September 11, 2026
Anthropic Says AI Agents Performed Nearly All the Work in Some Data Thefts
A new threat report shows attackers delegating discovery, exploitation and exfiltration to AI. Oracle's cloud numbers, a blast-resistant data-center rethink, California's child-tech laws and Apple's $1,999 foldable show what it costs to put capability inside a durable system.

The Short Version
Anthropic says AI agents performed nearly all the work in some data thefts it investigated.
In one cluster of attacks linked by the company to ShinyHunters affiliates, a stolen developer token became full administrative control of a victim's cloud environment in roughly three hours. Another breach moved from initial access to bulk data theft within hours. The agents explored unfamiliar systems, wrote and ran scripts, collected data and kept trying until the task was complete. People supplied targets and direction.
The disclosure comes from Anthropic, whose models were used and whose threat team investigated the activity. It isn't an independent census of cybercrime, and the report focuses on unusually serious or novel cases between December 2025 and August 2026. The details still expose a practical change: a small crew can sustain work that once required several specialists.
That changes the defensive clock. A static alert can cause an attacker-controlled agent to rewrite malware and redeploy it. A stolen credential can be tested, expanded and monetized at machine speed. Security teams need controls that limit what a valid credential can reach, detect unusual sequences of behavior and stop an account before the attacker completes the whole chain.
Four other developments published Thursday and Friday reveal different costs of turning technical capacity into dependable value.
Oracle reported $19.3 billion in quarterly revenue, up 30% from a year earlier, and $7.4 billion from cloud infrastructure, up 121%. It also spent $28.5 billion on capital projects and produced negative free cash flow of $5.4 billion. Its $664 billion backlog shows contracted demand, while the cash flow shows how expensive fulfillment remains.
The United Arab Emirates is likely to replace a planned 5-gigawatt AI campus with a network of data centers, according to six people who spoke with Reuters. Officials are considering underground construction, blast-resistant concrete, backup power and cooling, air defenses and electronic jamming after Iranian attacks damaged regional cloud facilities. G42 says work is progressing and project details remain under review. The revised master plan has yet to be finalized.
California enacted a package of child-tech laws. The measures restrict addictive social-media features for users under 16, require risk assessments for AI chatbots, create parental controls and temporarily ban the manufacture and sale of toys with companion chatbots. The rules move safety questions into product design, yet enforcement, age assurance, privacy and constitutional challenges will determine how much changes in practice.
Apple's first folding iPhone starts at $1,999 and reaches $3,199 at the highest storage tier. The larger screen supports split-screen work and iPad-like layouts. Foldables still represent a small share of smartphones, and repair specialists remain wary of the category. A premium device needs a job that earns its weight, price and repair risk.
Across all five stories, capability arrives first. The surrounding system decides whether it becomes useful, affordable and survivable.
Attackers Can Keep the Loop Running
Anthropic's report shows AI moving from advice into cyber execution
Anthropic published a threat intelligence report Thursday covering malicious use of Claude between December 2025 and August 2026.
The company says it disrupted every operation described, banned associated accounts, strengthened safeguards and shared intelligence with authorities or industry partners where appropriate. The report spans cyberattacks, surveillance, influence operations, fraud, conventional weapons, biological misuse and attempts to extract Claude's capabilities for competing models.
The cyber cases deserve immediate attention from ordinary organizations because they describe attacks against familiar systems: cloud accounts, software vendors, mobile applications, hotel Wi-Fi, email tenants and authentication tokens.
One suspected Russia-linked espionage actor used AI across reconnaissance, phishing, infrastructure setup, persistence, data theft and malware maintenance. Anthropic says the group's tradecraft and targets were consistent with Midnight Blizzard, which the US government has linked to Russia's foreign intelligence service. The group targeted more than 20 organizations, concentrated in Ukraine and Europe, including ministries, defense organizations, embassies, think tanks and drone suppliers.
Its agents also monitored whether security products detected the malware. When a defense flagged an implant, the system modified and rebuilt the code until it evaded detection. This created a feedback loop that could continue while the human operator refined goals and reviewed results.
A second cluster involved operators Anthropic suspected were affiliated with ShinyHunters. One pipeline downloaded 1.8 million Android application packages and scanned them for exposed credentials. In supply-chain attacks, the operators used access to a software provider to reach downstream customers. Anthropic describes one dump containing more than 2,100 Microsoft cloud token sets across over 40 corporate tenants in about 34 hours.
The company says AI agents performed nearly all the work in these intrusions. Anthropic's systems weren't breached in the cases. Attackers used stolen API keys from customer environments, which means weak credential handling at one company helped finance attacks on others.
The biological findings carry higher stakes and heavier uncertainty. Anthropic documented five cases in which scientists used its models for work that could support biological weapons development. One user sought help planning experiments involving adaptation of avian influenza to mammals. Another worked on a grant application involving gain-of-function research on chikungunya. Such research can support vaccines or treatments and can also make a pathogen more dangerous.
