Top stories.
- Anthropic is reportedly helping the NSA deploy Mythos.
- Malware-as-a-service operation targets Minecraft players.
- DentaQuest breach affects 2.6 million accounts.
Anthropic is reportedly helping the NSA deploy Mythos.
Anthropic is helping the US National Security Agency (NSA) deploy its Mythos AI model for cybersecurity purposes, including potential offensive cyber operations, the Financial Times reports. Sources told the Times that Anthropic has around six "forward-deployed engineers" within the agency to help customize the model for specific applications. It's unclear if these workers are actively involved in operations. One source told the Times that Mythos would be useful for infiltrating the networks of adversary nations.
Anthropic announced earlier this week that it would distribute Mythos to 150 organizations across 15 countries, having previously limited its rollout to a few dozen US-based industry and government partners. The company is expanding access to critical infrastructure operators in the power, water, healthcare, communications, and hardware sectors. Anthropic noted, "What each partner has in common is that a successful attack on their codebase could be catastrophic. For most partners, we estimate that a major attack could affect more than 100 million people, with important ramifications for both global and national security."
Malware-as-a-service operation targets Minecraft players.
McAfee is tracking a major malware-as-a-service campaign that's targeting Minecraft players with Trojanized game clients and mods. The malware operation, dubbed "Weedhack," allows threat actors to "remotely access and manipulate the victims' screen, webcam, and file system through a dashboard hosted on the clear net." The researchers discovered over 3,800 unique malicious JAR files and more than 240 URLs responsible for distributing the malware, averaging around 2,000 to 3,000 hits per day.
Weedhack is distributed via SEO poisoning and deceptive YouTube tutorials instructing users to download the malicious mods. McAfee notes that the malware is widely used for cyberbullying, as many of its users are teenagers and young adults who are targeting victims of the same age.
DentaQuest breach affects 2.6 million accounts.
Massachusetts-headquartered dental benefits administrator DentaQuest sustained a data breach affecting 2.6 million accounts, according to Have I Been Pwned (HIBP). The breach affected email addresses, names, addresses, phone numbers, and health insurance information. HIBP adds, "Much of the data appeared in healthcare enrollment files (ASC X12 transaction sets) with some containing Medicaid IDs, while additional data appeared in member records and related files." The ShinyHunters extortion group claimed responsibility for the breach last month, and leaked hundreds of gigabytes of the allegedly stolen data after failing to obtain a ransom.
DentaQuest, a subsidiary of Canadian financial services firm Sun Life, confirmed earlier this week that it sustained a "cybersecurity incident involving unauthorized access to a limited portion of our network." The company added, "We are working as quickly and carefully as possible to determine the exact scope of the incident, including the nature and extent of any data that may have been compromised."