Anthropic says Chinese AI company used 16 million Claude queries to copy model

Ravi LakshmananFebruary 24, 2026Artificial Intelligence / Humanity Anthropic announced on Monday that it had identified an “industrial-scale campaign” in which three artificial intelligence (AI) companies, Deep Seek, Moonshot AI, and MiniMax, illegally extracted Claude’s abilities to improve their models. This distillation attack resulted in more than 16 million interactions with its large-scale language model (LLM) […]

APT28 uses webhook-based macro malware to target European companies

Ravi LakshmananFebruary 23, 2026Malware/Threat Intelligence A Russian-affiliated state-sponsored threat actor tracked as APT28 is believed to be involved in a new campaign targeting specific organizations in Western and Central Europe. According to S2 Grupo’s LAB52 threat intelligence team, this activity was active from September 2025 to January 2026. The code name is “Operation MacroMaze”. “This […]

Wormable XMRig campaign uses BYOVD exploit and time-based logic bombs

Cybersecurity researchers have revealed details of a new cryptojacking campaign that uses pirated software bundles as bait to deploy a custom-built XMRig miner program on compromised hosts. “Analysis of recovered droppers, persistence triggers, and mining payloads reveals sophisticated multi-stage infections that prioritize maximizing cryptocurrency mining hashrate, often destabilizing victims’ systems,” Trellix researcher Aswath A said […]

Double-Tap Skimmers, PromptSpy AI, 30Tbps DDoS, Docker Malware & More

Ravie LakshmananFeb 23, 2026Cybersecurity / Hacking Security news rarely moves in a straight line. This week, it feels more like a series of sharp turns, some happening quietly in the background, others playing out in public view. The details are different, but the pressure points are familiar. Across devices, cloud services, research labs, and even […]

How exposing endpoints increases risk across your LLM infrastructure

hacker newsFebruary 23, 2026Artificial Intelligence/Zero Trust As more organizations run their own large-scale language models (LLMs), they are also introducing more internal services and application programming interfaces (APIs) to support those models. Modern security risks are increasingly introduced not from the models themselves, but from the infrastructure that serves, connects, and automates them. Each new […]

Malicious npm package collects cryptographic keys, CI secrets, and API tokens

Cybersecurity researchers have uncovered what they claim is an active “Shai-Hulud-like” supply chain worm campaign that leverages a cluster of at least 19 malicious npm packages to enable credential harvesting and cryptocurrency key theft. The campaign has been codenamed SANDWORM_MODE by supply chain security company Socket. Similar to previous waves of Shai-Hulud attacks, the malicious […]

MuddyWater uses GhostFetch, CHAR, HTTP_VIP to target MENA organizations

Ravi LakshmananFebruary 23, 2026Threat Intelligence/Artificial Intelligence The Iranian hacker group known as MuddyWater (also known as Earth Vetala, Mango Sandstorm, and MUDDYCOAST) targeted multiple organizations and individuals primarily based in the Middle East and North Africa (MENA) region as part of a new campaign codenamed Operation Olalampo. According to a report published by Group-IB, this […]

OpenClaw Security Crisis: Detecting AI Agent Risks

You’ve probably heard of OpenClaw. This open source AI agent quickly became one of the fastest growing repositories in GitHub’s history, gaining over 135,000 stars within a few weeks. However, this led to the first major AI agent security crisis of 2026. Reco helps you identify whether an AI agent is present in your environment. […]

AI-assisted attackers compromise over 600 FortiGate devices in 55 countries

Russian-speaking, financially motivated attackers have been observed leveraging commercial generative artificial intelligence (AI) services to compromise more than 600 FortiGate devices in 55 countries. This is according to new findings from Amazon Threat Intelligence, which observed activity from January 11, 2026 to February 18, 2026. CJ Moses, chief information security officer (CISO) at Amazon Integrated […]

Anthropic launches Claude Code Security, an AI-powered vulnerability scan

Rabi LakshmananFebruary 21, 2026Artificial Intelligence / DevSecOps Artificial intelligence (AI) company Anthropic has begun rolling out new security features in Claude Code that can scan users’ software codebases to find vulnerabilities and suggest patches. This feature, called Claude Code Security, is currently available in limited research preview for Enterprise and Team customers. “By scanning codebases […]