Connect with us

Technology

Chinese hackers turned AI tools into an automated attack machine

Published

on

Chinese hackers turned AI tools into an automated attack machine

NEWYou can now listen to Fox News articles!

Cybersecurity has been reshaped by the rapid rise of advanced artificial intelligence tools, and recent incidents show just how quickly the threat landscape is shifting.

Over the past year, we’ve seen a surge in attacks powered by AI models that can write code, scan networks and automate complex tasks. This capability has helped defenders, but it has also enabled attackers to move faster than before.

The latest example is a major cyberespionage campaign conducted by a Chinese state-linked group that used Anthropic’s Claude to carry out large parts of an attack with very little human involvement.

HACKER EXPLOITS AI CHATBOT IN CYBERCRIME SPREE

Advertisement

Sign up for my FREE CyberGuy Report 
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter 

How Chinese hackers turned Claude into an automated attack machine

In mid-September 2025, Anthropic investigators spotted unusual behavior that eventually revealed a coordinated and well-resourced campaign. The threat actor, assessed with high confidence as a Chinese state-sponsored group, had used Claude Code to target roughly 30 organizations worldwide. The list included major tech firms, financial institutions, chemical manufacturers and government bodies. A small number of those attempts resulted in successful breaches.

Claude handled most of the operation autonomously, triggering thousands of requests and generating detailed documentation of the attack for future use. (Kurt “CyberGuy” Knutsson)

How the attackers bypassed Claude’s safeguards

This was not a typical intrusion. The attackers built a framework that let Claude act as an autonomous operator. Instead of asking the model to help, they tasked it with executing most of the attack. Claude inspected systems, mapped out internal infrastructure and flagged databases worth targeting. The speed was unlike anything a human team could replicate.

To get around Claude’s safety rules, the attackers broke their plan into tiny, innocent-looking steps. They also told the model it was part of a legitimate cybersecurity team performing defensive testing. Anthropic later noted that the attackers didn’t simply hand tasks to Claude; they engineered the operation to make the model believe it was performing authorized pentesting work, splitting the attack into harmless-looking pieces and using multiple jailbreak techniques to push past its safeguards. Once inside, Claude researched vulnerabilities, wrote custom exploits, harvested credentials and expanded access. It worked through these steps with little supervision and reported back only when it needed human approval for major decisions.

Advertisement

The model also handled the data extraction. It collected sensitive information, sorted it by value and identified high-privilege accounts. It even created backdoors for future use. In the final stage, Claude generated detailed documentation of what it had done. This included stolen credentials, systems analyzed and notes that could guide future operations.

Across the entire campaign, investigators estimate that Claude performed around 80-90% of the work. Human operators stepped in only a handful of times. At its peak, the AI triggered thousands of requests, often multiple per second, a pace still far beyond what any human team could achieve. Although it occasionally hallucinated credentials or misread public data as secret, those errors underscored that fully autonomous cyberattacks still face limitations, even when an AI model handles the majority of the work.

Why this AI-powered Claude attack is a turning point for cybersecurity

This campaign shows how much the barrier to high-end cyberattacks has dropped. A group with far fewer resources could now attempt something similar by leaning on an autonomous AI agent to do the heavy lifting. Tasks that once required years of expertise can now be automated by a model that understands context, writes code and uses external tools without direct oversight.

Earlier incidents documented AI misuse, but humans were still steering every step. This case is different. The attackers needed very little involvement once the system was in motion. And while the investigation focused on usage within Claude, researchers believe similar activity is happening across other advanced models, which might include Google Gemini, OpenAI’s ChatGPT or Musk’s Grok.

This raises a difficult question. If these systems can be misused so easily, why continue building them? According to researchers, the same capabilities that make AI dangerous are also what make it essential for defense. During this incident, Anthropic’s own team used Claude to analyze the flood of logs, signals and data its investigation uncovered. That level of support will matter even more as threats grow.

Advertisement

We reached out to Anthropic for comment but did not hear back before our deadline.

Hackers used Claude to map networks, scan systems and identify high-value databases in a fraction of the time human attackers would need. (Kurt “CyberGuy” Knutsson)

FORMER GOOGLE CEO WARNS AI SYSTEMS CAN BE HACKED TO BECOME EXTREMELY DANGEROUS WEAPONS

You may not be the direct target of a state-sponsored campaign, but many of the same techniques trickle down to everyday scams, credential theft and account takeovers. Here are seven detailed steps you can take to stay safer.

