
<a target="_blank" href="Anthropic’s latest threat intelligence report describes a case where criminals allegedly used AI agents to automate a large part of a cyberattack, from finding exposed credentials to accessing company systems and extracting data.One part of the report that really stood out to me is the scale.The attackers reportedly:Scanned 1.8 million Android apps looking for exposed credentials and keys.Used AI to help automate reconnaissance, scripting, and data discovery.Targeted software suppliers to reach the data of their customers.Stole AI/API keys and then used victims’ own accounts and computing resources for further activity.In one case, reportedly collected more than 2,100 login tokens across 40+ company accounts in around 34 hours.Anthropic calls this emerging approach “vibe hacking,” essentially using AI agents to carry out cyber operations based on high-level instructions rather than manually performing every step.The biggest lesson isn't necessarily “AI is dangerous.” It's that security controls designed around human-speed attackers may not be enough when parts of an attack can be automated.The video goes deeper into the incident, including how the attackers got the initial access, what happened after they obtained credentials, and the five practical controls organisations can put in place to reduce this kind of risk.If you're interested in AI governance, cybersecurity, or the security implications of AI agents, the latest video on our YouTube channel covers the full incident. @ Latha-ai-governanceQuestion for security/AI governance professionals:Does your organisation actually know where every active API/AI key is right now, or is there still some uncertainty around old projects, applications, repositories, and third-party systems? " title="Three hours. One stolen password. An entire cloud environment compromised.">full image</a>
<strong> - Repost: Three hours. One stolen password. An entire cloud environment compromised.</strong> (<i>from Reddit.com, Three hours. One stolen password. An entire cloud environment compromised.</i>)
<br><blockquote> Anthropic’s latest threat intelligence report describes a case where criminals allegedly used AI agents to automate a large part of a cyberattack, from finding exposed credentials to accessing company systems and extracting data.One part of the report that really stood out to me is the scale.The attackers reportedly:Scanned 1.8 million Android apps looking for exposed credentials and keys.Used AI to help automate reconnaissance, scripting, and data discovery.Targeted software suppliers to reach the data of their customers.Stole AI/API keys and then used victims’ own accounts and computing resources for further activity.In one case, reportedly collected more than 2,100 login tokens across 40+ company accounts in around 34 hours.Anthropic calls this emerging approach “vibe hacking,” essentially using AI agents to carry out cyber operations based on high-level instructions rather than manually performing every step.The biggest lesson isn't necessarily “AI is dangerous.” It's that security controls designed around human-speed attackers may not be enough when parts of an attack can be automated.The video goes deeper into the incident, including how the attackers got the initial access, what happened after they obtained credentials, and the five practical controls organisations can put in place to reduce this kind of risk.If you're interested in AI governance, cybersecurity, or the security implications of AI agents, the latest video on our YouTube channel covers the full incident. @ Latha-ai-governanceQuestion for security/AI governance professionals:Does your organisation actually know where every active API/AI key is right now, or is there still some uncertainty around old projects, applications, repositories, and third-party systems? </blockquote>
<hr><h3>
<hr><strong>Mining:</strong> <br>
<a title="Cryptotab browser" target="_blank" href="https://cryptotabbrowser.com/12/4000343"><u>Bitcoin</u>, Cryptotab browser</a>
- <a title="Pi Network, CLOUD PHONEMINING" target="_blank" href="https://minepi.com/cusidore"><u>Pi Network</u> cloud PHONE MINING</a>
<br><a title="Fone, CLOUD PHONE MINING" target="_blank" href="https://play.google.com/store/apps/details?id=com.cloud.earning"><u>Fone</u>, cloud PHONE MINING</a> cod. dhvd1dkx
- <a title="Mintme, PC PHONE MINING" target="_blank" href="https://www.coinimp.com/invite/86d61388-18f9-4f8b-8561-8962c67e7166">Mintme, PC PHONE MINING</a>
<hr><strong>Exchanges:</strong> <br>
<a title="Coinbase.com" target="_blank" href="http://coinbase.com/join/occhip_8?src=android-link">Coinbase.com</a>
- <a title="Stex.com" target="_blank" href="https://stex.com/?ref=27877494">Stex.com</a>
- <a title="Probit.com" target="_blank" href="https://www.probit.com/r/46858290">Probit.com</a>
<hr><strong>Donations:</strong> <br>
<a title="Done crypto" target="_blank" href="https://commerce.coinbase.com/checkout/140e9bb6-c4ef-4156-92cf-9c87a88fd259">Done crypto</a>
</h3><br><br>
Social Media Icons