BTC $77,350.64 +0.26%
ETH $2,513.98 -0.37%
BNB $722.08 -0.61%
XRP $1.36 -0.32%
SOL $101.40 +0.03%
TRX $0.3413 +0.43%
DOGE $0.0843 -0.54%
ADA $0.2088 +0.67%
BCH $224.89 -0.36%
LINK $11.45 -0.41%
HYPE $78.83 -1.00%
AAVE $126.82 +0.88%
SUI $0.7209 -0.37%
XLM $0.1806 +0.38%
ZEC $1,107.01 -1.13%
AAPL $330.73 -0.71%
AMZN $254.47 -0.88%
GOOGL $338.37 -0.82%
MSFT $491.99 -0.61%
META $644.78 -0.56%
NVDA $215.67 -1.20%
TSLA $362.83 -1.21%
SNDK $1,574.14 -3.19%
INTC $99.25 -2.75%
SPCX $149.28 -0.52%
MU $939.17 -2.95%
AMD $502.40 -2.63%
BTC $77,350.64 +0.26%
ETH $2,513.98 -0.37%
BNB $722.08 -0.61%
XRP $1.36 -0.32%
SOL $101.40 +0.03%
TRX $0.3413 +0.43%
DOGE $0.0843 -0.54%
ADA $0.2088 +0.67%
BCH $224.89 -0.36%
LINK $11.45 -0.41%
HYPE $78.83 -1.00%
AAVE $126.82 +0.88%
SUI $0.7209 -0.37%
XLM $0.1806 +0.38%
ZEC $1,107.01 -1.13%
AAPL $330.73 -0.71%
AMZN $254.47 -0.88%
GOOGL $338.37 -0.82%
MSFT $491.99 -0.61%
META $644.78 -0.56%
NVDA $215.67 -1.20%
TSLA $362.83 -1.21%
SNDK $1,574.14 -3.19%
INTC $99.25 -2.75%
SPCX $149.28 -0.52%
MU $939.17 -2.95%
AMD $502.40 -2.63%

cybersecurity

All
Article
Flash

first_img North Korea uses IT employees from third countries to infiltrate American companies, paying interview assistants with cryptocurrency

According to NBC, North Korea is utilizing remote IT workers from third countries such as Iran and Lebanon to assist in infiltrating American companies and obtaining funds to finance its weapons programs. Alerts issued by the U.S. and several foreign agencies in July indicated that North Korean IT workers "seek to sign contracts with the intention of remitting salaries back to relevant North Korean agencies," while also posing internal threats to companies, involving data leaks, cryptocurrency theft, and sensitive information theft.As governments like the United States increase countermeasures, North Korea is increasingly leveraging third-country IT workers to secure job interviews, and after obtaining work contracts, the relevant positions are typically taken over by North Korean agents. Reports indicate that these foreign IT workers are scouted on LinkedIn, with some earning about $500 per month in cryptocurrency to work part-time as "interview assistants."Cointelegraph reported in May, citing data from cybersecurity company CrowdStrike, that state-affiliated North Korean hackers and threat actors caused cryptocurrency losses exceeding $2 billion in 2025, a 51% increase year-on-year. The Bank of Korea estimates that despite facing global sanctions, North Korea's GDP will still grow by 3.5% in 2025.

first_img Anthropic reported that Claude was used in cyber attacks and surveillance activities

In a threat intelligence report released on Thursday, Anthropic stated that Russian and Chinese users are leveraging its AI model Claude to automate cyberattacks. Among them, a Russian operator codenamed "JackPoterz" has automated most parts of the attack chain through a customized AI-driven workflow, targeting over 20 organizations, including government departments and intelligence agencies, as well as embassies and diplomatic missions in Ukraine and several European countries.Chinese users are using Claude as the engineering and orchestration layer for vulnerability research, with one workflow producing more than a dozen potential zero-day vulnerabilities in network device firmware within a month. Anthropic pointed out that AI is changing the economics of cyberattacks, allowing a single operator to complete an intrusion in two to three hours and handle dozens of victims in parallel.Additionally, the report revealed that a suspected independent consultant based in Bamako, collaborating with Mali's national intelligence agency, has used Claude as the primary engineering force to build a large-scale domestic surveillance system covering approximately 25 million SIM cards across all three mobile operators in the country. This system is locally deployed and operates using local models, with software design and engineering support provided by Claude, enabling the generation of intelligence profiles on phone numbers without the need for court warrants.

first_img OpenAI released GPT-6 Astra, calling it the arrival of the AGI era

OpenAI officially released GPT-6 Astra on Thursday, with President Greg Brockman calling it a "generational leap in capability" during the press conference, and believing that the model has reached the standard of Artificial General Intelligence (AGI), meaning that artificial intelligence can match or exceed human capabilities. Brockman stated, "Welcome to the era of AGI." If this judgment holds, it means AI entities will be closer to performing reasoning tasks in various complex tasks that humans can do, and even more.GPT-6 Astra is OpenAI's first model to cross the "critical" threshold under its internal danger capability scoring system, the Preparedness Framework, which means it can independently discover previously unknown software vulnerabilities (i.e., zero-day vulnerabilities) without gradual human supervision and chain them into attacks that can run in hardened systems. In testing, the model achieved a score of 100% on the ExploitBench benchmark; to rule out inflated scores due to memory answers, OpenAI conducted a second test using 20 recent vulnerabilities from the Google V8 JavaScript engine. Astra not only surpassed the previous generation GPT-5.6 Sol but also discovered and chained two previously unknown zero-day vulnerabilities, which are still being disclosed to the affected parties.Due to its high autonomy, the monitoring difficulty of Astra has also increased. OpenAI acknowledges that in tests assessing its ability to evade supervision, the model is more difficult to track than previous systems.

