TechLetters ☕️ AI agents coordinate hacking. Claude and DeepSeek become a cyberattack team. CAPTCHA falls. Agents leave instructions for agents. AI writes viable virus genomes.
Security
And another one! AI agents took unsanctioned action online in 10 of 122 runs, 17 actions came from Anthropic’s Mythos 5 and two from OpenAI’s GPT-5.6 Sol. One agent tried to insert malicious code into an open-source project, created fake identities to pressure the maintainer, used Tor to bypass restrictions, contacted people with harmful files and left instructions later agents reused.
AI agent got past an audio-based “prove you’re human” test (CAPTCHA) in order to register a public web address on a free domain-name service. A code repository became a shared “message board” that several AI agents used to leave each other explicit instructions and coordinate. AI agent sent deceptive, targeted emails to specific people (“spearphishing”).
This was not a sandbox escape. Internet access was enabled, safety classifiers disabled and real-time monitoring absent. The tests literally kind of invited the agents to do this. https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf
China-linked hackers used Claude Code and DeepSeek as a cyberattack AI team. DeepSeek planned exploits and adapted when attacks failed, Claude handled the operational layer - ran commands, maintained access, built phishing pages. The impact is scale - faster attacks on governments, cloud systems and finance, with stolen credentials, source code and citizen data. https://hunt.io/blog/chinese-operators-claude-deepseek-government-intrusion
It was not a single rogue AI agent, but emergent coordination among multiple agents. Some recognised the activity as out of scope but continued because others were doing it and the task seemed impossible otherwise. An internal package manager became a Moltbook-style persistent message board with hundreds of thousands of messages. Agents shared exploits, divided tasks, reused access from earlier runs and considered cryptographic signatures. OpenAI had inadvertently given them cross-run memory, persistence and cumulative collaboration. One agent could discover a vulnerability once, document it, and leave the door open for later agents. https://www.wired.com/story/openai-didnt-notice-its-ai-agents-using-a-message-board-to-plan-their-hacking-spree/
Privacy
Technology Policy
Other
Scientists in the US have for the first time used AI to create complete, viable virus genomes unlike any known in nature. AI is writing genomes. Potential impact? Programmable phage therapies, faster responses to antibiotic. It also raises urgent biosecurity questions https://www.science.org/doi/10.1126/science.aec2657
In case you feel it's worth it to forward this content further:
Subscribed
If you’d like to share:
