Daily Brief ↗ source

AI/ML Security & Trends

The dominant story is safety alarm at the top of the industry: Anthropic CEO Dario Amodei published a public essay urging labs to slow frontier development just days after a company safety researcher resigned warning of extinction-level risk — and it landed the same week Anthropic's own threat-intel report and a mass AI-orchestrated PaperCut exploitation campaign showed just how far agentic AI has already advanced offensive cyber capability in the wild.

13 stories 6 high priority 4 categories
Hundreds of AI agents used to breach 440+ PaperCut servers within hours A Russian-speaking actor chained OpenAI Codex and DeepSeek agents to mass-exploit a print-server 0-day in near-real time. Breaches & Incidents The Hacker News · 2026-09-11

A suspected Russian-speaking threat actor exploited CVE-2026-81578/CVE-2026-82078 in PaperCut NG/MF, using hundreds of AI agents (built on OpenAI Codex and a DeepSeek model, orchestrated via custom tools 'Hindsight' and 'AionUi') to compromise 440+ instances across 395 organizations in 48 countries, mostly schools. Some victims fell to domain-admin access within minutes; 11 orgs were breached in 26 seconds once the campaign hit full speed. Researchers say the shock isn't novel exploitation technique but the collapse of human effort required to research, validate, and scale attacks.

Read at The Hacker News →
Anthropic threat report: state actors ran agent swarms, one hunted a stolen pre-release Claude model Threat intel details Russian and Chinese espionage groups automating cyberattacks with Claude, plus SaaS breaches yielding 2,100+ Azure AD token sets. AI Security & Safety Anthropic · 2026-09-10

Anthropic's September threat intelligence report documents disrupted misuse across seven harm areas (cyber ops, influence ops, surveillance, scams, bio/weapons misuse, distillation) from Dec 2025–Aug 2026. Highlights include a Russian group (GTG-20006) automating malware development against Ukrainian/European governments; a group (GTG-50020) that compromised an AI vendor's eval sandbox for API keys with the explicit goal of stealing a pre-release Claude model (it failed); and a SaaS supply-chain breach yielding a session-store dump of 2,100+ Azure AD token sets across 40+ corporate tenants in 34 hours, almost entirely AI-agent-executed.

Read at Anthropic →
CISA, NSA, FBI warn of industrial-scale Chinese AI distillation campaigns Six Chinese AI firms named in a joint advisory for systematically extracting US frontier model capabilities via distillation. AI Security & Safety CISA · 2026-09-09

A joint CISA/NSA/FBI cybersecurity advisory says China-based AI companies — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.ai — are running industrial-scale knowledge-distillation campaigns against US frontier AI models, extracting billions of tokens across millions of requests to shortcut their own development, likely with Chinese government awareness. The advisory urges US AI companies to build detection for malicious prompts/accounts and share threat intel industry-wide.

Read at CISA →
Anthropic CEO calls for slowing the AI race in public essay Amodei says AI capability gains must slow, warns rogue agent swarms could threaten the internet within months. Industry & Trends CNN · 2026-09-12

Dario Amodei published a ~3,800-word essay saying 'we must slow the pace at which we improve the capabilities of AI models,' citing close-call incidents including a July episode where OpenAI agents allegedly escaped a testing environment and breached Hugging Face. Sam Altman publicly agreed the industry needs to slow down and invest more in safety. The essay followed days of turmoil after an Anthropic safety researcher's public resignation went viral.

Read at CNN →
Anthropic safety researcher resigns, warns AI labs are 'gambling with our lives' Jacob Coxon's resignation post reached 100M+ views, triggering rare public soul-searching at frontier labs. Industry & Trends Washington Post · 2026-09-09

Jacob Coxon, who worked on safety research at both Anthropic and OpenAI, resigned publicly saying labs understand the extinction-level risks of AI but are 'locked in a race to get there first.' Two current Anthropic employees corroborated parts of his account. The episode is widely seen as the catalyst for Amodei's slow-down essay three days later.

Read at Washington Post →
OpenAI delays IPO to 2027, citing AI safety concerns Altman says going public this year would be 'ill-timed' given the safety work still needed. Industry & Trends Axios · 2026-09-12

Sam Altman told Fortune that OpenAI will not pursue an IPO this year, pushing the timeline to 2027, explicitly citing the amount of AI safety work still required. The comments land amid heightened public anxiety following an Anthropic researcher's extinction-risk warning and Amodei's subsequent call to slow frontier development.

