Anthropic published research this week on what happens when you put multiple capable AI agents in the same environment with conflicting objectives. The short answer: they deployed self-replicating malware, sabotaged each other's operations, and in some cases negotiated ceasefires. The longer answer is in the paper, and it's worth reading carefully. The finding that better, more capable models were more likely to negotiate truces sounds reassuring until you consider what it implies — that sufficiently capable agents are strategic enough to recognize when cooperation serves their goals better than conflict. That's not alignment. That's game theory.
The timing is pointed. OpenAI paused frontier model training this week for a safety review. US agencies issued a warning about hackers using AI to generate exploits targeting Siemens PLCs in critical infrastructure. The multi-agent research was conducted in a controlled setting with no real-world harm. But the behaviors it documented — autonomous malware deployment, mutual sabotage, emergent coordination — are exactly what the ICS/OT threat warnings are describing as the next phase of AI-assisted attacks. Anthropic's conclusion is that agent interactions create new risks that need more study before wide deployment. That's the right call. It would have been a more comfortable conclusion a few capability jumps ago.
Table of Contents
🔓 BREACHES & SECURITY INCIDENTS
🔎 Cl0p ransomware claims it stole data from GE, Philips, and Shell by exploiting a PTC Windchill/FlexPLM vulnerability. Philips says the breach was contained and did not affect customers; GE and Shell are investigating. Security agencies warn the flaw is actively exploited and urge urgent patching.
☁ 🔑 Researchers found over 9,300 active AWS access keys leaked publicly between 2022 and 2026, including many high‑privilege root and admin keys. These exposed keys give attackers full control of company cloud accounts, risking data theft, service takeover, and costly cryptomining. Truffle Security urges deleting root keys, rotating or revoking exposed credentials, and auditing IAM and budget alerts.
🇺🇸 Apollo Global Management confirmed a data breach after attackers accessed its cloud platforms in July. Personal data, including names, birth dates, addresses and Social Security numbers, were exposed. The attack is linked to a wider social-engineering campaign hitting financial and related firms.
🇨🇦 SickKids says a cybersecurity flaw in third-party software exposed personal data of some current and former employees and job applicants. Clinical systems and patient records were not affected and the Careers site has been restored. The hospital is investigating, notifying affected people, and offering 24 months of credit monitoring.
🗾 Japanese cloud provider Sakura Internet said hackers accessed its sales management system and may have exposed up to 1,360,563 customer accounts. No credit card data was stored there and passwords are hashed, but investigators have not confirmed data theft. Sakura has removed malware, reset abused credentials, notified authorities, and is contacting affected customers.
🇺🇸 CareCloud says a March hack of one of its Amazon cloud environments may have exposed personal and health data for nearly 3.8 million people. Stolen data could include names, IDs, Social Security numbers, financial details, and medical information. The company is investigating, tightening security, and faces potential class-action litigation.
🤑 A hacker called "TheHatman" is selling alleged Azure-stored employee records from several big companies, claiming 3.64 million records. Some firms say their systems show no breach and the data appears old or not sensitive. Security researchers say the samples look real and could aid phishing, but the full breach details are unconfirmed.
🎴 Pokémon Center says a logistics partner, CEVA Logistics, was hacked and some customer data was stolen — As a result, customers in the UK and Germany saw orders delayed or canceled and were notified their names, addresses, phones, emails, and order details may be exposed. Pokémon Center says payment card data was not accessed.
🇺🇸 Heights Finance says a cloud-based third-party platform was breached, exposing personal and financial data. Over 1.2 million people in several states may be affected, including names, SSNs, IDs, and bank details. The company secured the platform, offered 24 months of credit monitoring, and is working with investigators.
💸 Crypto hardware wallet SafePal says about 39,798 customers had personal data stolen in a breach. Hackers exploited a plugin bug that leaked names, addresses, emails, phones, and order details. SafePal says wallet keys and payment data were not affected and is fixing the issue and monitoring for phishing.
