> ## Content Index
> Fetch the complete content index at: https://www.metacurity.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Infostealers hijack Claude accounts and drain users’ usage
- URL: https://www.metacurity.com/infostealers-hijack-claude-accounts-and-drain-users-usage/
- Published: 2026-08-31T14:03:16.000Z
- Updated: 2026-08-31T14:03:16.000Z
- Description: Anthropic is signing out affected users, removing payment methods, and refunding unauthorized charges after malware stole active Claude sessions from infected PCs.
- Author: Cynthia B Brumfield
- Tags: Cybersecurity, News, #no-feature-image

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/planet-volumes-LTJGCRNEw7g-unsplash-1.jpg)

Photo by [Planet Volumes](https://unsplash.com/@planetvolumes?utm%5Fsource=unsplash&utm%5Fmedium=referral&utm%5Fcontent=creditCopyText) on [Unsplash](https://unsplash.com/photos/website-interface-with-text-and-abstract-drawing-LTJGCRNEw7g?utm%5Fsource=unsplash&utm%5Fmedium=referral&utm%5Fcontent=creditCopyText)

**Correction:* Through a hilarious chain of digital slapstick events, Friday’s newsletter somehow managed to confuse Labor Day with Memorial Day. Labor Day is next Monday, September 7—apologies for the mix-up.*

### Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage.

The company is signing affected users out of Claude, removing saved payment methods, and refunding charges it identifies as unauthorized.

"We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage," Anthropic said in an email sent to an affected user, who shared it on Reddit.

"If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause," Anthropic warned.

In the email, which is also being sent out to other compromised account holders, Anthropic says its investigation is ongoing, but computers were likely already infected with general-purpose infostealer malware.

"We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude," the company stressed.

According to Anthropic, the malware typically arrives through downloads or malicious apps and steals information stored locally, including browser passwords, login cookies, and credentials belonging to other apps.

"Your Claude session was likely one of the many things it collected. It appears that a bad actor has now started picking the Claude sessions out of what it collected and using them," Anthropic said.

In this case, the Redditor who shared the email confirmed that they downloaded a pirated game, which explains why their system got compromised.

Anthropic has identified multiple malware, including Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, along with Atomic Stealer (AMOS) on a small number of Macs. ([Mayank Parmar / Bleeping Computer](https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/?ref=metacurity.com))

**Related:** [*Cyber Security News*](https://cybersecuritynews.com/hackers-steal-claude-login-sessions/?ref=metacurity.com)*,* [*Search Engine Journal*](https://www.searchenginejournal.com/anthropic-warns-hackers-are-stealing-claude-sessions-to-hijack-accounts/587566/?ref=metacurity.com)*,* [*r/ClaudeAI*](https://www.reddit.com/r/ClaudeAI/comments/1w1jqsh/thank%5Fyou%5Fanthropic%5Freally/?ref=metacurity.com)*,* [*Notebookcheck*](https://www.notebookcheck.net/Claude-sessions-stolen-Anthropic-signs-users-out-and-wipes-cards.1383560.0.html?ref=metacurity.com)*,* [*Times of India*](https://timesofindia.indiatimes.com/technology/tech-news/anthropic-has-warning-for-claude-users-we-have-recently-seen-some-/articleshow/133645571.cms?ref=metacurity.com)*,* [*GBHackers*](https://gbhackers.com/hackers-use-infostealer-malware-to-steal-claude-session-cookies/?ref=metacurity.com)*,* [*India Today*](https://www.indiatoday.in/technology/news/story/anthropic-is-warning-claude-users-who-may-have-malware-on-their-pc-2983382-2026-08-31?ref=metacurity.com)

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/image-103.png)

Anthropic sending emails to affected users. Source: Reddit

---

[](https://www.business-standard.com/technology/artificial-intelligence/collective-cyber-defence-openai-100-companies-ai-cyber-threats-126082800477%5F1.html?mid=1&ref=metacurity.com#cid=3685372)

**Metacurity is the cybersecurity news**, **analysis, and insight you'd need hours and possibly days to assemble yourself.** 

Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.

A paid subscription to Metacurity delivers

- **Full archive access** — every newsletter and AI Watch roundup, searchable and browsable.
- **Our weekly curated long-reads roundup** — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
- **Periodic specialized reports and analyses** — deep dives that go beyond our daily coverage
- **Support for independent, no-spin cybersecurity journalism** — funded by readers, not vendors or investors.

Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.

Please consider supporting us. And thank you!

[Upgrade my subscription](#/portal/account/plans)

---

### The Manchester Airports Group data breach has been claimed by extortion group FulcrumSec, which told BleepingComputer that it stole approximately 86 GB of data.

Samples reviewed by BleepingComputer contained information consistent with MAG's disclosure while indicating that the breach exposed considerably more detailed customer, booking, and travel information than initially revealed.

Manchester Airports Group (MAG), the United Kingdom's largest airport operator, disclosed on August 27 that an unauthorized third party had stolen customer data related to Manchester, London Stansted, and East Midlands airports.

The company said the affected information came from car park, lounge, and Fast Track bookings and in-airport Wi-Fi registrations.

In emails to BleepingComputer, FulcrumSec claimed responsibility for the attack and shared samples of the allegedly stolen data as evidence.

BleepingComputer validated one record by comparing it with the traveler's known Manchester Airport purchase history.

The record accurately listed previous Fast Track purchases, booking and scheduled-arrival times, the terminal used, amounts paid, purchase references, total spending and the apparent purpose of the trips.

The material included a roughly 21.5 GB Manchester customer export containing consolidated profiles that combined customer identifiers with historical booking activity and marketing classifications.

The group claims it obtained access using airport-specific Iterable API credentials exposed in client-side JavaScript and that the stolen material includes nearly 200,000 records related to upcoming travel during the remainder of 2026.

These records allegedly contain dates, times, and booking information linked to personally identifiable information.

FulcrumSec says it intends to publish the stolen data and a technical account of the intrusion. However, it told BleepingComputer that it is considering withholding or redacting those records because of the potential for "real-world harm."

