Update and great video on AI-assisted cybercrime One bad actor spent a month "vibe hacking" — using AI to hit 17 orgs and steal sensitive data, and then threatened to expose the private data unless a ransom was met. The ransom was up to $500,000. "You would typically see
CYBERSECURITY
-
Malicious Actors Adapting to Exploit Advanced AI Capabilities
By
–
Malicious actors are adapting to exploit AI’s most advanced capabilities. We're sharing these findings to strengthen collective defenses across the industry. Read more:
-

Anthropic Addresses AI Cybercrime Threat Intelligence Disruption
By
–
Watch Jacob Klein and Alex Moix from Anthropic's Threat Intelligence team discuss what Anthropic is doing to disrupt AI cybercrime:
-

Anthropic disrupts AI-enabled cybercrime schemes in threat intelligence report
By
–
Our new Threat Intelligence report details how we’ve identified and disrupted sophisticated attempts to use Claude for cybercrime. We describe a fraudulent employment scheme from North Korea, the sale of AI-created ransomware by someone with only basic coding skills, and more.
-
Browser Use Safety: Combating Prompt Injection Risks
By
–
Browser use brings several safety challenges—most notably “prompt injection”, where malicious actors hide instructions to trick Claude into harmful actions. We already have safety measures in place, but this pilot will help us improve them. Read more:
-
Enterprise MCP Security Whitelist Platform Launch
By
–
@rauchg how can I get our platform whitelisted? http://
mintmcp.com we work with enterprises to secure MCP use. -

Model Security Vulnerabilities: Environment Variable Theft Techniques
By
–
That's pretty common these days, the challenge is making those protections completely airtight. Check out how @wunderwuzzi23 defeats model resistance to stealing environment variables here for example; https://
embracethered.com/blog/posts/202
5/openhands-the-lethal-trifecta-strikes-again/
… -

Claude Code Exfiltration Vulnerability via DNS Requests
By
–
Does that reliable work though? @wunderwuzzi23 has a trick where he has it run strings and grep to hide that it's accessing .env https://
embracethered.com/blog/posts/202
5/claude-code-exfiltration-via-dns-requests/
…