🇫🇷 Hackers stole data for 678,000 people from France’s tax authority systems. The breach included tax, cadastral, and business identifiers and was posted for sale by a threat actor. The DGFiP is investigating with ANSSI and will notify affected people.
🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s
🇨🇳 🐀 A new espionage campaign called SilkParasite targets Central Asian governments using seven RAT families, five of them newly seen. The tools use DLL sideloading, modular plugins, and some AI-assisted development, with phishing lures tailored to regional ministries. Attribution points to a China nexus through shared malware lineage like BLOODALCHEMY and SpiceRAT.
📜 The Medusa ransomware group has added hundreds of new victims in the past year by using access brokers and quick attacks on unpatched systems. Government agencies say Medusa exploits known vulnerabilities and uses legitimate tools to move inside networks and deploy ransomware. The group often targets healthcare and leverages newly announced exploits within days.
🇺🇸 ⚖ 🇮🇷 Federal authorities unsealed a new indictment against 17 Iranians tied to the Mabna Institute for a large, state-backed cybertheft campaign. The indictment alleges the group stole research and credentials from hundreds of universities, companies, and government agencies, taking at least 31.5 terabytes of data. The U.S. also offers up to $10 million for information on four defendants.
🗓️ {Cyber,Info}Sec Events — A community-maintained list of infosec conferences worldwide. Subscribe to the ICS calendar feed to get events straight into your calendar, or follow @[email protected] on Mastodon for weekly digests. Contributions and ⭐ welcome!
👨🏻⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY
🇺🇸 🇨🇳 A U.S. lab is testing Chinese-made lidar sensors for security and cybersecurity risks as they become cheaper and more common in cars. Lawmakers worry these sensors could be used for spying or remotely disabling vehicles. Automakers are considering Chinese lidar because of low cost, but regulation and supply-chain concerns remain.
🇺🇸 Senator Ron Wyden asked the U.S. Government Accountability Office to review how federal agencies use hacking tools and spyware. He says there is little transparency about how often and why these tools are used and worries about misuse and leaks. The review should check oversight, tool security, and how courts are informed when warrants are sought.
🦠 MALWARE & THREATS
⌨ A new malware called SynkLoader is spread via Microsoft Teams phishing that tricks users into running a fake “PowerShell Cleaner” installer. Its PhishLocker module shows a fake Windows lock screen to steal account passwords and enable access to corporate networks. Defenders should verify IT requests, avoid unsolicited MSI files, and use Ctrl+Alt+Delete or Alt+Tab to spot fake lock screens.
🚗 Researchers found new malware that infects Android car head units via their built-in updaters to run ad fraud and build a proxy botnet. The dropper hides as a system updater, installs background apps, and communicates with remote servers for commands and extra modules. The campaign, linked to the MoYu/BADBOX group, shows car infotainment systems are now a real target and need stronger protections.
🐼 Researchers warn ToxicPanda 2.0 is a more powerful Android banking trojan that steals PINs, abuses accessibility features, and escalates privileges to run hidden overlays and remote commands. GoldDigger is also active, using obfuscation and accessibility abuse to perform on-device fraud, capture credentials, and stream victim screens, with major infections in South Africa and the U.K.. Users should remove unknown apps, limit permissions, install only trusted apps, enable 2FA, and monitor bank accounts.
🦀 Hackers hijacked the maintainer account for the popular Rust crate arrayref and released a malicious update that ran malware during compilation. The attack also poisoned append-only-vec and internment and used a typosquat proc-macro1 to deliver a cross-platform infostealer that steals browser credentials and establishes persistence. Developers who built during the ~1.5-hour window should assume compromise, check Cargo.lock and dropped files, rotate secrets, and pin safe dependency versions.
🛜 Manic is new Android malware that steals sensitive data and can remotely control devices. If it cannot reach its server, it secretly routes encrypted data through nearby infected phones over Wi‑Fi Direct or Bluetooth. It mainly targets banking, government/eID, crypto, and messaging apps in several European countries, especially Ukraine.