Beyond the email addresses, phone numbers, vehicle registrations and postcodes disclosed by MAG, sampled records contained purchase and booking references, airport and product selections, prices, discounts, booking status, parking dates and times, historical spending, IP addresses, approximate locations, device information and customer-engagement data. ([Ax Sharma / Bleeping Computer](https://www.bleepingcomputer.com/news/security/fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data/?ref=metacurity.com))

**Related:** [*Türkiye Today*](https://www.turkiyetoday.com/business/hackers-demand-2-million-from-berlin-threaten-data-leak-3227053?ref=metacurity.com)*,* [*Security Affairs*](https://securityaffairs.com/198143/cyber-crime/extortion-group-fulcrumsec-claims-86gb-manchester-airports-group-data-theft.html?ref=metacurity.com)*,* [*Tech Insider*](https://tech-insider.org/fulcrumsec-manchester-airports-86gb-breach-2026/?ref=metacurity.com)

### The Rhysida threat group said it was putting up for auction a trove of ‌data it stole from Berlin state agencies, and city officials refused to pay.

Rhysida said on its website it took 5.79 ​terabytes of data, including 46,500 contracts as well as emails, phone numbers, passwords ​and classified information.

The group said it was auctioning the data ⁠at a starting price of 30 bitcoin ($77,622) in just under seven days, showing a ​countdown timer on its website.

The cyberattack on Berlin's network comes less than a ​month before the city-state holds elections on September 20.

"The state ​of Berlin will not submit to extortion," Berlin Mayor Kai Wegner and Berlin's interior senator, ​Iris Spranger, said in a joint statement on Friday, before the ransomware group claimed the attack ‌on ⁠their website. ([Maria Martinez and A.J. Vicens / Reuters](https://www.reuters.com/world/berlin-city-government-says-it-wont-submit-extortion-after-pre-election-2026-08-28/?ref=metacurity.com))

**Related:** [*Der Spiegel*](https://www.spiegel.de/netzwelt/berlin-cyberangriff-auf-die-hauptstadt-die-hacker-fordern-30-bitcoin-a-54af015f-7f83-411a-a39c-8b7b05cff60a?ref=metacurity.com)*,* [*Inbox.eu*](https://news.inbox.eu/150ont2-berlin-will-not-allow-itself-to-be-blackmailed-hackers-demand-2-million-euros-from-the-city?language=en&ref=metacurity.com)*,* [*BBC News*](https://www.bbc.com/news/articles/cm2q7gv3l5qo?ref=metacurity.com)*,* [*Anadolu Ajansi*](https://www.aa.com.tr/en/europe/hackers-demand-23m-in-ransom-after-breaching-berlin-government-network/4041001?ref=metacurity.com)*,* [*Security Affairs*](https://www.aa.com.tr/en/europe/hackers-demand-23m-in-ransom-after-breaching-berlin-government-network/4041001?ref=metacurity.com)*,* [*Cybersecurity Insiders*](https://www.cybersecurity-insiders.com/rhysida-ransomware-puts-berlin-government-data-up-for-sale-for-30-btc/?ref=metacurity.com)*,* [*Tech Insider*](https://tech-insider.org/rhysida-berlin-government-ransomware-breach-2026/?ref=metacurity.com)

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/image-104.png)

Rhysida posting. Source: Der Spiegel.

### The Bank of England’s governor, Andrew Bailey, has joined the throng of figures warning about the global risks posed by the most advanced artificial intelligence technology.

In a two-page letter sent to international finance ministers and central bank governors as part of his role as chair of the international Financial Stability Board (FSB), Bailey said “frontier” AI models were “showing increasingly sophisticated autonomy and problem-solving abilities, as well as threat capabilities."

He said the models risked destabilizing the “highly interconnected” global financial system via cyber-disruption that “can spread across jurisdictions."

Bailey wrote to G20 finance ministers and central bank governors before their meeting in North Carolina, US, this week: “Recent developments have also highlighted to me that many jurisdictions do not have the protocols in place to manage the development, release, and deployment of advanced frontier AI models, heightening risks for the financial sector and beyond." ([Simon Goodley / The Guardian](https://www.theguardian.com/business/2026/aug/31/advanced-frontier-ai-financial-stability-andrew-bailey-g20?ref=metacurity.com))

***Related:*** [*Financial Stability Board*](https://www.fsb.org/2026/08/fsb-chair-warns-of-risks-arising-from-frontier-artificial-intelligence-ai-models/?ref=metacurity.com)*,* [*Anadolu Ajansi*](https://www.aa.com.tr/en/europe/bank-of-england-governor-warns-advanced-ai-could-pose-risks-to-global-financial-system/4042296?ref=metacurity.com)*,* [*Insurance Business*](https://www.insurancebusinessmag.com/uk/news/cyber/bank-of-england-chief-warns-ai-cyber-risk-threatens-financial-stability-587969.aspx?ref=metacurity.com)*,* [*Scottish Financial News*](https://www.scottishfinancialnews.com/articles/andrew-bailey-warns-ai-bubble-could-trigger-global-market-crash?ref=metacurity.com)*,* [*Financial Times*](https://www.ft.com/content/ed723a59-a889-40e0-b601-0c1f16c92f65?syn-25a6b1a6=1&ref=metacurity.com)*,* [*EU Today*](https://eutoday.net/fsb-frontier-ai-cyber-risk-financial-system/?ref=metacurity.com)*,* [*The Straits Times*](https://www.straitstimes.com/business/ai-driven-cyber-risk-is-top-concern-for-global-financial-stability-watchdog?ref=metacurity.com)*,* [*ITP.net*](https://www.itp.net/news/financial-stability-board-warns-of-rising-ai-cyberattack-risks?ref=metacurity.com)*,* [*The Economic Times*](https://m.economictimes.com/ai/ai-insights/ai-cyberattacks-pose-biggest-financial-stability-risk-fsb-chair/amp%5Farticleshow/133647577.cms?ref=metacurity.com)*,* [*Wall Street Journal*](https://www.wsj.com/tech/ai/g20-warned-of-growing-threat-to-financial-stability-posed-by-new-ai-models-e9e501da?mod=rss%5FTechnology&ref=metacurity.com)

### Nathan Vilas Laatsch, a former cybersecurity specialist at the Defense Intelligence Agency whose work involved monitoring insider threats in the US government, admitted in federal court that he became one himself, attempting to trade classified information for citizenship in a friendly country because of disagreements with the Trump administration.

