Show notes
Today's briefing explores a significant escalation in the AI cold war as Anthropic accuses Alibaba of launching a massive distillation campaign to clone the capabilities of its Claude model. The attack allegedly involved over 28 million exchanges across 25,000 fraudulent accounts. We also break down the discovery of STOCKSTAY, a new .NET-based backdoor attributed to the Russian threat actor Turla, which is being deployed against government and military targets in Ukraine. Finally, we cover urgent warnings from CISA regarding active exploitation of critical flaws in Lantronix EDS5000 and Ubiquiti UniFi OS devices, alongside the 'Miasma' npm supply chain worm that is currently harvesting developer credentials. Our focus remains on the shift toward highly automated, agentic threats that are shortening the window between vulnerability disclosure and weaponized exploitation.