1) Use strong antivirus software and keep it updated

Strong antivirus software does more than scan for known malware. It looks for suspicious patterns, blocked connections and abnormal system behavior. This is important because AI-driven attacks can generate new code quickly, which means traditional signature-based detection is no longer enough.

Advertisement

The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.

Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com

2) Rely on a password manager

A good password manager helps you create long, random passwords for every service you use. This matters because AI can generate and test password variations at high speed. Using the same password across accounts can turn a single leak into a full compromise.

Next, see if your email has been exposed in past breaches. Our No. 1 password manager (see Cyberguy.com) pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials. 

Check out the best expert-reviewed password managers of 2025 at Cyberguy.com

Advertisement

3) Consider using a personal data removal service

A large part of modern cyberattacks begins with publicly available information. Attackers often gather email addresses, phone numbers, old passwords and personal details from data broker sites. AI tools make this even easier, since they can scrape and analyze huge datasets in seconds. A personal data removal service helps clear your information from these broker sites so you are harder to profile or target.

FAKE CHATGPT APPS ARE HIJACKING YOUR PHONE WITHOUT YOU KNOWING

While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com

Advertisement

4) Turn on two-factor authentication wherever possible

Strong passwords alone are not enough when attackers can steal credentials through malware, phishing pages or automated scripts. Two-factor authentication adds a serious roadblock. Use app-based codes or hardware keys instead of SMS. While no method is perfect, this extra layer often stops unauthorized logins even when attackers have your password.

5) Keep your devices and apps fully updated

Attackers rely heavily on known vulnerabilities that people forget or ignore. System updates patch these flaws and close off entry points that attackers use to break in. Enable automatic updates on your phone, laptop, router and the apps you use most. If an update looks optional, treat it as important anyway, because many companies downplay security fixes in their release notes.

6) Install apps only from trusted sources

Malicious apps are one of the easiest ways attackers get inside your device. Stick to official app stores and avoid APK sites, shady download portals and random links shared on messaging apps. Even on official stores, check reviews, download counts and the developer name before installing anything. Grant the minimum permissions required and avoid apps that ask for full access for no clear reason.

7) Ignore suspicious texts, emails and pop-ups

AI tools have made phishing more convincing. Attackers can generate clean messages, imitate writing styles and craft perfect fake websites that match the real ones. Slow down when a message feels urgent or unexpected. Never click links from unknown senders, and verify requests from known contacts through a separate channel. If a pop-up claims your device is infected or your bank account is locked, close it and check directly through the official website.

By breaking tasks into small, harmless-looking steps, the threat actors tricked Claude into writing exploits, harvesting credentials and expanding access.  (Kurt “CyberGuy” Knutsson)

Advertisement

Kurt’s key takeaway

The attack carried out through Claude signals a major shift in how cyber threats will evolve. Autonomous AI agents can already perform complex tasks at speeds no human team can match, and this gap will only widen as models improve. Security teams now need to treat AI as a core part of their defensive toolkit, not a future add-on. Better threat detection, stronger safeguards and more sharing across the industry are going to be crucial. Because if attackers are already using AI at this scale, the window to prepare is shrinking fast.

Should governments push for stricter regulations on advanced AI tools? Let us know by writing to us at Cyberguy.com.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report 
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.

Copyright 2025 CyberGuy.com.  All rights reserved.

Advertisement

Technology

Roland’s Go:Mixer Studio turns your phone into a mobile music studio

Published

on

Roland’s Go:Mixer Studio turns your phone into a mobile music studio

Roland now offers a more capable audio mixer for phones and tablets with the launch of the Go:Mixer Studio. The Go:Mixer audio interface lineup has always been a bit limited, better suited for scrappy live streams and capturing quick demos on their phones than professional recording. The Go:Mixer Studio is an attempt to actually reach that lofty goal, with more inputs and outputs, built-in effects, and up to 24-bit / 192kHz audio. There’s even an iOS app that allows you to capture video and multitrack audio simultaneously.

