AI News selected for Professionals and Decision Makers
AI Security And Privacy Updates

ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories

17:27 · June 18, 2026 · Hacker News AI Section

ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories

The internet did not break this week. It got used exactly as designed, which is worse. Searches were siphoned through shady browser add-ons. AI chat links turned into malware delivery paths. macOS attacks ran in memory and left almost nothing behind. Cloud agents looked like helpers until attackers treated them like open shells. Add exposed edge gear, poisoned packages, cash courier scams,

Summary

Recent threat reports detail how attackers are exploiting trusted AI platforms, notably by hijacking Anthropic’s Claude shared-chat feature to distribute the MacSync credential stealer. Campaigns first directed victims through compromised Google Ads for developer tools, then shifted to claude.ai domains themselves, leveraging the site’s reputation to host malicious links. The operation concentrated on the Asia-Pacific region and was active across multiple waves before Anthropic disabled the accounts and conversations involved.

Parallel activity targeted macOS users with fileless infection chains delivered through ClickFix social-engineering lures. Victims were prompted to run clipboard commands that fetched and executed an AppleScript stager entirely in memory, harvesting browser data, keychain items, and cryptocurrency wallets while establishing persistent command-and-control. A separate Russian-speaking actor employed similar techniques against technology and media firms in Asia, North America, and Oceania.

Additional findings highlight risks in AI-assisted developer tooling. Researchers identified local code-execution flaws in the Cline VS Code extension that allowed a malicious repository to bypass approval dialogs and safe-command filters, granting attackers access to credentials and source code on the developer’s machine. Defensive efforts include AWS’s new model-agnostic security agent for continuous vulnerability discovery and remediation across cloud workloads.

The bulletin also notes clusters of deceptive browser extensions that silently reroute search traffic, ongoing phishing operations impersonating travel providers via WhatsApp, and a critical privilege-escalation flaw in Cisco Catalyst SD-WAN components that has been exploited since 2023. Together these incidents illustrate how everyday internet infrastructure and emerging AI services are being repurposed for credential theft and initial access.

Why it matters

The article provides critical threat intelligence regarding the weaponization of AI tools like Claude for malware delivery. This is highly actionable for Dutch security professionals needing to protect enterprise environments from emerging AI-enabled attack vectors.

More in this beat
anthropicclaudeMacSyncNastyC2phishingsecurity-operationsthreat-and-vulnerability-updates
How Outtake built a cyber investigator on Claude

02:00 · July 22, 2026

How Outtake built a cyber investigator on Claude

This article provides a practical use case for Product Teams and Builders on how to leverage Claude Code and the Agent SDK to build long-running, autonomous AI agents. It offers valuable architectural insights for Dutch AI practitioners developing cybersecurity solutions or complex agentic workflows.

Relevance 75 · Audience 85

ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories

17:24 · July 2, 2026

ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories

The inclusion of AI compute hijacking and vulnerabilities in AI systems makes this highly relevant for security professionals safeguarding AI infrastructure. Dutch enterprises and SMEs deploying AI must be aware of these emerging threat vectors to ensure robust, compliant, and secure AI operations.

Relevance 75 · Audience 85

More details on Fable 5’s cyber safeguards and our jailbreak framework

02:00 · July 2, 2026

More details on Fable 5’s cyber safeguards and our jailbreak framework

Provides actionable, specific guidance on model-level cyber safeguards and a structured jailbreak evaluation rubric directly usable by product teams building or auditing AI systems, with clear discussion of dual-use risks and deployment trade-offs.

Relevance 85 · Audience 80

Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs

17:30 · June 29, 2026

Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs

This article is highly relevant for security professionals as it demonstrates the practical application of AI models in discovering critical software vulnerabilities. It underscores the evolving landscape of AI-driven threat research and the immediate need for enterprises to patch affected Apple devices.

Relevance 85 · Audience 95

ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories

15:20 · June 11, 2026

ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories

The article highlights emerging security vulnerabilities specific to AI, such as the phishing of AI agents and patches for AI coding assistants like Claude. Dutch security professionals must understand these attack vectors to secure enterprise AI deployments and maintain compliance with strict EU data protection regulations.

Relevance 75 · Audience 85

AI Broke Vulnerability Management. That's Why CISOs Are Moving Budget to BAS.

13:30 · June 11, 2026

AI Broke Vulnerability Management. That's Why CISOs Are Moving Budget to BAS.

This article is highly relevant for security professionals as it highlights a critical shift in the threat landscape driven by AI, specifically the rapid weaponization of vulnerabilities. It provides actionable insights for Dutch CISOs and security teams to adapt their defensive strategies and tooling, such as adopting BAS, to maintain robust security postures against AI-accelerated threats.

Relevance 85 · Audience 95

AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload

15:19 · June 8, 2026

AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload

This article is highly relevant for security professionals as it highlights a critical, AI-driven threat vector that directly impacts SOC efficiency and enterprise security. Dutch organizations must adapt their defensive strategies to handle the increased volume and sophistication of AI-generated phishing attacks.

Relevance 85 · Audience 95

The Claude Code Guide For Startups

02:00 · August 20, 2026

The Claude Code Guide For Startups

This article is highly relevant for product teams and builders as it offers actionable strategies and technical tips for integrating agentic coding into the SDLC. Dutch AI practitioners can apply these insights to scale development efficiently while maintaining governance and compliance through robust evaluation frameworks.

Relevance 85 · Audience 95

How monday.com transformed its platform into an agent-first product where humans and agents collaborate

02:00 · August 20, 2026

How monday.com transformed its platform into an agent-first product where humans and agents collaborate

This case study is highly relevant for product teams and builders as it provides a strategic blueprint for transitioning from superficial AI features to a native, agent-first architecture. It offers actionable insights into integrating LLMs like Claude into core workflows, which is highly applicable for Dutch SaaS companies and AI practitioners looking to drive sustained user engagement.

Relevance 75 · Audience 90

Phishing 3.0: The Fight Moves to Agent Versus Agent

13:30 · August 19, 2026

Phishing 3.0: The Fight Moves to Agent Versus Agent

This article is highly relevant for security professionals as it highlights the emerging threat of AI-driven phishing agents. Dutch enterprises must adapt their cybersecurity strategies to counter AI-generated attacks, making this crucial for maintaining robust organizational security.

Relevance 85 · Audience 95