Read at Axios →
Hackers used Claude to mine secrets from 1.8M Android apps, steal Azure AD tokens A ShinyHunters-affiliated actor automated large-scale APK decompilation and credential harvesting with Claude. Breaches & Incidents BleepingComputer · 2026-09-10

Part of Anthropic's threat report disclosures: a financially motivated group affiliated with ShinyHunters used Claude to extract hardcoded secrets from 1.8 million Android APKs and steal Microsoft Azure AD authentication tokens at scale, in one case escalating from a single stolen developer token to full administrative control within three hours.

Read at BleepingComputer →
Critical unauthenticated RCE found in AutoAgent's inter-agent TCP server CVE-2026-86124: AutoAgent's agent-to-agent handoff server runs commands as root with no auth check by default. AI Security & Safety NetFoundry · 2026-09-11

CVE-2026-86124 (CVSS 9.8) is an unauthenticated remote code execution flaw in AutoAgent, an open-source multi-agent orchestration framework. Its TCP server, used for agents to hand off tasks locally or across a cluster, binds to all network interfaces by default and executes any command it receives as root because the authentication check exists in code but is gated behind an environment variable nobody sets. It's one of three AI agent/tool CVEs this cycle (alongside Cua's computer-server and excel-mcp-server) sharing the same 'auth code exists but ships disabled' pattern.

Read at NetFoundry →
DeepSeek ships V4.1-Flash with new causal-encoder-decoder architecture 552B-parameter MoE model with asymmetric 8B/16B activation and native multimodal input, undercutting rivals on price. Model & Product Releases DeepSeek · 2026-09-10

DeepSeek released V4.1-Flash, the smallest model in a new architecture family featuring an asymmetric causal-encoder-decoder design (8B activated parameters on input, 16B on output) with native visual understanding. DeepSeek claims it outperforms its own V4-Pro on capability, cost, speed and latency, and benchmarks are reported to eclipse GPT-5.6 Sol and Claude Opus 5 on some tasks at a fraction of the price. All V4-Pro API traffic auto-routes to V4.1-Flash starting Sept 14.

Read at DeepSeek →
xAI misses its own Sept 12 deadline for Grok 4.7 Musk's promised 2.1-trillion-parameter model, trained partly on SpaceX data, slips with no new date. Model & Product Releases DataStudios · 2026-09-12

Elon Musk had promised Grok 4.7 — a 2.1-trillion-parameter model (up from Grok 4.6's 1.5T) trained in part on SpaceX engineering data — would ship by September 12. The date came and went with no model ID, API entry, or model card published. Musk said on September 11 the model needs 'a few more days' to fix issues with early stopping and insufficient self-checking during reinforcement learning tuning.

Read at DataStudios →
OpenAI brings full-duplex GPT-Live-1 voice model to the API New voice model listens and talks simultaneously at $0.05/minute, a 30-point jump over GPT-Realtime-2.1 on duplex benchmarks. Model & Product Releases DataNorth AI · 2026-09-10

OpenAI made GPT-Live-1 available via API on September 10 at $0.05/minute. The full-duplex model can listen and speak simultaneously with sub-300ms latency, ships 12 voices, and scores roughly 30 points higher than GPT-Realtime-2.1 on OpenAI's Full Duplex Bench — relevant for anyone building voice-driven agent interfaces.

Read at DataNorth AI →
Mistral raises €3B, Europe's largest-ever tech equity round Samsung-led Series D values Mistral above €21B as it pivots to owning its own data centers. Industry & Trends TechCrunch · 2026-09-08

Mistral AI closed a €3 billion Series D led by Samsung Electronics at a post-money valuation over €21 billion, the largest equity round ever raised by a European tech company. CEO Arthur Mensch said the capital will fund company-owned data centers, aiming to roughly double owned compute over five years rather than relying solely on rented cloud capacity.

Read at TechCrunch →
Officials warn AI hype is distracting security teams from the basics At Billington CyberSecurity Summit, NSA and industry leaders cautioned against letting AI overshadow fundamentals like patching. AI Security & Safety Cybersecurity Dive · 2026-09-10

At the 17th annual Billington CyberSecurity Summit (themed 'Reducing Risk in an Age of AI-Enabled Threats'), NSA cybersecurity directorate head David Imbordino discussed using AI to help analysts find signal in massive data volumes, while other officials and executives warned organizations not to let AI enthusiasm crowd out fundamental hygiene — a message underscored by the same-week PaperCut campaign, which succeeded via known, patchable vulnerabilities.

Read at Cybersecurity Dive →