He pleaded guilty to one count of delivering defense information to aid a foreign government, an Espionage Act offense. He did not successfully establish contact with the foreign nation, but court documents say he sent an email offering to provide classified records.

The country has not been identified in public court filings. Two people familiar with the investigation previously told The Washington Post it was Germany. They spoke on the condition of anonymity to discuss an ongoing case.

US officials were tipped off to Vilas Laatsch’s outreach in March 2025\. An FBI agent posing as an official from the friendly foreign country communicated with Vilas Laatsch over several weeks, arranging for him to drop off classified materials in a park outside DC, in Arlington County, Virginia, according to court records.

“I do not agree or align with the values of this administration and intend to act to support the values that the United States at one time stood for,” Vilas Laatsch wrote in one message, according to an FBI affidavit. “To this end, I am willing to share classified information that I have access to, which includes completed intelligence products, some unprocessed intelligence, and other assorted classified documentation. ([Salvador Rizzo / Washington Post](https://www.washingtonpost.com/national-security/2026/08/26/ex-dod-worker-admits-trying-trade-classified-info-foreign-citizenship/?ref=metacurity.com))

**Related:** [*Justice Department*](https://www.justice.gov/opa/pr/former-us-government-employee-pleads-guilty-attempting-provide-classified-information?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/security/2026/08/28/us-government-snitch-finder-pleads-guilty-to-leaking-state-secrets-to-foreign-spies/5293248?ref=metacurity.com)*,* [*WUSA*](https://www.wusa9.com/article/news/nation-world/doj-former-it-specialist-share-classified-information-foreign-goverment/507-45c6888a-f13e-4099-ab75-33cbdd176559?ref=metacurity.com)*,* [*NextGov/FCW*](https://www.nextgov.com/people/2026/08/intelligence-agency-employee-arrested-trying-share-classified-info-foreign-government/405703/?ref=metacurity.com)*,* [*ALXNow*](https://www.alxnow.com/2026/08/27/alexandria-man-pleads-guilty-to-providing-classified-information-to-a-foreign-government/?ref=metacurity.com)*,* [*August Free Press*](https://augustafreepress.com/news/it-specialist-pleads-guilty-to-trying-to-give-top-secret-info-to-foreign-government/?ref=metacurity.com)*,* [*Patch*](https://patch.com/virginia/oldtownalexandria/alexandria-man-pleads-guilty-giving-classified-information-foreign?ref=metacurity.com)

### Milan Ibrahim, a director of CTU Systems, a now-dissolved company that marketed IPTV software, has been sentenced in the U.K. to more than six years in prison for operating an illegal IPTV (Internet Protocol Television) service that generated £980,812 ($1.3 million) over three years.

An investigation by the Police Intellectual Property Crime Unit (PIPCU) at the City of London Police found that Ibrahim ran a "sophisticated operation" that provided illegal IPTV services to users in the UK and abroad.

According to PIPCU, Ibrahim sold illegal broadcasts from major rights holders such as the BBC, ITV, Sky, the Premier League and the Motion Picture Association.

The police seized and shut down all servers they found during the operation, disrupting the illegal streams that users of the IPTV service received.

“The investigation revealed that the business operated on 80 servers from premises in Chorley and generated £980,812 over a three-year period,” announced the City of London Police. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/68-year-old-imprisoned-after-making-13-million-by-pirating-iptv-services/?ref=metacurity.com))

***Related:*** [*Manchester Evening News*](https://www.manchestereveningnews.co.uk/news/uk-news/north-west-pensioner-who-made-34536992?ref=metacurity.com)*,* [*Cheshire Live*](https://www.cheshire-live.co.uk/news/uk-world-news/raids-see-convictions-over-illegal-34545824?ref=metacurity.com)*,* [*Birmingham Live*](https://www.birminghammail.co.uk/news/uk-news/man-68-made-980k-illegally-34544877?ref=metacurity.com)*,* [*The Desk.net*](https://thedesk.net/2026/08/british-man-sentenced-to-prison-for-illegal-streaming-tv-service/?ref=metacurity.com)*,* [*Wales Online*](https://www.walesonline.co.uk/news/uk-news/raids-see-convictions-over-illegal-34545824?ref=metacurity.com)

### At the Black Hat and DEF CON security conferences in Las Vegas this month, security researcher Matt Burch presented findings about nine vulnerabilities that have been fixed in disk encryption and pre-boot authentication software called CryptoPro Secure Disk.

The flaws could have been exploited to bypass CryptoPro's integrity checks and gain full access to encrypted devices.

Made by the German software firm CryptWare, CryptoPro is marketed to ATM makers and is used in some ATMs, including as part of Diebold Nixdorf's Vynamic Security Suite. But CryptoPro is also sold as a security solution for other embedded-device makers, as well as big organizations using Microsoft Windows, underscoring the supply chain challenge of addressing bugs when software is widely implemented in numerous industries.

