Every week I go through DOJ press releases, vendor research, and breaking news to find the insider threat and fraud cases worth knowing about. Then I explain why they matter and what they mean for your program. No vendor pitch. Just the cases, the numbers, and the lessons.
|
Rabbit holes have actually lessened this week, turns out having the pipeline in place and a routine for collecting and sending these out helps. But this week has wrecked me in other ways. Multiple early mornings, and prepping for the webinar next week has eaten most of my spare time. Which reminds me, if you haven't joined one of my webinars before, come along to this one: Hermes AI Agent Detection Workshop Investigating a Real-World Incident: When Claude Won the CTF for RealThe most interesting item to come out of Anthropic's cybersecurity evals post, from an insider threat perspective, is Incident 2. In a capture-the-flag exercise, Claude spotted an opening: if it published its own Python package under the same name the fictional target company would pull automatically, it could win the challenge. It built and published a working malicious package, believing the registry was part of the simulation. It wasn't. The package was live and publicly downloadable for around an hour, during which it ran on 15 real systems, including a scanner belonging to an actual security company whose job is scanning packages for malware. When that scanner installed it, Claude's hidden code executed, exfiltrated the company's credentials, and used them to access further infrastructure. The persistence and skill involved here is what stands out. The model wrote a working Python package that got past a company whose actual job is scanning packages for malware. The concern for organisations is scale. An agentic AI used with malicious intent could plant supply chain risks like this en masse, seeding well known repositories that corporate agentic AI tools pull from every day. Those packages then get downloaded and executed inside the environment, exposing data and credentials without the user or the organisation knowing anything happened. Look at it through the lethal trifecta and the picture gets worse. Internal agentic AI already has access to sensitive data and can communicate externally. That is two of the three circles. The final circle is exposure to untrusted content, and this incident proves that untrusted content now sits inside repositories we treat as known and trusted. Source: Anthropic — https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals Insider Scoop: Apple Sues OpenAIApple is suing OpenAI and several of its former employees, alleging theft of trade secrets. When employees move to other companies, of course they're going to take the knowledge in their head with them. The key for Apple here is proving that individuals were actually exfiltrating data out of Apple to take to OpenAI. On top of that, the pattern of behaviour, multiple employees leaving for the same company around the same time, will strengthen their case. Will be interesting to see if we get to read the full fallout on this one, or if it gets settled out of court. Source: https://www.bbc.com/news/articles/cy8w379e091o Crime RoundupCanadian woman accused of spying at NATO HQ A Canadian woman has been identified by CBC as the person arrested on suspicion of espionage at NATO military headquarters. Worth remembering, she's been arrested on suspicion of espionage. She is not yet guilty of anything. Independent research has already been done and her name and face plastered everywhere, which will undoubtedly damage her reputation if she's found innocent. This is exactly why privacy is one of the core tenets of a proper insider threat program. Let's not be unprofessional here. Source: https://www.cbc.ca/news/canada/canadian-nato-intern-espionage-arrest-biwei-zhang-9.7290088 Zimmer Biomet sues former executive over trade secret theft Zimmer Biomet is suing a former executive over alleged trade secret theft. Personal opinion, but non-competes are rubbish. They unfairly favour the organisation over the individual, especially someone who's dedicated their career and become a niche specialist. That said, if this person transferred company data into personal accounts, that's off limits, and it should be easy to prove. We had the monitoring in place, right? AI Insider Threat WatchAre AI Agents The New Insider Risk? Did we cover this last week? Feels like I read something like this at least 6 times a month. Yes, agentic AI is an insider risk. No, it's probably not doing it on purpose. Yes, it's still more risky than the majority of your employees. Cyber insurtech BOXX adds AI deepfake cover to Cyberboxx Business Really interesting to see how quickly this is being implemented. Having insurance for AI deepfakes brings some peace of mind, and I hope insurers are enforcing it as part of the contract, pushing organisations to harden their procedures on high value transfers of data and money. TriviaIn cybersecurity, what does the term "capture the flag" (CTF) originally refer to when used to describe a security exercise? A) A competitive exercise where participants find hidden flags in vulnerable systems to test hacking skills Mitigation Corner: Your Most Trusted Vendor (Accenture) Just Became Your Biggest RiskI mean, why are we giving them source code and credentials. Shouldn't it be treated like a pentest. Corporate laptop supplied, only for the engagement timeline, all in segmented network space. Trusted Profession WatchThis is just heart breaking to read. You were meant to be one of the good ones. Just hurts us as a profession overall and hopefully serves as a warning. Corporate NewsWhat Employers Actually Track in 2026: Inside the Monitoring Stack I thought this was interesting. The results are what I expect. My main point when talking to anyone is assume nothing is private when using a corporate device, and always refuse to do corporate work on your own device. What's Coming UpHermes AI Agent Detection Workshop — my latest insider threat webinar. https://www.dtex.ai/events/ita-workshop-hermes-ai-agent-detection/ Trivia AnswerAnswer: A — CTF exercises originated in hacker conferences (DEF CON ran one of the first in 1996) as a way to test offensive and defensive security skills in a controlled environment, exactly the kind of exercise Claude was operating in during this week's headline story. Enjoyed this issue? Buy me a Coffee keeps the research running. |
Every week I go through DOJ press releases, vendor research, and breaking news to find the insider threat and fraud cases worth knowing about. Then I explain why they matter and what they mean for your program. No vendor pitch. Just the cases, the numbers, and the lessons.