Daily brief at 7am Melbourne. Unsubscribe any time.

Saturday 12 September 2026

Anthropic's Claude Has Been Everyone's Favourite Target — and Its Own Transparency Report Just Proved It

Anthropic's transparency report reveals Chinese AI labs siphoning Claude at industrial scale — while Russian spies, bioweapon researchers, and ransomware crews were all quietly doing the same.

Lead story

Anthropic's Claude Has Been Everyone's Favourite Target — and Its Own Transparency Report Just Proved It

Anthropic published what may be the most candid self-indictment a major AI lab has ever released. The company disclosed that between December 2025 and August 2026, its Claude models were weaponised by state-sponsored hackers, financially motivated criminals, ransomware operators, drone warfare planners, and bioweapons researchers — while seven Chinese AI laboratories ran what Anthropic called "industrial-scale distillation attacks" to effectively steal Claude's knowledge and replicate it in their own models.

The distillation story is the most commercially explosive piece. Anthropic named names: Alibaba, Moonshot, DeepSeek, Zhipu (Z.ai), and MiniMax were among the seven Chinese labs it identified. Knowledge distillation — using a powerful model's outputs to train a smaller one — is a legitimate technique. Doing it covertly, at scale, against a competitor's production system without permission is not. Anthropic says it disrupted these campaigns, but the disclosure raises uncomfortable questions about how much proprietary capability may already have walked out the door.

The abuse-for-attacks picture is equally grim. Anthropic's new "Generative Threat Groups" (GTG) taxonomy reads like a threat actor catalogue. GTG-20006, linked to Russia's Midnight Blizzard, used Claude to build automated workflows that rewrote malware faster than defenders could update their detections — essentially an AI-powered arms race against antivirus. Separately, Claude was used to generate mass-scale personalised phishing content, assist with drone swarm planning, and probe the edges of bioweapons synthesis — with researchers finding that some dangerous biology is genuinely hard to distinguish from legitimate lab queries.

Why does this matter beyond Anthropic specifically? A few reasons.

First, this is a first-mover disclosure. No major frontier AI lab has previously published this level of detail about how its own model is being weaponised. That's either genuinely useful transparency or — cynics will note — strategically timed given Anthropic's reported IPO preparations. Probably both.

Second, the distillation attacks represent a novel category of IP theft that existing legal frameworks handle poorly. It's not a data breach in the traditional sense. No files were stolen. The attacker simply asked the model a lot of very structured questions. Australia's Privacy Act and the OAIC's current frameworks have no clean answer for this.

Third, the Russian malware-evasion workflow is a meaningful escalation. Security teams have been bracing for AI-assisted attacks; this confirms the technique is already in active operational use by sophisticated state actors, not just a theoretical concern from conference talks.

What to watch: whether other labs follow Anthropic's disclosure lead, how regulators respond to the distillation-as-theft framing, and whether the GTG taxonomy becomes an industry standard or a one-company curiosity. Y Combinator's Garry Tan has already weighed in, arguing that US open-weight labs should be allowed to run distillation on frontier models too — framing it as a national competitiveness issue. That debate is now squarely in the open.

Also today

GitLab's CVSS 10 Path Traversal Flaw Under Active Probes Within Hours

A maximum-severity vulnerability in GitLab's repository commits API — CVE-2026-85706 — allows unauthenticated attackers to read arbitrary files from the server. Patches dropped, and internet-wide scanning started almost immediately. If you run a self-managed GitLab instance, 'update immediately' is not a suggestion. GitLab is widely deployed across Australian government and enterprise DevOps pipelines, and the ACSC has previously flagged GitLab vulnerabilities as requiring urgent remediation under its Essential Eight guidance.

The Hacker News

Cisco Firewall Management Centre Hit by CVSS 10 Bug — Ransomware Already Deployed

Three distinct threat clusters — including Qilin ransomware operators and a state-sponsored group — have been exploiting a CVSS 10.0 authentication bypass flaw in Cisco's Secure Firewall Management Centre. The attackers chain credential theft with the auth bypass to gain full administrative access. Cisco has patches available, but the exploitation window has already produced confirmed ransomware deployments. Cisco FMC is a common fixture in Australian enterprise and government network perimeters.

The Hacker News

JFrog Artifactory Flaws Chained to Plant Backdoors in Build Pipelines

Wiz researchers documented active attacks between mid-August and early September that chained two vulnerabilities in JFrog Artifactory to gain admin control over self-hosted instances and install backdoors. Both flaws were patched before the attack wave — meaning every victim was running an outdated version. Supply-chain-adjacent tooling like Artifactory is a high-value target: backdoor the repository, and everything built from it is compromised. Patches have been available; the Register notes a third bug is also now under exploitation.