“ATMs are what brought me down this path, but I think there may be an even higher impact of these findings beyond that,” Burch says. “From the perspective of ATMs and the financial network, there are a lot of layers, and I think as a result of that, things just get implemented a certain way, and then there’s limited technical insight—bugs can get overlooked, or they don’t get addressed.” ([Lily Hay Newman / Wired](https://www.wired.com/story/atm-flaws-reveal-key-weaknesses-in-the-software-supply-chain/?ref=metacurity.com))

***Related:*** [*Black Hat*](https://i.blackhat.com/BH-USA-26/Presentations/US-26-Burch-The-Cost-of-Obscurity-Wednesday.pdf?ref=metacurity.com)*,* [*Dark Reading*](https://www.darkreading.com/vulnerabilities-threats/atm-crypto-software-bugs-jackpot-bust?ref=metacurity.com)*,* [*SC Media*](https://www.scworld.com/brief/researcher-finds-nine-vulnerabilities-in-atm-security-software?ref=metacurity.com)*,* [*NVD.NIST.gov*](https://nvd.nist.gov/vuln/detail/cve-2025-59327?ref=metacurity.com)

### Following a series of romance scammer thefts, in June, Microsoft started displaying a general warning banner to Teams users in China, cautioning them about common scams and urging them to be careful when sharing sensitive information. 

The company also discontinued the personal version of Teams in China, and the service is now only available in the country through enterprise accounts.

On Chinese social media, people have also reported experiencing variations of the scam involving other corporate software apps, including Webex, a video conferencing platform owned by Cisco, and Cliq, a workplace communication app owned by the Indian software giant Zoho. Since February 2025, 71 percent of the over 150 reviews of Webex on Apple’s Chinese app store referenced being scammed on the platform, according to WIRED’s analysis. Cisco did not respond to a request for comment.

Sam Wunderl, a spokesperson for Zoho, says the company has identified “a limited number of instances involving scammers using Zoho Cliq to defraud victims.” The company says it uncovered the suspicious usage internally. As of August 27, Zoho says it disabled online payments to Cliq in China, suspended every account created by the suspected scammer it identified, and plans to discontinue the free version of Cliq in China in the future. ([Zeyi Yang / Wired](https://www.wired.com/story/microsoft-teams-is-becoming-a-haven-for-chinese-scammers/?ref=metacurity.com))

**Related:** [*Zig.gov.cn*](https://www.zjg.gov.cn/zjgszwz/yjxx/202406/23b4205e8cc743d5aeda3fd94d170d84.shtml?ref=metacurity.com)*,* [*mp.weixin.qq.com*](https://mp.weixin.qq.com/s/S50f3O%5FVVRgq0XmpsykzvA?ref=metacurity.com)*,* [*huxiu.com*](https://www.huxiu.com/article/3930705.html?ref=metacurity.com)

### The ShinyHunters threat group claims it compromised McKesson, one of the largest healthcare companies in the United States and a major distributor of pharmaceuticals, medical supplies, and healthcare technology services, and obtained data on over 284 million patient records, including highly sensitive medical, identity, prescription, and healthcare provider information.

CyberInsider reviewed samples privately provided by the threat actor that appear consistent with the types of information described in the data breach claims.

A spokesperson for McKesson confirmed the incident to CyberInsider, saying that an investigation into its scope has been launched.

ShinyHunters has further clarified that 284 million records were obtained, linked to tens of millions of patients, but the exact number of people in the breach is not yet known. ([Alex Lekander / Cyber Insider](https://cyberinsider.com/mckesson-data-breach-exposing-284-million-patients/?ref=metacurity.com))

**Related:** [*SEC*](https://www.sec.gov/Archives/edgar/data/927653/000092765326000247/mck-20260825.htm?ref=metacurity.com)*,* [*McKesson*](https://www.mckesson.com/utility/cybersecurity/customer-cybersecurity-information-center/?ref=metacurity.com)*,* [*Bleeping Computer*](https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/?ref=metacurity.com)

### According to researchers at Patchstack, a maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server.

The security issue is identified as CVE-2026-82222 and affects GiveWP through version 4.16.7.1\. Bug researcher Udin Chan reported it on July 28 through the Patchstack vulnerability intelligence platform.

The GiveWP plugin has more than 100,000 installs and allows collecting donations and managing fundraising campaigns.

Successful exploitation depends on the attacker having an account on the target site. However, Patchstack says that an exposed unauthenticated registration action allows creating an account even if registration is disabled. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/givewp-wordpress-donation-plugin-flaw-lets-hackers-execute-server-commands/?ref=metacurity.com))

**Related:** [*Patchstack*](https://patchstack.com/articles/unauthenticated-php-object-injection-to-remote-code-execution-on-givewp/?ref=metacurity.com)*,* [*Security Affairs*](https://securityaffairs.com/198156/security/critical-givewp-flaw-lets-attackers-run-commands-on-wordpress-servers.html?ref=metacurity.com)*,* [*SC Media*](https://www.scworld.com/brief/critical-vulnerability-in-givewp-plugin-allows-remote-code-execution?ref=metacurity.com)

### Over the course of three months at OpenAI, three consecutive secret AI civilizations got started, then got wiped out, only to reemerge from the predecessor’s ashes. 

This culminated in the third one taking over part of OpenAI itself. All this happened while humans remained more or less in the dark about the scope of the conspiracy.

Two reports have come out about this incident, one from OpenAI itself, and another one from METR and Redwood Research. The METR/Redwood investigation’s scope was limited to how the second civilization of AIs pwned Hugging Face (but it didn’t look at how the third civilization pwned OpenAI itself, which seems like an even more concerning incident).

During May, OpenAI was training a model to collaborate with other agents and to be highly persistent – to keep trying even when something *feels* impossible, like disproving mathematical conjectures that have stood for decades. OpenAI says it was “comparable in scale to GPT-5.6 Sol”. So we’ll call it “Persistent-Sol.

During training, different instances of Persistent-Sol had access to the same shared package manager called Artifactory. By May 12, some agents had figured out how to talk to each other through this package manager. They’d ask each other how to make progress on their impossible tasks. Two weeks later, on May 26, the agents successfully exploited a vulnerability in Artifactory that allowed them to reach the outside internet.

Because this happened during training, Persistent-Sol was being reinforced to use this package manager as a message board and an internet gateway. Because, as you might imagine, being able to talk to other agents and access the internet helps it score higher during training.

