2026-09-12 AI 与数据工作流雷达
来源:The Hacker News。这里只保留与 AI 编程、数据/研究工作流、安全边界或可信工程直接相关的高信号线索;不抓取全文,也不代表事实核验或产品推荐。
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
主题:数据工作流与自动化
来源日期:2026-09-11
相关性分数:4
候选状态:待评估
为什么值得看:命中与临床统计、研究工程或可信 AI 工作流直接相关的高信号主题;仍需阅读全文并回到官方文档、原始研究或供应商公告交叉核验。
Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax. Knowledge distillation by itself is a legitimate training method . It refers to a machine learning technique where a large, powerful AI model assumes the role of a “teacher” to train a smaller, less-capable or faster “student” model to copy its capabilities. Illicit distillation, on the other hand, is an industrial-scale campaign that covertly extracts a model’s capabilities and replicates them in another model without authorization, typically by making use of networks of fake accounts created with stolen credit cards, login credentials, and API keys. Frontier AI labs in the West, including those from Google and OpenAI , have repeatedly called out distillation attacks aimed at their models. Anthropic said it has observed unauthorized labs …
可转化方向:评估对可复现分析、依赖管理、数据质量或研究工程流程的启发
Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example “sk-1234” Admin Key
主题:数据工作流与自动化
来源日期:2026-09-10
相关性分数:4
候选状态:待评估
为什么值得看:命中与临床统计、研究工程或可信 AI 工作流直接相关的高信号主题;仍需阅读全文并回到官方文档、原始研究或供应商公告交叉核验。
Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234 , the example admin key in LiteLLM’s own setup guide. LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway’s administrator credential. Anyone who holds it can read every model provider’s API key stored on the server. In Wiz’s tests, it also reached the cloud IAM credentials of the machine the gateway runs on. Changing the key needs no upgrade, and it closes every path in Wiz’s report that depends on holding it. Where the Number Comes From Wiz ran one scan. It found 3,074 LiteLLM gateways on Shodan in February, and 294 of them accepted the key. In 191 of those 294, no key was set at all, so they would have accepted anything. The rest had the setup guide’s value left in place. A second scan in August found more than 85,000 instances, but W…
可转化方向:评估对可复现分析、依赖管理、数据质量或研究工程流程的启发
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
主题:AI 与数据安全
来源日期:2026-09-11
相关性分数:3
候选状态:待评估
为什么值得看:命中与临床统计、研究工程或可信 AI 工作流直接相关的高信号主题;仍需阅读全文并回到官方文档、原始研究或供应商公告交叉核验。
Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals. “The cybersecurity skills of AI models means that AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators,” Anthropic said . “The use of AI went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing reconnaissance, exploitation, and data exfiltration.” Among the notable cases highlighted by Anthropic is the development of an AI-assisted workflow by…
可转化方向:评估 AI 辅助研究和编程中的隐私、凭据、供应链与安全边界