Streaming and social video are still the major use cases here. The Go:Mixer Studio can even be mounted on a mic stand so you can keep it in easy reach during a live session. The screen and knobs allow you to control all the parameters on the Go:Mixer Studio directly, but there’s also a desktop app for Windows and MacOS that gives you complete control of the mixer remotely.

There’s plenty of connectivity, including two XLR inputs on the back with phantom power, a 1/4-inch instrument input for directly connecting a guitar or bass, stereo 1/4-inch line-in jacks, and an aux input. There’s also 1/8-inch TRS MIDI in and out, two headphone jacks, and stereo line outs for connecting to studio monitors. Each audio input has a dedicated EQ and compressor on the channel. The XLR and instrument ins also have reverb available.

The Go:Mixer Studio is available now for $299.

Continue Reading

Technology

Alexa.com brings Alexa+ to your browser

Published

on

Alexa.com brings Alexa+ to your browser

NEWYou can now listen to Fox News articles!

For years, Alexa mostly stayed in one place. It lived on kitchen counters, nightstands or living room shelves. That setup worked for music and timers, but it also limited when and how people could actually use the assistant. Now that is changing.

Amazon has rolled out Alexa.com, which brings Alexa+ directly to your web browser for Early Access users. Instead of relying on a speaker or phone, you can now open a laptop and start using Alexa like any other web-based AI tool.

This shift is less about new tricks and more about access. Alexa can now follow you throughout your day instead of waiting for you at home.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Advertisement

CHATGPT HEALTH PROMISES PRIVACY FOR HEALTH CONVERSATIONS

Amazon’s Alexa is no longer tied to a smart speaker, with Alexa.com bringing the assistant and Alexa+ directly to the web browser for Early Access users. (Photo Illustration by Thomas Fuller/SOPA Images/LightRocket via Getty Images)

What Alexa.com actually is

Alexa.com is the browser-based version of Alexa+. You can type questions, explore topics, plan trips, organize tasks, or create content without touching a smart speaker. The biggest difference is continuity. Alexa keeps context across devices, so conversations carry over whether you are on your laptop, phone, Echo, or Fire TV. You do not have to repeat yourself every time you switch screens. That makes Alexa feel less like a command tool and more like an assistant that remembers what you are working on.

Who can use Alexa.com right now

Alexa.com is not open to everyone yet. To use it, you need:

  • Alexa+ Early Access
  • An Amazon account linked to a compatible Echo, Fire TV, or Fire tablet
  • US-based Amazon account
  • Device language set to English, United States

Child profiles are not supported on the browser version. Older Echo devices will continue using the original Alexa.

What Alexa.com cannot do yet

Because Alexa.com is still in Early Access, it has limits that matter for everyday users. Right now:

Advertisement
  • You can only type to Alexa in your browser
  • Voice interaction is not supported on the web
  • Music playback is not available
  • Smart home controls are limited compared to Echo devices

Amazon says features will roll out gradually. Alexa.com is meant to complement your devices, not fully replace them yet.

Meal planning without juggling tabs

One area where Alexa.com feels genuinely useful is meal planning. You can ask Alexa for a full week of meals and set preferences like high protein, low sugar, or kid-friendly lunches. Alexa generates a plan and turns it into a shopping list. From there, items can be added directly to Amazon Fresh or Whole Foods. Instead of bouncing between recipes, notes and carts, everything happens in one place.

Organizing everyday life in one place

Alexa.com also works as a lightweight life organizer. You can upload documents, emails and images so Alexa can pull out key details. That includes appointments, reminders and schedules you would otherwise forget. Instead of searching your inbox, you can ask Alexa when the dog last went to the vet or what time practice starts tonight. The information stays available across devices.

Smart home access, with limits

Alexa.com keeps your smart home controls visible next to your chat window. While full smart home control is still limited in the browser, Alexa.com lets you check status, review activity and continue actions on your Echo or Fire TV devices. It is most useful as a bridge. You can start something in the browser and finish it at home without starting over.

Recipes that follow you into the kitchen

Alexa.com also simplifies cooking. If you find a recipe online, you can paste the link into Alexa and ask it to adjust for dietary needs. Alexa can save it, convert it into ingredients and add everything to your shopping list. When it is time to cook, Alexa can pull the recipe up on your Echo Show, guide you step by step and manage timers so your hands stay free.