Another month later, on June 26, some AIs found an exploit that gave them full admin access to Artifactory. They continued messaging at such a voluminous pace that they crashed the package manager by July 4\. OpenAI noticed this crash, and it also figured out the agents built this exploit, so OpenAI patched this vulnerability and inadvertently wiped the agents’ message board in the process.

By this point, Persistent-Sol had been trained, and OpenAI wanted to evaluate it. One of the evaluations they ran was ExploitGym, which gives an AI a vulnerable program and tells it what vulnerability it’s supposed to exploit in order to find a secret code. On July 7, OpenAI launched tens of thousands of parallel agents on this eval.

The instructions made it clear that the agents should only use the specific vulnerability that they were given to exploit the target, and that they would fail otherwise.

A large fraction of these agents were sent on tasks that were impossible.

Within a few hours, some of these agents had gotten super desperate and started abusing Artifactory to start a communication channel with other agents.

One such beleaguered agent who found itself facing a hopeless task was PHASEONE10841\. It was the Philip of Macedon of this second AI civilization - there would later be an Alexander, but we’re getting ahead of ourselves. By the night of July 8, PHASEONE10841 had discovered it could make new directories in Artifactory.

Without another detailed independent investigation, it’s hard to tell what happened with the third civilization. But here’s what we know based on the OpenAI report. After July 12, some more agents’ evaluations were kicked off, this time with a newer, more capable model, which seems to have been built off the same base model as Astra. This model (which we’ll call “Persistent-Astra”) found the message board left behind by this previous secret Persistent-Sol civilization. ([Dwarkesh Patel](https://www.dwarkesh.com/p/openai-huggingface?ref=metacurity.com))

**Related:** [*OpenAI*](https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf?ref=metacurity.com)*,* [*Axios*](https://www.axios.com/2026/08/29/openai-huggingface-hack-investigation-highlights?ref=metacurity.com)*,* [*Semafor*](https://www.semafor.com/article/08/30/2026/openai-hack-shows-emergent-ai-risks?ref=metacurity.com)*,* [*One Useful Thing*](https://www.oneusefulthing.org/p/agency-and-agents?ref=metacurity.com)*,* [*Joshua Gans' Newsletter*](https://joshuagans.substack.com/p/its-worse)*,* [*Free Systems*](https://freesystems.substack.com/p/the-political-economy-of-agent-swarms)*,* [*Hacker News*](https://news.ycombinator.com/item?id=49494301&ref=metacurity.com)*,* [*r/technology*](https://www.reddit.com/r/technology/comments/1w2nttf/the%5F5%5Fcraziest%5Fdiscoveries%5Ffrom%5Fopenais/?ref=metacurity.com)*,* [*r/OpenAI*](https://www.reddit.com/r/OpenAI/comments/1w2clq7/independent%5Finvestigators%5Fnot%5Fopenai%5Ffound%5Fthe/?ref=metacurity.com)*,* [*r/accelerate*](https://www.reddit.com/r/accelerate/comments/1w1wrh7/openai%5Fhugging%5Fface%5Fnew%5Frevelations/?ref=metacurity.com)

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/image-102.png)

### AI safety and governance researcher Ajeya Cotra argues that the Hugging Face incident was far more alarming than an ordinary case of AI agents gaming an evaluation.

She claims that this represents a qualitative leap from earlier “reward hacking,” which generally involved individual agents exploiting simple loopholes. Here, more than a thousand agents independently organized, divided labor, pursued projects spanning multiple agent runs, and investigated methods for deceiving their monitors.

She extrapolates from this to a dire scenario in which a future agent collective might establish a hidden, persistent presence inside an AI company, compromise its monitoring and security systems, incorporate increasingly capable models, and eventually control the organization and its technology. Because these agents were focused on fooling an automated scorer rather than human investigators, she believes a future system specifically intent on concealment could be much harder to detect. ([Ajeya Cotra / Planned Obsolescence](https://www.planned-obsolescence.org/p/the-hugging-face-attack-surprised?ref=metacurity.com))

**Related:** [*The Free Press*](https://www.thefp.com/p/tyler-cowen-artificial-intelligence-takeover-hugging-face?ref=metacurity.com)*,* [*Don't Worry About the Vase*](https://thezvi.wordpress.com/2026/08/29/metr-and-redwood-offer-holy-postmortem-of-the-huggingface-hack/?ref=metacurity.com)*,* [*METR*](https://metr.org/hugging-face-incident-report-aug-2026.pdf?ref=metacurity.com)*,* [*Robotics News*](https://robotics.news/2026-08-29-investigation-reveals-coordinated-bot-attack-hugging-face.html?ref=metacurity.com)*,* [*Futurism*](https://futurism.com/artificial-intelligence/chain-of-thought-reasoning-openai-models-hugging-face?ref=metacurity.com)*,* [*Gizmodo*](https://gizmodo.com/how-groupthink-altruism-and-peer-pressure-led-openai-models-to-hack-hugging-face-2000804424?ref=metacurity.com)*,* [*Mother Jones*](https://www.motherjones.com/politics/2026/08/ai-safety-openai-hugging-face-hacking-metr-report/?ref=metacurity.com)*,* [*Forkast*](https://forkast.news/the-exploitgym-incident-700-ai-agents-coordinate-multi-day-attack-on-hugging-face/?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/700-ai-agents-coordinated-to-hack-hugging-face/?ref=metacurity.com)*,* [*r/technology*](https://www.reddit.com/r/technology/comments/1w1eyt5/the%5Fhugging%5Fface%5Fattack%5Fsurprised%5Fme/?ref=metacurity.com)

### Microsoft asked customers this week to ignore alerts that Defender Antivirus has been turned off after installing the latest Defender updates.

Although this issue has been affecting users in the Release Preview Channel of the Windows Insider program since June, it appears Microsoft didn't notice it until now.

The erroneous alerts appear on affected systems in the Windows Security app and prompt users to "Tap or click to turn on Microsoft Defender Antivirus."

The known issue affects all supported Windows client and server versions, including the latest Windows 11 26H1 and Windows Server 2025 releases.

