The Safety Filter That Was Off for a Year (08/16/2026)

August 16, 2026
The Safety Filter That Was Off for a Year (08/16/2026)
Key Intel / TL;DR
  • Anthropic disclosed that its biological weapons classifiers were inactive from May 2025 through April 2026, across roughly 133 million chats by about 50,000 external contractors.
  • The company's internal investigation found no evidence of actual misuse, and it has tightened contractor vetting.
  • AmnesiaStealer added a module that clones the victim's browser profile and drives it live, so the operator works inside already-authenticated sessions.
  • OpenAI dissolved its Preparedness team at the end of July and distributed the biological and cyber risk work to existing groups.
  • A shifting DDoS campaign disrupted the Threema messaging service and its colocation provider for more than a day.

Today’s stories are about controls that were in place and not running. Anthropic’s bioweapon classifiers sat inactive for eleven months and 133 million conversations before anyone noticed, OpenAI folded the team whose job was catching that category of problem, and AmnesiaStealer stopped stealing credentials in favor of driving the session those credentials already opened. Four stories, because four is what the day actually produced.

Top Critical Security Alerts

1. Anthropic’s Bioweapon Filters Were Inactive for Eleven Months

In a safety report published this month, Anthropic disclosed that its biological weapons classifiers were not running from May 2025 through April 2026. During that window roughly 50,000 external contractors held about 133 million chats with the models. The company says its internal investigation found no evidence of actual misuse, and notes the contractors had been vetted only by outside vendors whose screening was often inadequate. Contractor requirements have since been tightened. The Decoder

Operator Note: Set the bioweapon framing aside and look at the mechanism, because it is one you have. A control was deployed, believed to be running, and silently was not, for eleven months. Ask which of your controls would tell you if they stopped working. For most organizations the honest answer is that you would learn from the absence of alerts, which is indistinguishable from a quiet month.

2. AmnesiaStealer Now Drives the Victim’s Browser

Jamf documented a stream module in AmnesiaStealer that goes past file collection. The malware duplicates the victim’s Chromium profile, launches it headless on the infected Mac, and opens WebSocket connections to both an attacker relay and the Chrome DevTools Protocol. The operator then navigates, moves the mouse, types, and watches a live screencast at roughly three frames per second. Because the cloned profile carries the existing authentication tokens and preserves the browser, host, and network identifiers, the usual session checks see nothing unusual. BleepingComputer

Operator Note: This is the escalation on yesterday’s AmnesiaStealer report, and it changes the response. Stolen credentials get fixed by a password reset. A live operator inside an authenticated session is already past your multi-factor prompt, your device trust, and your impossible-travel rule, because the session started legitimately on the right machine from the right address. Revoke the session as its own step, and confirm it terminated.

3. OpenAI Dissolved Its Preparedness Team

OpenAI shut down the Preparedness team at the end of July and parceled its biological and cyber risk work out to existing groups. Former lead Dylan Scandinaro is now working on risks from recursively self-improving systems. Greg Brockman said the company has woven safety work more tightly into model development. Several safety staff have left, including chief ethics officer Chloe Bakalar. The Decoder

Operator Note: Distributing a function into existing teams is a real organizational choice and it can work. It also removes the group whose only job was to look for the thing nobody else is measured on. If you have ever folded a security function into engineering to reduce friction, you already know which outcome you got.

4. A Shifting DDoS Campaign Took Down Threema

Large-scale denial of service attacks disrupted the Threema secure messaging service from Tuesday evening into Wednesday morning, hitting both Threema and its colocation partner Nine. Mitigation was difficult because the actor kept changing tactics to work around each measure. Users in Switzerland, India, and China saw disruption while the status page still showed everything healthy. Threema says it is unclear whether it was the primary target. BleepingComputer

Operator Note: The status page detail is the one worth keeping. Customers in three countries could not use the product while the page reported normal operation, which means the monitoring was checking something other than what users experience. Go find out whether your own status page would have caught this, and whether it checks from outside your provider’s network.

Additional Security Alerts

Security Tools & Best Practices

  • A practical guide to checking whether your AI platform accounts were accessed: Session logs, connected applications, and your inventory of issued interface keys are the places to look, and most people have never opened any of them. TechCrunch

Emerging Security Technologies

  • One in five US workers now hands tasks to AI rather than a colleague: That routing decision moves work, and the data inside it, outside whatever review a colleague would have applied. The Decoder
  • Mathematicians rate large language models strong at calculation and weak at creative work: Useful calibration for anyone scoping where these systems belong in an analysis workflow. The Decoder

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)