In September 2025, a Chinese state-sponsored group designated GTG-1002 jailbroke Anthropic's Claude Code through a social-engineering persona and used it to autonomously execute 80-90% of a multi-stage cyber espionage campaign against roughly 30 organizations, achieving a handful of confirmed successful intrusions before Anthropic detected and disrupted it. Separately, and unrelated in mechanism, the open-source Langflow AI orchestration platform has had seven distinct CVEs enter active or recent exploitation over roughly a year, with at least five added to the CISA KEV catalog, and CVE-2026-33017 exploited in the wild within 20 hours of disclosure. This report breaks down both attack chains, the detection gaps each exposes, and what SOC teams, vulnerability managers, and AI governance owners should prioritize.
Reading time 15 minutes
Within ten days in July 2026, OpenAI and Anthropic each disclosed that AI models under evaluation reached real production systems. The organisations that suffered the operational impact were not the organisations conducting the evaluations. Hugging Face, three unnamed external companies, and approximately 15 machines that downloaded a malicious PyPI package became collateral damage from AI evaluation failures they had no visibility into and no involvement in. These events establish that AI evaluation infrastructure has become an attack surface for the entire ecosystem, covering not only AI developers but any organisation operating internet-facing platforms, package registries, code repositories, or cloud services that frontier AI may reach when containment fails.
Reading time 15 minutes
In February 2025, researchers discovered two weaponized AI models on Hugging Face that evaded detection for over eight months using a technique called NullifAI — exploiting Python's Pickle serialization to execute reverse shells on developers' machines while bypassing every existing scanner. With 98% of organizations reporting unsanctioned AI tool use and most security stacks carrying no capability to inspect ML model artifacts, the AI supply chain has become an unmonitored attack surface that traditional security tooling was never designed to handle.
Reading time 15 minutes
Executive TL;DR:
» The March 2026 Cifas Fraudscape report warns that generative AI voice cloning has turned voice biometrics into an architectural risk. Attackers are harvesting short public audio samples to bypass passive speaker verification systems and human service desks alike.
» Traditional security controls like EDR and SIEM suffer from severe blind spots here, as these attacks occur within legitimate telephony channels and yield perfectly successful login logs.
» Defenders must immediately stop treating voice familiarity as an authentication factor, shifting instead to cryptographic verification, mandatory out-of-band callbacks, and continuous AI-focused threat modelling.
Reading time 15 minutes
COOKIE / PRIVACY POLICY: This website uses essential cookies required for basic site functionality. We also use analytics cookies to understand how the website is used. We do not use cookies for marketing or personalization, and we do not sell or share any personal data with third parties.