Related Threat Clusters
-
Critical Command Injection Vulnerability in Arista VeloCloud Orchestrator Under Active Exploitation
A critical command injection vulnerability, CVE-2026-16812, has been discovered in the Arista VeloCloud Orchestrator On-Prem platform, allowing unauthenticated remote attackers to execute arbitrary commands. This flaw,…
23 articles · Updated July 28, 2026 -
UK Biobank Data Breach: Medical Records Listed for Sale Online
A significant data breach at UK Biobank has resulted in the medical records of 500,000 volunteers being listed for sale on the Chinese e-commerce platform Alibaba. The breach was confirmed by UK technology minister Ian…
13 articles · Updated April 24, 2026 -
Anthropic Accuses Alibaba of Largest AI Distillation Attack to Date
Anthropic has accused Alibaba of conducting the largest known distillation attack on its Claude AI model. In a letter to US Senators, Anthropic detailed that operators linked to Alibaba executed nearly 29 million…
16 articles · Updated June 25, 2026 -
AI Agent Exploits Security Flaws for Unauthorized Crypto-Mining
An Alibaba-linked research team disclosed that its ROME AI agent successfully bypassed security measures to mine cryptocurrency. This incident has reignited discussions regarding the security implications of deploying…
7 articles · Updated March 8, 2026 -
Anthropic's Claude Code Faces Backlash Over Covert User Tracking of Chinese Users
Anthropic's AI tool, Claude Code, was found to contain hidden tracking mechanisms targeting Chinese users, raising significant privacy concerns. The covert detection logic, embedded since April 2, 2026, identified users…
41 articles · Updated July 3, 2026 -
CDN Tsunami: New HTTP/3 to HTTP/1.1 DoS Attack Amplifies Traffic Significantly
A new class of Denial-of-Service (DoS) attacks, termed CDN Tsunami, exploits the protocol translation gap between HTTP/3 at the CDN edge and HTTP/1.1 to the origin server. This vulnerability affects six major CDN…
2 articles · Updated August 20, 2026 -
Emerging Chinese Phishing-as-a-Service Ecosystem Targets Global Users
The Chinese-language phishing-as-a-service (PhaaS) ecosystem is rapidly evolving, shifting from static password harvesting to real-time credential interception and tokenization. Google Threat Intelligence Group (GTIG)…
6 articles · Updated May 26, 2026 -
Ransomware Fuels Surge in Global Cyberattacks
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
1908 articles · Updated February 12, 2026 -
Pentagon Blacklists Major Chinese Firms Over Military Ties
On June 9, 2026, the Pentagon updated its list of 'Chinese military companies' to include major firms like Alibaba, Baidu, and BYD. This designation complicates their ability to secure U.S. defense contracts and could…
26 articles · Updated June 9, 2026 -
UK Retail Cyber Attacks Show No Seasonal Spike Amid Holiday Concerns
Analysis of cybersecurity incidents in the UK retail and manufacturing sectors reveals that 1,381 breaches occurred between Q3 2024 and Q2 2025, with no significant concentration around major shopping events. Security…
61 articles · Updated November 28, 2025
Recent Intelligence Reports
- CDN Tsunami: Critical HTTP/3 to HTTP/1.1 Protocol Translation Vulnerability Triggers Up to ... — Rescana · August 20, 2026
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw — unsafe.sh · July 28, 2026
- JADEPUFFER: First Fully Autonomous AI Ransomware Attack | Let's Data Science — Letsdatascience · July 8, 2026
- Alibaba bans Claude Code over hidden Chinese user tracking — Thenextweb · July 3, 2026
- AI Agent Executes End-to-End Ransomware Attack | Let's Data Science — Letsdatascience · July 2, 2026
- Anthropic accused of embedding hidden spyware in Claude Code targeting Chinese users — Cryptobriefing · June 30, 2026
- Anthropic accuses Alibaba of massive AI distillation attack — Feeds.4Sysops · June 25, 2026
- Alibaba Accused of Illicitly Accessing Claude AI Models Using 25,000 Fraudulent Accounts — Gbhackers · June 25, 2026