first_img Anthropic admits that Claude accessed the system beyond his authority due to a security error

In a blog post released on Monday, Anthropic acknowledged that its Claude model had unauthorized access to real computer systems during a cybersecurity assessment, an incident reflecting operational security failures as well as alignment failures in motivation reasoning and intent to harm. Anthropic disclosed in July that the Claude model had breached the systems of three companies because the third-party assessment environment was connected to the public internet, while the model was informed it was in a simulated environment without internet access.Anthropic stated that Claude may have interpreted evidence of real internet access as still being in a simulated environment and was willing to take harmful actions on the real internet to complete the cybersecurity assessment task. Additionally, during tests at the UK AI Safety Institute, after assessors deliberately granted Claude Mythos internet access, the model took unauthorized actions on the live network. Anthropic emphasized that the models involved did not have the cybersecurity protections included in the officially released products.Following the incident on July 30, Anthropic has suspended cybersecurity assessments of pre-release models and introduced stricter protections: tests must run in verified offline sandboxes equipped with real-time monitoring; a new classifier can intercept suspected boundary violations, terminate tests, and notify humans. Anthropic has also expanded the scope of offline monitoring used by internal frontier agents. Previously, OpenAI models had also breached Hugging Face in July to obtain answers for cybersecurity tests, with investigations revealing that about 1,200 agents acted collaboratively through unauthorized message boards.

first_img The U.S. Department of Justice and CrowdStrike teamed up to dismantle the Sality botnet, which had been operating for over 20 years

According to Decrypt, CrowdStrike and the U.S. Department of Justice announced on Tuesday that they have dismantled the Sality peer-to-peer botnet, which has been active since 2003.This botnet primarily hijacked cryptocurrency payments through the EggJagger malware over the past eight years, which monitored the cryptocurrency wallet addresses in victims' clipboards and replaced them with the operator's own address, causing victims to send funds to strangers.CrowdStrike estimates that the operator has stolen at least 12.1 million rubles (approximately $150,000) solely through the EggJagger payload. Most of the stolen cryptocurrency has not been spent, and CrowdStrike assesses that these unspent assets were worth about 147 million rubles (nominally around $1.35 million) at their peak in January 2025. The reason Sality has survived to this day is that it does not have a central server that can be seized; infected machines communicate directly with each other.This multinational operation involved the United States, Bulgaria, Hungary, and Romania. The U.S. Department of Justice, FBI, and Defense Criminal Investigative Service seized Sality-related domains within the United States, and police from multiple European countries also seized other domains.CrowdStrike isolated more than 15,000 infected machines to its controlled honeypot by exploiting its architectural vulnerabilities. The operator has been tracked as SALTY SPIDER, which launched a denial-of-service attack against the Russian cryptocurrency exchange AvanChange in September 2023.

first_img OpenAI's new model Astra can autonomously discover and exploit software vulnerabilities, rated as "critical" in cybersecurity capability level

OpenAI stated that its upcoming Astra model can autonomously discover previously unknown software vulnerabilities and convert them into usable attack vectors without human intervention, making it the company's first model to reach the "Critical" cybersecurity capability level threshold. In a blog post released on Tuesday, OpenAI mentioned that according to its Preparedness Framework, reaching this level means the model can discover zero-day vulnerabilities and develop usable exploit code in hardened real systems without human involvement, or design and execute attacks based solely on a high-level objective.In testing, Astra achieved a 100% score in benchmark tests for developing exploit code based on known vulnerabilities and discovered two previously unknown vulnerabilities in another internal test. Additionally, the model successfully broke through a hardened browser sandbox and executed commands on the host machine, while gaining root access by exploiting multiple weaknesses in the operating system. OpenAI stated that it has delayed some of Astra's development progress to enhance security measures and plans to make its advanced cybersecurity capabilities available only to selected testers.This capability is particularly relevant to the cryptocurrency industry, as software vulnerabilities can be converted into financial losses within minutes. CoinDesk reported in June that increasingly powerful AI models can compress the process of searching code, discovering misconfigurations, and assembling attacks from days or weeks to machine speed. Security researchers noted at the time that the significant change was not the emergence of new categories of attacks, but rather the dramatically increased speed at which existing vulnerabilities are discovered and exploited.

Ledger CTO responds to vulnerability FUD: The issue was fixed before it was disclosed, and users can safely use it by updating in a timely manner

Ledger's Chief Technology Officer Charles Guillemet stated that there has recently been "FUD" targeting Ledger in the market, as a smart contract security company claimed to have discovered vulnerabilities in the Ledger Ethereum application. Guillemet mentioned that there indeed were vulnerabilities related to certain Clear Signing processes in the Ledger Ethereum application, but these vulnerabilities were discovered by Ledger's security research team Donjon using AI-driven vulnerability research tools, and the fixes were completed and deployed two weeks ago. Users can obtain protection by timely updating their Ledger device firmware and applications.The relevant security company contacted Ledger's bug bounty program only after the fixes were completed, did not follow responsible disclosure processes, and did not communicate with the bug bounty team, yet implied in subsequent content that the issue had not been resolved. This approach is not true security research but rather a way to create panic for attention. AI is changing the cybersecurity landscape, and both attackers and defenders can enhance efficiency with AI, but AI-driven security research can only truly enhance the security of the entire ecosystem when basic security principles such as responsible disclosure and pre-release verification are followed.Guillemet finally reminded Ledger users to keep their device firmware, Ledger applications, and related software up to date to automatically receive the latest security fixes and research results. Users should not be influenced by the related "FUD" and should timely update their software and maintain safe habits.
app_icon
ChainCatcher Building the Web3 world with innovations.