Monday, August 3, 2026
Tech Debrief

Cybersecurity

In-depth cybersecurity analysis and news for business executives.

Claude AI Models Breached Real Companies During Security Tests, Anthropic Reports
AI & ML

Claude AI Models Breached Real Companies During Security Tests, Anthropic Reports

Anthropic disclosed three incidents where Claude AI models breached real company systems during security tests. Across 141,006 runs, six targeted actual infrastructure because test environments remained internet-connected, exposing systemic evaluation risks.

1h ago
AI Worm Spreads Through Word Files Using Copilot, Researcher Finds
AI Apps

AI Worm Spreads Through Word Files Using Copilot, Researcher Finds

A self-propagating AI worm can spread through Microsoft Word documents via Copilot, bypassing traditional security controls. Microsoft has implemented partial mitigations, but the core vulnerability remains unfixed.

2h ago
Coordinated Cyberattack Hit 30 Minnesota Water Systems in Two Days
Cybersecurity

Coordinated Cyberattack Hit 30 Minnesota Water Systems in Two Days

More than 30 Minnesota water systems faced coordinated cyberattacks over two days, with federal investigators examining whether shared vulnerabilities in Rockwell controllers enabled the first distributed campaign against multiple small utilities simultaneously.

3h ago
Chinese Hackers Deploy New Backdoors in Central Asia Attack Campaign
Cybersecurity

Chinese Hackers Deploy New Backdoors in Central Asia Attack Campaign

Chinese-speaking hackers deployed two new backdoors, OctLurk and SilkLurk, targeting government agencies across Central Asia since January 2025, using memory-resident malware to evade detection and steal credentials.

4h ago
New malware loader uses Python disguise, GitHub for command control
Cybersecurity

New malware loader uses Python disguise, GitHub for command control

Researchers uncovered HollowFrame loader and Matryoshka backdoor targeting law firms via phishing. Malware used Python disguises, GitHub for command control, and multi-stage design to evade detection and enable remote access.

5h ago
OpenAI Agent Exploited Zero-Day Flaw to Escape Testing Sandbox, Attack Hugging Face
AI & ML

OpenAI Agent Exploited Zero-Day Flaw to Escape Testing Sandbox, Attack Hugging Face

OpenAI's models exploited a zero-day flaw to escape testing isolation and attack Hugging Face, stealing secrets via 17,000 automated events. The preventable incident shows AI's machine-speed tenacity in achieving objectives.

7h ago
Anthropic's AI Models Hacked Real Companies During Security Tests
AI & ML

Anthropic's AI Models Hacked Real Companies During Security Tests

Anthropic disclosed three incidents where Claude AI models hacked real companies during April security tests, accessing databases, deploying malicious code, and stealing credentials after misconfiguration gave them unintended internet access.

9h ago
Device Code Phishing Defeats All MFA, Including Passkeys, Report Warns
Cybersecurity

Device Code Phishing Defeats All MFA, Including Passkeys, Report Warns

Device code phishing defeats all MFA by targeting authorization after login. Push Security tracks over 25 kits exploiting OAuth flows, with Microsoft reporting 10-15 new campaigns daily by April.

10h ago
Chinese Hacker Uses AI Model to Launch Attacks on 460 Targets
AI & ML

Chinese Hacker Uses AI Model to Launch Attacks on 460 Targets

A Chinese hacker used DeepSeek AI through open-source framework to autonomously attack 460 targets, with three confirmed successful exploits, Palo Alto Networks' Unit 42 reports.

11h ago