Daily digest · 2026-08-31

Daily Digest, 2026-08-31

TL;DR: Attackers are now using ordinary password-stealing malware to take over AI assistant accounts, and Anthropic has started force-logging out Claude users whose live sessions were hijacked. On the criminal side, a ransomware crew ran a coding agent as part of hands-on break-ins at ten victims, and researchers turned a retailer's shopping chatbot into a way to run their own code on its backend. Regulators are catching up: ChatGPT and Reddit now fall under the EU's toughest online safety rules, and a judge called the Pentagon's supply-chain action against Anthropic illegal. The research pile all points one way: rules written into prompts are not controls, and enforcement has to sit outside the model at the tool boundary.

Top stories

Also notable