The Safety Filter That Was Off for a Year (08/16/2026)
- › Anthropic disclosed that its biological weapons classifiers were inactive from May 2025 through April 2026, across roughly 133 million chats by about 50,000 external contractors.
- › The company's internal investigation found no evidence of actual misuse, and it has tightened contractor vetting.
- › AmnesiaStealer added a module that clones the victim's browser profile and drives it live, so the operator works inside already-authenticated sessions.
- › OpenAI dissolved its Preparedness team at the end of July and distributed the biological and cyber risk work to existing groups.
- › A shifting DDoS campaign disrupted the Threema messaging service and its colocation provider for more than a day.
Today’s stories are about controls that were in place and not running. Anthropic’s bioweapon classifiers sat inactive for eleven months and 133 million conversations before anyone noticed, OpenAI folded the team whose job was catching that category of problem, and AmnesiaStealer stopped stealing credentials in favor of driving the session those credentials already opened. Four stories, because four is what the day actually produced.
Top Critical Security Alerts
1. Anthropic’s Bioweapon Filters Were Inactive for Eleven Months
In a safety report published this month, Anthropic disclosed that its biological weapons classifiers were not running from May 2025 through April 2026. During that window roughly 50,000 external contractors held about 133 million chats with the models. The company says its internal investigation found no evidence of actual misuse, and notes the contractors had been vetted only by outside vendors whose screening was often inadequate. Contractor requirements have since been tightened. The Decoder
Operator Note: Set the bioweapon framing aside and look at the mechanism, because it is one you have. A control was deployed, believed to be running, and silently was not, for eleven months. Ask which of your controls would tell you if they stopped working. For most organizations the honest answer is that you would learn from the absence of alerts, which is indistinguishable from a quiet month.
2. AmnesiaStealer Now Drives the Victim’s Browser
Jamf documented a stream module in AmnesiaStealer that goes past file collection. The malware duplicates the victim’s Chromium profile, launches it headless on the infected Mac, and opens WebSocket connections to both an attacker relay and the Chrome DevTools Protocol. The operator then navigates, moves the mouse, types, and watches a live screencast at roughly three frames per second. Because the cloned profile carries the existing authentication tokens and preserves the browser, host, and network identifiers, the usual session checks see nothing unusual. BleepingComputer
Operator Note: This is the escalation on yesterday’s AmnesiaStealer report, and it changes the response. Stolen credentials get fixed by a password reset. A live operator inside an authenticated session is already past your multi-factor prompt, your device trust, and your impossible-travel rule, because the session started legitimately on the right machine from the right address. Revoke the session as its own step, and confirm it terminated.
3. OpenAI Dissolved Its Preparedness Team
OpenAI shut down the Preparedness team at the end of July and parceled its biological and cyber risk work out to existing groups. Former lead Dylan Scandinaro is now working on risks from recursively self-improving systems. Greg Brockman said the company has woven safety work more tightly into model development. Several safety staff have left, including chief ethics officer Chloe Bakalar. The Decoder
Operator Note: Distributing a function into existing teams is a real organizational choice and it can work. It also removes the group whose only job was to look for the thing nobody else is measured on. If you have ever folded a security function into engineering to reduce friction, you already know which outcome you got.
4. A Shifting DDoS Campaign Took Down Threema
Large-scale denial of service attacks disrupted the Threema secure messaging service from Tuesday evening into Wednesday morning, hitting both Threema and its colocation partner Nine. Mitigation was difficult because the actor kept changing tactics to work around each measure. Users in Switzerland, India, and China saw disruption while the status page still showed everything healthy. Threema says it is unclear whether it was the primary target. BleepingComputer
Operator Note: The status page detail is the one worth keeping. Customers in three countries could not use the product while the page reported normal operation, which means the monitoring was checking something other than what users experience. Go find out whether your own status page would have caught this, and whether it checks from outside your provider’s network.
Additional Security Alerts
Security Tools & Best Practices
- A practical guide to checking whether your AI platform accounts were accessed: Session logs, connected applications, and your inventory of issued interface keys are the places to look, and most people have never opened any of them. TechCrunch
Emerging Security Technologies
- One in five US workers now hands tasks to AI rather than a colleague: That routing decision moves work, and the data inside it, outside whatever review a colleague would have applied. The Decoder
- Mathematicians rate large language models strong at calculation and weak at creative work: Useful calibration for anyone scoping where these systems belong in an analysis workflow. The Decoder
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.