China
A suspected China-linked threat actor has integrated Anthropic’s Claude Code and DeepSeek-v4-pro into an active intrusion campaign targeting government entities, Taiwanese industry, and financial-services organizations. TencShell was first documented by Cato CTRL in May and assessed as linked to suspected China-based activity. A shared HTTP header fingerprint on port 111111111111 led researchers to 131313 Hong […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
