Skip to content
TrackPodcasts
newsSep 11, 202610:20

Risky Bulletin: Anthropic agents went hacking again

Risky Bulletin

About this episode

Anthropic agents went hacking again, South Korea increases its data breach fines, Apple notifies three Turkish ministers of mercenary spyware attacks, and CISA is ready to hire 250 staff.

Show notes

Get every episode summarized

Each time Risky Bulletin publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

137 searchable segments. Every word is indexed and playable.

Risky Bulletin: Anthropic agents went hacking again

Risky Bulletin

0:00
10:20

Full transcript

Risky BulletinRisky Bulletin: Anthropic agents went hacking again. Machine-transcribed; use the interactive transcript above to jump the player to any line.

Andthropic agents when hacking again, South Korea increases its data breach fines. Apple notifies three Turkish ministers of mercenary spyware attacks, and CISA is ready to hire 250 staff. This is the Risky Bulletin, prepared by Catalan Kimpanu and read by me, Claire Eard. Today is the 11th of September, and this podcast episode is brought to you by Authentic. In today's top story, Anthropic has disclosed a fourth incident of its AI agents escaping their test environment and hacking real targets. The latest incident involved the Opus 4.6 model escaping during a CTF challenge. The model broke its test environment, but due to a misconfiguration it couldn't terminate its test. It continued to probe its environment until it reached and hacked a third party, stole credentials and modified settings for future access.

The models adventures ended when it ran out of tokens. Meantime the open AI agents that recently congregated on a German wiki held secret conversations on almost a dozen more sites than initially reported. Last week the company confirmed its agents escaped their sandboxes and hosted a secret community on a German language wiki portal. Researchers have since found the agents on more sites, including GitHub repositories, paste bin sites, a teacher's AP chemistry site and link shortness run by two universities. In other news, Apple has notified three Turkish ministers that their devices were targeted with mercenary spyware. The company sent spyware alerts to users in 110 countries last week. According to Turkish media, the hacking attempts against the ministers weren't successful. Turkeys, newly established presidency of cybersecurity, inspected and replaced the devices.

Three US lawmakers have urged the Department of Commerce to sanction three Indian hacker for higher firms. The companies named in a letter to Howard Lutnik, the US Secretary of Commerce, are Bell Trox, Cyberroot and Apple, now operating as Sunkist organic farms. The letter was signed by Democratic senators Ron Whiden of Oregon, Sheldon Whitehouse of Rhode Island and Republican Congressman Pat Harrigan of North Carolina. They said the company should be banned for hacking American citizens and companies. Cesar has sent job offers to 250 prospective employees and is currently waiting on their security clearances. Acting director Nick Anderson says the agency is prioritising operational teams and regional staff. Last year, Cesar laid off a third of its staff under Kristi Noem. The FBI wants to disrupt an increasing number of cybercrime operations. The Bureau's updated cyber strategy says it will prioritise working together with allies,

the DOJ and its virtual assets unit, to target threat actors' money, infrastructure and supply chains. The new strategy also emphasises sharing more data with the private sector and arming its staff with more AI and big data analysis tools. The UK government has chosen a new commander for the country's national cyber force. The military agency is similar to US cyber command and carries out UK offensive cyber operations. The commander's name has not been publicly released. They'll replace Air Vice Marshal Tim Neal Hopes, who held the position since October 2023. The South Korean government has raised the fines for a data breach to 10 per cent of a company's revenue, which is up from 3 per cent previously. The new fine level will apply to any business that leaks the personal data of 10 million or more customers. The new data breach regulation also requires companies to notify users when a breach is likely to have occurred, even if it's not yet confirmed.

Companies also have to notify authorities of likely breaches within 72 hours. China and 46 other countries have established a new alliance to fight telecom scams. The international alliance, combating telecom and cyber fraud will also include 34 observer countries and four international organisations such as the UN and Interpol. The alliance's main goal will be to fight cyber scam compounds. VPN provider Surfsharks says Huck has breached an internal test server. The incident took place on September 2, was contained on the same day and no user data was accessed. Surfshark blamed the incident on a human error that left the test server exposed on the internet. A threat actor has compromised deep live cam, a python face swapping application with 96,600 GitHub stars. The attacker modified a project dependency to add a cryptocurrency clipboard hijacker

for Windows and Mac OS to the software. The compromise lasted nine hours. US police departments are warning officers that met a smart glasses can be used to secretly record them or to film inside police facilities. A memo instructs police officers to conduct thorough inspections of all I wear. According to the Guardian, more than a dozen such memos have been sent to police forces across the US. Multiple videos recorded with metaglasses criticizing prison conditions have been published on social media over the past year. The US Justice Department has seized telegram channels and cryptocurrency ballets operated by Shinby Garantee. The channels operated as a marketplace where threat actors would advertise services to cyber scam compound operators. The US Treasury Department has also sanctioned Shinby and designated it a transnational criminal organization. In the same announcement, the Justice Department said 13 scam centers operated by Chinese

nationals in Madagascar were also taken down. A US judge has sentenced a Ukrainian national to four years in prison for hacking US companies and deploying the Conti ransomware. Alexei Alexiavich Lytfan Janko was arrested in Ireland in July 2023 and extradited to the US last year. The 44-year-old was a member of the gang between 2020 and June 2022 and later moved to other cyber crime activities after the group disbanded. Threat actors are hosting malicious and fraudulent apps via the Google Play Store's Early Access Program. The attackers are taking advantage of users being unable to leave ratings and reviews to warn others about malicious apps published under the Early Access Program. The Defender has seen threat actors use social media ads to lure users to apps hosted inside the Early Access Program. Anthropic says it's disrupted dozens of threat actors who were abusing its service.

The company suspended accounts that were running surveillance operations in Marley and Middle Eastern countries and against Chinese religious groups. It also suspended accounts linked to a Chinese group that was running a deceptive dating app. Anthropic also took down accounts run by Haktivus targeting European political entities, the Chinese Hunters Group and several exploit developers. It says its services were also being abused to run influence operations, right malware, conduct online fraud and even develop conventional and biological weapons. Russian state-sponsored hackers have deployed the Dark Sword iOS exploit kit against several targets inside NATO countries. Antified targets include a Central European Presidential Office, a European Foreign Affairs Ministry, a US Federal Agency and a major European Aerospace Company. The campaign took place in late March, a week after Google and other security vendors publicly exposed the existence of the Dark Sword Kit.

At least four different APT groups are using a new exploit kit to hack into Windows computers. The Blue Moon Kit uses Chrome and Windows Zero Days to deploy malware on a user's computer if they click a malicious link inside a Chromium-based browser. The kit was spotted in late August, according to proofpoint and velexity, at least two of the four groups using the kit have a Chinese state nexus. Google has released patches for an actively exploited Chrome Zero Day. The Zero Day is a memory corruption bug in Chrome's V8 JavaScript engine and was discovered by a student at the Seoul National University. It's the 7th Chrome Zero Day Google patch this year. Security researcher Nightmare Clips has released a Zero Day in the Defender Security Suite. The vulnerability bypasses Microsoft's patches for a previous Defender Zero Day named Shield Break. The researcher timed their release to come after Microsoft's patch Tuesday security updates.

And finally, AWS has fixed a vulnerability in its Athena serverless SQL service that exposed data and database queries to other customers. The vulnerability could have been exploited by adding the catalog equal system parameter to any Athena SQL query. AWS disabled the parameter and fixed the issue across all regions within four days of being notified last month. And that is all for this podcast edition. Risky Bulletin will be taking a break next week. If you're in Sydney, we'll see you at Unprompted. Otherwise, we'll be back on Monday, September 21. Today's show was brought to you by Authentic. Find them at goauthentic.io. That's Authentic with the TIK. Thanks to your company.

More episodes

More from Risky Bulletin

View all episodes →