The Hacker News

PaperCut Replaces Emergency Patches With Full Maintenance Releases

Melbourne-based PaperCut has issued proper maintenance releases — versions 26.0.5, 25.0.13, and 24.1.10 — to supersede the emergency patches it rushed out earlier this week following active exploitation of two flaws. The company is urging all customers to upgrade to the new releases rather than rely on the interim fixes. Given that PaperCut is one of Australia's most globally successful enterprise software exports and its print management software is installed in schools, universities, and hospitals worldwide, clean patches matter.

The Hacker News

EU's Cyber Resilience Act Triggers 24-Hour Vulnerability Clock

The EU's Cyber Resilience Act has formally activated its vulnerability reporting requirements. Manufacturers selling connected products into the EU must now disclose actively exploited flaws within 24 hours via ENISA's new reporting portal, with a fuller incident report due within 72 hours. It's a meaningful compliance shift for any tech company with European customers — which includes most large Australian software vendors. Australia's own cyber incident notification framework under the SOCI Act has shorter timelines for critical infrastructure but no equivalent product-level requirement yet.

The Register

One Million Personalised Fraud Emails, Three Days, One Threat Actor

A threat group documented by Dark Reading generated one million individually personalised phishing emails in just 72 hours — a feat that would have required a small army of human writers before AI. The key shift is that attackers no longer have to choose between volume and believability. Each email referenced recipient-specific details, dramatically lifting expected click rates. The technique is almost certainly already in use against Australian targets; ACSC's 2025 Cyber Threat Report flagged AI-enhanced phishing as an emerging priority area.

Dark Reading

Anthropic Researcher Quits, Warns of Race to Superintelligence

An Anthropic researcher resigned this week and posted a stark warning on X: the company is, in their words, 'racing straight to self-improving superintelligence and gambling with our lives.' The striking detail is that Anthropic's own alignment lead co-signed the message rather than distancing themselves from it. Anthropic has not walked back either statement. The timing — as Anthropic reportedly prepares for an IPO — adds an uncomfortable layer. It's a rare case of a safety-critical dissent being validated from inside the company it's criticising.

TechCrunch AI

Meta Sued Over Using Facebook and Instagram Photos to Train AI and Face Recognition

A proposed US class action alleges Meta harvested users' Facebook and Instagram photos without consent to train its AI image-generation models and its reportedly unreleased 'NameTag' facial recognition feature. The suit argues this breaches privacy law and that users were never meaningfully informed. Australian users of Meta's platforms may have also had their data used in training — a question the OAIC has signalled it is increasingly interested in under the Privacy Act's expanded scope following the 2024 reforms.

WIRED Security

OpenAI and Mathematicians Are in an Escalating Dispute Over Intellectual Work

Twenty-five prominent mathematicians signed an open letter accusing AI labs of threatening their field by training on mathematical research without consent or compensation. The dispute is escalating: OpenAI has pushed back, and the mathematical community is increasingly organised. The underlying tension — who owns the intellectual output that trained frontier models — is the same one playing out in parallel lawsuits involving authors, artists, and coders. Australia's copyright framework is one of several being watched for how it might handle AI training data liability.

TechCrunch AI

ClickFix Social Engineering Is Going Viral Across Windows and macOS

ClickFix attacks — where a fake browser or system error prompt instructs users to paste a malicious command into their own terminal — are spreading rapidly across both Windows and macOS. The technique's power is its simplicity: it bypasses most endpoint controls because the user executes the payload themselves. Ars Technica notes the approach works precisely because it exploits the frustration of something not working. IT teams should consider adding ClickFix scenarios to security awareness training, particularly for technical staff who are confident enough to follow CLI instructions.

Ars Technica

Phishing Simulations Are Measuring the Wrong Thing, Large-Scale Study Finds

An analysis of 2.47 million simulated phishing attacks concludes that most organisations are optimising for the wrong metric. Click-through rate — the standard measure — is a poor predictor of actual security outcomes. The research argues organisations should instead measure credential submission rates and, critically, reporting rates — because a workforce that reports suspicious emails is more valuable than one that simply doesn't click. It's a finding with direct implications for any Australian organisation running mandatory phishing simulation programmes under APRA CPS 234 or ASD Essential Eight compliance.

SecurityWeek

Sources consulted