Anthropic's AI Misuse Report: Agents Do the Work, Humans Steer
Anthropic's report on detected Claude misuse describes AI agents handling reconnaissance, exploitation and data theft while humans pick targets and review output. Here is what security teams should take from it.
Iran's MOIS Uses Telegram-Controlled Spyware Against Dissidents
A joint FBI, NCSC, and AIVD advisory details CHOSEN BRICK, Windows spyware that Iran's intelligence service has run through Telegram bots since 2023 to surveil journalists and activists worldwide.
A Fake DeFi Startup Exposed How North Korean IT Workers Get Hired
Researchers built a shell company, ran a full hiring pipeline, and let sandboxed 'employees' walk straight into a monitored environment — capturing the tooling behind DPRK employment fraud in granular detail.
Bauman University Leak Exposes Russia's GRU Cyber-Operator Pipeline
A roughly 1.8GB leak from a covert department at Bauman Moscow State Technical University details how the GRU recruits, vets, and routes students into units linked to APT28 and Sandworm.
OpenAI Disrupts Cambodia-Based ChatGPT Scam Network — What It Reveals
OpenAI banned accounts tied to a Cambodia-based crime network that used ChatGPT to run romance, crypto, gambling, and impersonation scams simultaneously — and to manage forced-labor recruitment behind the operation.
Unit 42's AI Malware Reality Check: 97% Never Left the Sandbox
Palo Alto Networks' Unit 42 analysed 405 AI-touched malware samples and found almost all of them were proof-of-concept or researcher submissions — but the handful that reached real endpoints show where the trend is actually heading.
MacSync Stealer: Microsoft Traces macOS Malware Through 30+ Rotating Domains
Microsoft Defender Experts mapped MacSync Stealer's infrastructure not by blocklisting domains, but by fingerprinting the behavior behind them — a lesson for anyone still treating IOC feeds as a detection strategy.
Dysphoria Botnet Moves C2 to Ethereum and Solana Name Services
After a March law-enforcement takedown of JackSkid infrastructure, the same IoT-botnet operator rebuilt around blockchain name records and infected-device relays — a design built to survive the next seizure.
Insurance Phishing Goes Real-Time: Inside the InsureOTP Kit
CTM360 has uncovered a phishing framework that no longer waits to cash in stolen logins — it hijacks insurance accounts live, relaying intercepted OTPs before they expire.