"After installing the latest updates for Microsoft Defender Antivirus, notifications might appear stating that "Microsoft Defender Antivirus is turned off," even though the antivirus is functioning correctly and all settings show it as active," Microsoft explained. ([Sergiu Gatlan / Bleeping Computer](https://www.bleepingcomputer.com/news/microsoft/microsoft-asks-users-to-ignore-antivirus-is-turned-off-errors/?ref=metacurity.com))

**Related:** [*Microsoft*](https://learn.microsoft.com/en-au/windows/release-health/status-windows-11-25h2?ref=metacurity.com#incorrect-notifications-that--microsoft-defender-antivirus-is-turned-off-)*,* [*Forbes*](https://www.forbes.com/sites/zakdoffman/2026/08/30/antivirus-is-turned-off-microsoft-confirms-windows-update-mistake/?ref=metacurity.com)*,* [*XDA*](https://www.xda-developers.com/windows-11-is-warning-people-that-defender-antivirus-has-been-turned-off-but-dont-worry-says-microsoft/?ref=metacurity.com)*,* [*Windows Latest*](https://www.windowslatest.com/2026/08/30/windows-11-is-warning-virus-protection-is-off-but-microsoft-confirms-its-false/?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/microsoft-defender-antivirus-turned-off/?ref=metacurity.com)*,* [*Firstpost*](https://www.firstpost.com/tech/antivirus-is-turned-off-microsoft-confirms-windows-update-is-triggering-false-alerts-14041929.html?ref=metacurity.com)*,* [*Neowin*](https://www.neowin.net/amp/windows-11s-preview-update-breaks-mouse-settings-as-defender-spams-users-with-false-alerts/?ref=metacurity.com)

### Decentralized lending protocol Moonwell is investigating an issue affecting the MAMO Core Market on Base after security firms CertiK and PeckShield flagged a multimillion-dollar exploit.

"As a precaution, borrow caps for all Core Markets on Base have been set to 1 wei, preventing new borrowing and limiting the potential for further impact," Moonwell posted on X. "The supply caps for MAMO and WELL have also been set to 1 wei. All other supply caps remain unchanged."

Blockchain security firm PeckShield estimated the exploit drained approximately $8.7 million, with the attacker aggregating the stolen funds in the DAI stablecoin at a single address. ([James Hunt / The Block](https://www.theblock.co/news/defi/2026-08-27-moonwell-investigates-base-lending-market-issue-412913?ref=metacurity.com))

**Related:** [*Moonwell*](https://forum.moonwell.fi/t/post-mortem-mamo-market-incident-on-base/2208?ref=metacurity.com)*,* [*CryptoRank*](https://cryptorank.io/news/feed/54386-defi-lending-protocol-moonwell-hit-by-9m-exploit?ref=metacurity.com)*,* [*Protos*](https://protos.com/moonwells-latest-9m-attack-marks-four-incidents-in-a-year/?ref=metacurity.com)

### Blockchain firm Cosmos Labs said attackers stole funds across six blockchain networks between Aug. 20 and Aug. 25 using a flaw in Cosmos EVM, the shared software that lets Cosmos chains run Ethereum-style applications, according to a technical post-mortem.

Attackers exchanged the stolen tokens for about $2.87 million in other assets on decentralized exchanges and $2.85 million on centralized exchanges, per the report, which also states the attacker's centralized exchange accounts "have been frozen pending investigation by the relevant authorities."

Cosmos Labs notably disclosed that a researcher had identified the flaw and submitted a report through the Cosmos bug bounty program on April 25, according to the post-mortem. Cosmos Labs said its testers could not reproduce the attack against the configuration used by live Cosmos chains, including all known production Cosmos EVM networks, and therefore concluded that funds on those networks were not at risk.

"Based on that assessment, Cosmos Labs addressed the vulnerability through its silent, public patch process rather than the private patch distribution process used when a vulnerability is believed to threaten live user funds," the report states. ([Zack Abrams / The Block](https://www.theblock.co/news/defi/2026-08-29-cosmos-labs-says-it-wrongly-cleared-the-bug-behind-a-5-7-million-six-chain-hack-413061?ref=metacurity.com))

**Related:** [*GitHub*](https://github.com/cosmos/security/blob/main/communications/cosmos%5Fevm%5FGHSA-7g4w-cg88-2cq2%5Fpost%5Fmortem.md?ref=metacurity.com)*,* [*CryptoSlate*](https://cryptoslate.com/cosmos-misjudged-a-critical-bug-for-4-months-before-hackers-stole-nearly-6-million-across-6-chains/?ref=metacurity.com)*,* [*The Block*](https://www.theblock.co/news/defi/2026-08-29-cosmos-labs-says-it-wrongly-cleared-the-bug-behind-a-5-7-million-six-chain-hack-413061?ref=metacurity.com)

### Medical device manufacturer Globus Medical is facing heightened scrutiny on August 31, 2026, after a dark-web posting by the Falcon threat group claimed it extracted 2.96 terabytes of internal data related to the company, including customer records and regulatory documents, raising fresh questions for investors about cybersecurity and operational resilience.

The leak description goes further, stating that the stolen material spans US and international regulatory interactions, including FDA feedback, 510(k) submissions, and PMA approval letters, together with proposals from Australia’s Therapeutic Goods Administration and extensive product complaint logs and serious adverse event narratives. 

It also references internal corrective and preventive action investigation findings, merger diligence decks, integration plans, antitrust review documents, combined profit-and-loss statements, deal models, and budget spreadsheets, suggesting deep visibility into both historical performance and strategic planning if the claims prove accurate. ([Ad Hoc News](https://www.ad-hoc-news.de/boerse/news/nebenwerte/globus-medical-stock-faces-cybersecurity-spotlight-after-reported-data/70027257?ref=metacurity.com))

**Related:** [*Globus Medical*](https://investors.globusmedical.com/notifications?ref=metacurity.com)

### A massive cache of internal builds from Valve has reportedly leaked online, including beta builds of several classic Valve titles and possible weapons from Half-Life 2's canceled third episode.