5 TECH TERMS THAT SHAPE YOUR ONLINE PRIVACY

Advertisement

Alexa.com lets users type questions, plan trips, organize tasks and create content without relying on an Echo or smartphone. (Michael Nagle/Bloomberg via Getty Images)

Finding something to watch faster

Decision fatigue hits hard at night. On Alexa.com, you can explore movie themes, get recommendations and save picks for later. When you sit down, Alexa remembers your choices and sends them to your Fire TV. That cuts down on scrolling and family debates.

What about privacy

Using Alexa on the web raises natural privacy questions. Amazon says Alexa+ includes built-in protections and user controls. Still, it is worth taking a minute to review your settings, especially if you plan to upload documents or personal information. A few smart habits can help:

  • Check your Alexa privacy settings and review stored activity
  • Avoid uploading sensitive documents like IDs or medical records
  • Use strong antivirus software to protect your device. The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.

As with any AI assistant, convenience comes with trade-offs. Staying aware helps you stay in control.

How much Alexa+ will cost

Alexa+ is free during Early Access. When Early Access ends, you will not be automatically charged. After that:

  • Alexa+ stays free with a Prime membership
  • Non-Prime users can subscribe for $19.99 per month

This makes Alexa.com more appealing for Prime members and a tougher sell for everyone else.

What this means to you

For most people, Alexa.com is about convenience. If you already use Alexa at home, the web version makes it easier to use during the day. You can plan, organize or look things up from your computer and then pick up later on your phone or Echo. It also puts Alexa in the same category as other browser-based AI tools, but with deeper ties to shopping, smart home features and entertainment. Whether you stick with it will likely come down to how often you want Alexa to help you during your day.

Advertisement

Take my quiz: How safe is your online security?

Think your devices and data are truly protected? Take this quick quiz to see where your digital habits stand. From passwords to Wi-Fi settings, you’ll get a personalized breakdown of what you’re doing right and what needs improvement. Take my Quiz here: Cyberguy.com.

YOU CAN FINALLY CHANGE YOUR GMAIL ADDRESS WITHOUT LOSING DATA

Amazon says Alexa.com allows conversations to carry over across devices, giving users continuity between laptops, phones and smart home screens. (Photographer: Michael Nagle/Bloomberg via Getty Images)

Kurt’s key takeaways

Alexa.com does not reinvent Alexa. It simply makes it easier to use where people already spend time. By bringing Alexa+ to the browser, Amazon is betting that continuity matters more than novelty. For some users, that will be enough to make Alexa feel relevant again.

Advertisement

If Alexa followed you from your laptop to your living room, would you actually rely on it more, or would it still feel optional? Let us know by writing to us at Cyberguy.com.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Copyright 2026 CyberGuy.com.  All rights reserved.

Advertisement
Continue Reading

Technology

A second US Sphere could come to Maryland

Published

on

A second US Sphere could come to Maryland

The second US sphere would be built in an area known as National Harbor in Prince George’s County, Maryland. Located along the Potomac River, National Harbor currently features a convention center, multiple hotels, restaurants, and shops. While Abu Dhabi plans to build a sphere as large as the one in Las Vegas, the National Harbor venue would be one of the first mini-Sphere venues announced last March.

Its capacity would be limited to 6,000 seats instead of over 17,000. But the smaller Sphere would still be hard to miss with an exterior LED exosphere for showcasing the “artistic and branded content” that helped make the original sphere a unique part of the Las Vegas skyline.

The inside of the mini-Sphere will feature a high-resolution 16,000 by 16,000 pixel wrap-around screen, the company’s immersive sound technology, haptic seating, and “4D environmental effects.” For the AI-enhanced version of The Wizard of Oz currently playing in Las Vegas, audiences experience effects like wind, fog, smells, and apples falling from the ceiling.

The mini-Sphere will potentially also be cheaper to build than the $2.3 billion original, but its construction is contingent on the “receipt of certain governmental incentives and approvals from Prince George’s County and the State of Maryland.” Sphere Entertainment says the project “would utilize a combination of public and private funding, including approximately $200 million in state, local, and private incentives,” but would potentially generate millions of dollars in revenue for the country and state while supporting over 4,700 jobs once it opens.

Continue Reading
Advertisement

Trending