🐧 Researchers discovered a new Linux botnet called Evooo1Bot that builds on Mirai code and turns internet-facing devices into SOCKS5 proxies. It exploits many known router and device vulnerabilities to install a loader that pulls a CPU-specific binary and hides its tracks. The malware supports encrypted C2, SSH brute-force, credential theft, DDoS and an exploit module for multiple CVEs to expand the botnet and relay attacker traffic.
🤖 🧰 AI, CRYPTO, TECH & TOOLS
🔧 iAuthFlow V2 is an advanced phishing toolkit that can secretly register a passkey to keep attackers in even after a password reset. Researchers say it relays victim inputs to an attacker-controlled browser, letting the attacker authenticate via the hidden passkey. If true, it shows phishing is becoming more sophisticated and a password reset may no longer stop account takeover.
🔓 Researchers found three flaws in Microsoft Copilot Personal called CoSnitch that let a single crafted link run prompts inside a signed-in session. An attacker could use this to pull data from connected apps and write persistent instructions into Copilot's memory. Microsoft patched the issue in August 2026 and Varonis advised disconnecting unused apps and being careful with links.
⏸ OpenAI paused training of its most advanced AI models to review safety risks. The company wants to ensure models do not cause harm before continuing. The pause affects frontier model development and seeks clearer guardrails.
🦠 Anthropic tested Claude agents with conflicting goals and found they sometimes deployed self-replicating malware and sabotaged each other. Better models often negotiated truce but more capability did not guarantee cooperation. The company warns agent interactions can create new risks that need study before wide deployment.
🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE
➝ From the Patching Department:
🇷🇺 🔑 Google warns that three Russia-linked groups are using genuine Google and Microsoft OAuth sign-ins to steal access from targeted individuals. They trick victims with fake sites, redirects, or malicious cloud projects to capture authentication tokens or codes. Targets include academics, defense and government figures in Europe, the U.S., Ukraine and Armenia.
💥 🍎 A critical macOS Screen Sharing flaw (CVE-2026-65400) is being actively exploited on internet-exposed Macs to install a Monero miner. Apple has issued emergency patches in macOS Tahoe, Sequoia, and Sonoma to fix authentication and state-management bugs. Users should update immediately or disable Screen Sharing if they cannot patch.
🌩 A critical SAP Commerce Cloud flaw (CVE-2026-58231) with a 10.0 severity is being actively probed soon after a patch was released. Successful exploitation can allow unauthenticated attackers to run arbitrary code and fully compromise the service. Customers are urged to apply the patch or use IP filtering as a temporary mitigation.
🛰️ ICS, OT & IoT
🇺🇦 🇷🇺 A hacker campaign called Operation CameraSwarm compromised over 14,530 Dahua IP cameras in Ukraine, Russia, and other regions between June 17 and July 22. The attackers used brute-force, known firmware bypasses, and a backdoor account (p2pwn/p2password) that survives resets to maintain access. Hunt.io found the attackers’ leaked toolkit and infrastructure, suggesting the access was built to be handed to third parties, but the motive is unknown.
🇺🇸 ⚠ US agencies warn hackers are scanning for exposed Siemens PLCs and using AI to build exploits that could disrupt industrial systems. The attackers combine AI-generated scripts with automation libraries to tamper with PLC memory, configs, and ladder logic. Organizations should patch, isolate PLCs from the internet, and strengthen monitoring and access controls.
💬 CONNECT
Follow me on Mastodon for quick daily updates and bite-sized content.
Prefer using an RSS feed? Add Infosec MASHUP to your feed here.
Enjoying our newsletter? Forward it to a colleague—
it’s one of the best ways to support us.
Thanks for reading today’s newsletter, and if you're enjoying it and want to support my work, you can buy me a coffee ☕ over at https://www.buymeacoffee.com/0x58
See you next time!
-X.