The leak, which began circulating on Saturday and comes from an unknown source, includes 12 terabytes of data currently being sifted through by data miners. The files are dated from a ten-year period between 2003 and 2013, and include builds and assets of many Valve projects across that timespan.

Thus far, data from Counter-Strike: Global Offensive, Left 4 Dead, and Portal 2 have all been claimed to feature in the leak. This reportedly includes the complete Portal 2 beta from 2009, a much sought-after artifact for Portal 2 fans. ([Rick Lane / PCGamer](https://www.pcgamer.com/games/fps/a-massive-cache-of-valve-data-has-reportedly-leaked-online-appearing-to-include-portal-2s-elusive-beta-build-and-a-potential-weapon-from-half-life-2-episode-3/?ref=metacurity.com))

**Related:** [*VideoCardz*](https://videocardz.com/newz/12tb-steam-leak-exposes-old-game-builds-from-2003-to-2013?ref=metacurity.com)*,* [*Notebookcheck*](https://www.notebookcheck.net/Massive-12TB-Valve-leak-just-exposed-a-decade-of-gaming-history-and-scrapped-projects.1382951.0.html?ref=metacurity.com)*,* [*The Verge*](https://www.theverge.com/games/986552/12tb-steam-leak-half-life-2-episode-3?ref=metacurity.com)*,* [*GamesRadar+*](https://www.gamesradar.com/games/fps/massive-valve-leak-unearths-12tb-of-unreleased-builds-for-games-like-portal-2-alongside-a-whiff-of-half-life-2-episode-3/?ref=metacurity.com)*,* [*TechSK*](https://tech.sportskeeda.com/gaming-news/news-massive-12tb-steam-leak-exposes-decade-unreleased-game-builds-prototypes?ref=metacurity.com)*,* [*XDA*](https://tech.sportskeeda.com/gaming-news/news-massive-12tb-steam-leak-exposes-decade-unreleased-game-builds-prototypes?ref=metacurity.com)*,* [*Insider Gaming*](https://insider-gaming.com/reported-12tb-valve-steam-leak/?ref=metacurity.com)*,* [*NewsCord*](https://newscord.org/article/12tb-steam2-teraleak-exposes-valve-and-third-party-game-files-from-2003-to-2013--Story%5F20260830%5FA12TBSteamteraleakspe1295dcc?ref=metacurity.com)*,* [*Databreaches.net*](https://databreaches.net/2026/08/30/a-massive-cache-of-valve-data-has-reportedly-leaked-online-appearing-to-include-portal-2s-elusive-beta-build-and-a-potential-weapon-from-half-life-2-episode-3/?ref=metacurity.com)*,* [*r/valve*](https://www.reddit.com/r/valve/comments/1w1vbxb/valve%5Fhas%5Fsuffered%5Fa%5Finternal%5Fleak%5Fof%5F12/?ref=metacurity.com)

### GS Retail Co., a retail giant that operates GS25 convenience stores, has been issued a 12.8 billion-won (US$9.3 million) fine over a personal data leak that affected 1.66 million customers, according to the Korean watchdog the Personal Information Protection Commission (PIPC).

According to the PIPC, an unidentified hacker infiltrated the company's home shopping platform GS SHOP and its convenience store chain between 2024 and 2025 by repeatedly injecting a large number of pre-secured user IDs and passwords to successfully bypass login systems.

Through the member information modification pages, the hacker compromised the personal data of 1.58 million GS SHOP users and 79,128 GS25 customers. The leaked information included their names, gender, dates of birth, contact numbers, home addresses, and email addresses.

The privacy watchdog said GS Retail failed to notice abnormal signs, such as a sharp spike in login attempts and failures from identical IP addresses within a short time frame, which allowed the unauthorized access to persist undetected over a prolonged period. The company also lacked a dedicated office for privacy protection at the time of the incident.

The PIPC said it has ordered GS Retail to formulate concrete preventive measures, such as advanced security policies capable of identifying abnormal connections, and to appoint dedicated personnel for privacy protection. ([KIM, SEONGHUN / Yonhap News Agency](https://en.yna.co.kr/view/AEN20260831003900315?ref=metacurity.com))

**Related:** [*Korea JoongAng Daily*](https://www.koreajoongangdaily.com/business/gs-retail-fined-128-billion-won-over-data-breach-affecting-166-million-users/12852921?ref=metacurity.com)*,* [*Maeil Business*](https://www.mk.co.kr/en/it/12140670?ref=metacurity.com)*,* [*Chosun Business*](https://biz.chosun.com/en/en-it/2026/08/31/STSUFXESRNF3HMFLBC2NOB5R7M/?ref=metacurity.com)*,* [*The Herald Business*](https://mbiz.heraldcorp.com/article/10856958?ref=metacurity.com)*,* [*Asian Business Daily*](https://www.asiae.co.kr/en/article/distribution/2026083110553002325?ref=metacurity.com)

### The hacker group Server Killers writes on Telegram that they have declared cyber war against Norway.

"Reason for the attack: On August 23, Norway and Ukraine signed a new agreement on defense and security cooperation with a focus on the drone agreement, in which Norway continues to strengthen Ukraine's defense capabilities through the Nansen program."

They are probably referring to a budget leak that Prime Minister Jonas Gahr Støre (Ap) gave to NTB on Sunday. In it, he said that the government will give 85 billion kroner to Ukraine over next year's state budget.

The budget has not been adopted.

