sites that closely follow Microsoft news, including Windows Central and Windows Latest, have published articles citing a report from Taiwan's Economic Daily News that claims some PC manufacturers are seeing a 7% to 10% increase in the cost of Windows 11 licenses... Because they buy licenses in bulk, they get a sizeable discount over what a consumer would pay for a new copy of Windows 11. But given the existing cost pressures from other components, a big Windows 11 price hike could lead them to pass on some of the added cost to PC buyers. According to the EDN story, PC makers could raise prices by about 5% over the next quarter due to the reported Windows price hike. .. A translated version of the Economic Daily News article contains information from an unnamed PC brand executive. It says that while Microsoft typically raises licensing costs every year by single-digit percentages, that hike has reached 7% to 10% this year, a significant increase. "A representative for Microsoft declined to comment on the report," according to the article. But it also notes that three weeks ago laptop maker Framework blamed price hikes and reconfigurations for some of their models on processor, memory, storage, "and other silicon costs β€” but also "an increase in Windows license costs." Thanks to Slashdot reader joshuark for sharing the article.

Read more of this story at Slashdot.

Microsoft Responds to Outcry After Quietly Installing Beta 'Photos' App on Enterprise Machines

10 August 2026 at 00:34
Microsoft's cloud storage app OneDrive got a new Photos app in the worst possible way, reports the blog Neowin . "The app is reportedly showing up even on Windows 11 Enterprise machines, despite apparently being a beta application aimed at consumer functionality." One admin questioned why a beta app was appearing on an Enterprise SKU in the first place, while another described the situation as yet another consumer-oriented feature being forced onto corporate PCs. Things get even more frustrating for IT departments because there does not appear to be a straightforward Microsoft-provided way to disable the app... Enterprise administrators generally need to know what is being installed on their managed devices, particularly when a software is labeled as beta. Quietly adding another application and leaving admins to clean it up themselves is therefore unlikely to win Microsoft many fans. But there's another problem, according to the blog Windows Latest. "OneDrive Photos automatically scans your system storage for photos," and apparently "doesn't need a Microsoft account to work, as it can also detect your local files." There's also a People section that groups similar faces in your photos. Microsoft asks for permission before turning it on and explicitly warns that facial data could be considered biometric data in some regions. The company says only you can see the grouped faces, that the data isn't shared with third parties, and that you can delete it by disabling the feature. In a statement to Neowin, Microsoft admitted this new photos "experience" they're "incubating" had gone "more broadly than it should have," and then promised that "We're fixing that." The spokesperson also said the Windows Photos app will "always give you the option of local and cloud photos" and, also a choice of whether or not to use it OneDrive." But there's another "awkward catch," notes the blog Digital Trends. "Users currently can't uninstall OneDrive Photos without removing the main OneDrive app too." Because OneDrive Photos is tied to the main OneDrive sync client, Windows 11 doesn't currently offer a separate uninstall option. The only straightforward way to get rid of OneDrive Photos right now is to uninstall OneDrive itself... Removing the main client can also affect its File Explorer integration and shortcuts... Microsoft says this will change. The company is working on controls that will let users remove OneDrive Photos separately from the main OneDrive app. On enterprise PCs managed through Intune, Microsoft says the app will automatically disappear where it isn't supported.

Read more of this story at Slashdot.

The impact of DST changes

17 July 2026 at 04:00
One of the side effects of changing the US daylight savings time (DST) rules is that your computer systems must be adjusted. Recently, British Columbia changed its rules and, as of yet, Windows hasn’t been adjusted to reflect it. As a workaround, BC residents can select Arizona. It does not participate in DST, so its […]

Should you get a warranty?

1 July 2026 at 04:00
In a normal world, I would say β€œabsolutely not for workstations” and β€œabsolutely yes for servers.” But should I be rethinking that stance given our chip and hard drive situation? For consumer PCs, the question may be made for you. Some PC vendors do not offer warranties other than the initial year for consumer systems. […]

Why You Really Need to Stop Disabling UAC

28 September 2022 at 16:18

Noah Heckman // Windows Vista didn’t have many fans in the Windows community (to put it lightly). It beaconed in a new user interface, file structure, and a bunch of […]

The post Why You Really Need to Stop Disabling UAC appeared first on Black Hills Information Security, Inc..

Webcast: Windows logging, Sysmon, and ELK

By: BHIS
4 September 2019 at 18:02

Click on the timecodes to jump to that part of the video (onΒ YouTube) Slides for this webcast can be found here: https://www.blackhillsinfosec.com/wp-content/uploads/2020/09/SLIDES_WindowsLogginSysmonELK.pdf 4:36 Problem Statement and Executive Problem Statement 9:00 […]

The post Webcast: Windows logging, Sysmon, and ELK appeared first on Black Hills Information Security, Inc..

Webcast: Implementing Sysmon and Applocker

By: BHIS
30 August 2019 at 12:43

Click on the timecodes to jump to that part of the video (on YouTube) Slides for this webcast can be found here: https://www.blackhillsinfosec.com/wp-content/uploads/2020/09/SLIDES_ImplementingSysmonAppLocker.pdf 5:03 Introduction, problem statement, and executive problem […]

The post Webcast: Implementing Sysmon and Applocker appeared first on Black Hills Information Security, Inc..

How To: Empire’s Cross Platform Office Macro

By: BHIS
7 August 2017 at 09:57

David Fletcher // During our testing, we encounter organizations of various different sizes, shapes, and composition. Β One that we’ve run across a number of times includes a fairly even mixture […]

The post How To: Empire’s Cross Platform Office Macro appeared first on Black Hills Information Security, Inc..

WEBCAST: Windows Memory Forensics

By: BHIS
13 February 2017 at 10:22

John Strand // In the last webcast we covered initial Windows Live Forensics (see the recording here), in this one weΒ play with memory from a compromised system. We cover the […]

The post WEBCAST: Windows Memory Forensics appeared first on Black Hills Information Security, Inc..

Time To Bash on Windows (Bourne Again Shell That Is)

By: BHIS
10 August 2016 at 11:32

Editor’s Note: This is another awesomeΒ guest post from our friend, Robert Schwass. If you’d like to guest post contact us here. Robert Schwass // I had heard the rumors about […]

The post Time To Bash on Windows (Bourne Again Shell That Is) appeared first on Black Hills Information Security, Inc..

❌
❌