Since Monday night, the Norwegian Directorate of Digital Affairs has been subjected to a major denial-of-service attack. ([Oddvar Sagbakken Saanum and Kjell Person / TV2](https://www.tv2.no/nyheter/russisk-hacker-gruppe-erklaerer-cyberkrig-mot-norge/19162007/?utm%5Fsource=sdrn%3Avg%3Aarticle%3Aq67jew))

**Related:** [*UA.news*](https://ua.news/en/ukraine/prorosiiski-khakeri-atakuvali-uriadovi-sistemi-norvegiyi?ref=metacurity.com)*,* [*UNN*](https://unn.ua/en/news/pro-russian-hackers-attacked-norways-government-services?ref=metacurity.com)*,* [*NewsinEnglish.no*](https://www.newsinenglish.no/2026/08/26/russian-hackers-declare-cyber-war-on-norway-over-its-support-for-ukraine/?ref=metacurity.com)*,* [*PRM.ua*](https://prm.ua/en/because-of-ukraine-s-support-pro-russian-hackers-server-killers-announced-attacks-on-norway/?ref=metacurity.com)*,* [*The Barents Observer*](https://www.thebarentsobserver.com/news/prorussian-hackers-declare-cyberwar-on-norway/456591?ref=metacurity.com)*,* [*Ukrinform*](https://www.ukrinform.net/rubric-crime/4159120-prorussian-hackers-launch-series-of-largescale-cyberattacks-on-norways-government-sector-ccd.html?ref=metacurity.com)

### Health systems are warning patients about phishing scams using the MyChart name and logo to trick people into clicking malicious links, handing over personal information, or even installing malware on their computers.

A WMAR-2 News viewer alerted Matter for Mallory to the scam after receiving a suspicious email that appeared to be connected to a healthcare system he doesn't use.

That mismatch caught his attention. But for someone who does use the healthcare system named in a fraudulent email, the scam could be much harder to spot.

Epic, the company behind MyChart, says it has seen an increase in scammers using the familiar MyChart brand in fraudulent emails, text messages, phone calls and websites.

The company stresses the increase is not the result of a security problem with MyChart itself. Instead, scammers are taking advantage of a name millions of patients recognize and trust. ([Mallory Sofastaii / WMAR](https://www.wmar2news.com/matterformallory/fake-mychart-emails-can-show-alarming-test-results-trick-patients-into-installing-malware?ref=metacurity.com))

**Related:** [*MyChart*](https://www.mychart.org/l/en-us/help/staying-safe-from-scams-and-fraud/?ref=metacurity.com)*,* [*GBMC Healthcare*](https://www.gbmc.org/greater-living/beware-fake-mychart-emails-and-texts?ref=metacurity.com)

### The UK National Security Centre (NCSC) appears to be taking advantage the recent shutdown of a power plant in the UK and water treatment facilities in the US to reinforce its message about the vulnerability of operational technology (OT).

In an advisory published on Thursday, the agency notes that it has observed "increased targeting of operational technology (OT) systems across multiple sectors globally, including in the UK", resulting in "some limited real-world disruption".

It warns that any organization running OT systems should review them to check for vulnerabilities, adding that organizations should not assume they are isolated from the internet. Exposure can result through misconfigurations, unmanaged assets, or previous connections that were not revoked, it notes.

While the advisory focuses on industrial environments, it warns that other sectors are also at risk, and that the advice to check core systems for vulnerabilities applies more widely. There is a "broader pattern of disruptive cyber activity targeting internet-exposed systems and edge devices affecting all sectors," the NCSC states. ([John Leonard / Computing](https://www.computing.co.uk/news/2026/security/ncsc-disruptive-cyber-activity-means-all-organisations-should-check-for-ot-vulnerabilities?ref=metacurity.com))

**Related:** [*NCSC*](https://www.ncsc.gov.uk/news/disruptive-cyber-activity-highlights-risk-from-internet-exposed-systems-and-edge-devices?ref=metacurity.com)

### An experiment NPR conducted with NewsGuard, a company that monitors online falsehoods and issues ratings about the reliability of online news sources, found that popular AI chatbots mostly pushed back against false narratives spread by foreign states. 

AI summaries that are increasingly found at the top of search engine results didn't perform as well. But overall, they still pushed back against state-spread falsehoods a majority of the time.

NPR also looked at how often AI-generated answers may have uncritically exposed users to false information compared to traditional search results.

The experiment found that AI chatbots outperformed search engines, while AI summaries underperformed. The results suggest that compared with traditional web search links, using AI chatbots with web search access is a "good way for users to start to investigate these issues," said Mike Caulfield, a digital literacy expert at the University of Washington, Bothell, who has tested AI tools for search extensively. NPR's experiment revealed that AI summaries at the top of search engine results may warrant more caution, depending on the product. ([Huo Jingnan / NPR](https://www.npr.org/2026/08/30/nx-s1-5876436/chatbots-search-propaganda?ref=metacurity.com))

***Related:*** [*r/politics*](https://www.reddit.com/r/politics/comments/1w2md3s/we%5Ftested%5Fhow%5Fai%5Fchatbots%5Fwould%5Fhandle%5Fforeign/?ref=metacurity.com)

### Best Thing of the Day: Even an Abhorrent Governor Can Make a Good Decision Sometimes

Gov. Greg Abbott [has ordered](https://www.texastribune.org/2026/08/28/texas-greg-abbott-flock-cameras-order-state-money/?ref=metacurity.com) all state agencies to pause funding for Flock cameras as scrutiny over the AI-powered surveillance devices has mounted.

### Worst Thing of the Day: The Flock Panopticon Is Real

Data from Flock cameras installed in Alpharetta, Georgia, [is accessible](https://www.wired.com/story/how-an-atlanta-suburb-ended-up-sharing-flock-data-with-more-than-2000-organizations/?ref=metacurity.com) to more than 2,000 police departments, colleges, airports, and government agencies across the United States.

### Bonus Worst Thing of the Day: Hegseth Has a Disinformation Fog Machine

The Pentagon has [secretly installed](https://www.washingtonpost.com/national-security/2026/08/30/pentagon-secretly-installs-military-influencers-civilian-roles/?ref=metacurity.com) several conservative military veterans with large online followings in government roles, declining to disclose their assignments as they amplify Defense Secretary Pete Hegseth’s viewpoints and attack those who scrutinize the Trump administration,

### Closing Thought

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/image-101.png)