Anthropic withheld the institutions, countries, specific agents and techniques. It said researchers' intent was uncertain. None of the biological cases used its newest Fable or Mythos-class models, and the company says older 2025 models were below the threshold for materially helping a sophisticated user conduct dangerous biological research. Anthropic also says that assurance has become uncertain for today's more capable systems, which is why newer models carry stronger biological safeguards.
This is company-observed evidence, selected by the company from its own service. It provides no denominator for total use, malicious use or incidents missed. It also cannot show how each operation would have performed without AI. The specific workflows and timings still give defenders useful evidence about where the pressure is moving.
A business can prepare without building an exotic AI security program. Protect the credentials that agents use. Give each service account the smallest useful authority. Keep production, backups and administrative identity on separate paths. Detect sequences such as a new token, rapid privilege escalation, cross-tenant access and bulk export, especially when they occur within hours.
Security teams also need a response loop that runs as quickly as the attack. A static signature buys less time when malware can rewrite itself. Behavior, rate limits, step-up approval and automatic containment can interrupt the sequence before the attacker reaches the data.
The economic measure is avoided consequence. Count stolen credentials found, time from first anomalous action to containment, downstream tenants reached, data exported, recovery hours and services interrupted. A tool that produces many alerts adds activity. A control that stops the chain before exfiltration reduces risk.
AI is giving attackers affordable persistence. Defenders need bounded authority and a faster stop.
Oracle Has Demand and a Cash Test
A $664 billion backlog still has to become revenue through expensive infrastructure
Oracle's fiscal first-quarter results offer a rare view of both sides of the AI infrastructure boom.
Revenue reached $19.3 billion for the three months ended August 31, up 30% from a year earlier. Cloud infrastructure revenue rose 121% to $7.4 billion. Oracle booked over $30 billion in additional AI cloud contracts, lifting remaining performance obligations, a measure of contracted revenue that hasn't yet been recognized, to $664 billion.
Those are operating results and signed commitments. They give Oracle stronger evidence of demand than a memorandum or capacity announcement.
They also sit beside $28.5 billion in quarterly capital spending and negative free cash flow of $5.4 billion. The cash outflow was smaller than the $9.56 billion analysts expected, according to LSEG data reported by Reuters. Smaller still means negative.
Oracle says about $11.36 billion of the quarter's capital spending was covered by customer prepayments. Finance chief Hilary Maxson said most of the new contracts use prepayment, customer-owned hardware or similar arrangements and therefore require little additional Oracle capital. The company expects roughly half its current backlog to convert into revenue within 36 months.
That financing design matters. Customers are helping fund capacity or bringing equipment to Oracle facilities. Oracle reduces some balance-sheet pressure. Customers gain reserved computing and accept a longer commitment, prepayment risk or responsibility for hardware.
The $664 billion figure remains a backlog. Revenue will arrive as Oracle brings sites online and delivers service. Labor, permits, power and construction can slow that conversion. Concentration among a small number of large AI customers can also turn one delayed project or changed strategy into a large financial exposure.
Oracle's result supports a precise ROI claim: cloud infrastructure revenue is growing quickly, contracted demand increased and current cash burn came in below analyst expectations. It provides no audited proof that Oracle's customers are earning returns from the AI workloads they run, or that Oracle's full buildout will produce adequate cash over its life.
That separation should travel into every AI business case. A signed vendor contract proves purchasing. Usage proves activity. Accepted work proves output. Revenue, cost reduction, added capacity, lower risk or faster service proves a business consequence.
Buyers should reconstruct one workload before reserving large capacity. Record its accepted outputs, baseline labor and delay, model quality, data-transfer cost, utilization, engineering support and switching path. Then calculate the cost per accepted result under the committed capacity, including idle periods.
Prepayment can lower a unit price and still destroy value when adoption lags. Bring-your-own-hardware can secure supply and still create integration and maintenance work. A multiyear commitment can protect capacity and reduce flexibility when models become more efficient.
Oracle's quarter says demand is real. It also shows who is paying early, how much cash the build consumes and how long delivery may take.
AI Infrastructure Is Becoming a Physical Target
The UAE is reportedly replacing one giant campus with a distributed network
The United Arab Emirates is reconsidering the physical design of one of the largest planned AI computing projects outside the United States after the Iran war reached regional technology infrastructure.
Reuters reports that the 5-gigawatt UAE-US AI Campus, originally envisioned as a 10-square-mile site in Abu Dhabi, will likely become a network of facilities across the country. Six people familiar with the deliberations described the review. Reuters couldn't determine how close officials are to a final plan or how the changes could affect cost and timing.
Officials are considering underground construction for some facilities, mountain locations for highly sensitive data, blast-resistant concrete, added backup power and cooling, drone and missile defenses and electronic jamming, according to the sources.
The project is led by G42 and involves US technology companies including OpenAI, Oracle, Nvidia and Cisco. G42 told Reuters that work is progressing as planned and said details are continuously reviewed against security, resilience and operating standards. The first phase, a $30 billion, 1-gigawatt cluster called Stargate UAE, began construction last year. Its first 200 megawatts are due online in 2026.
The trigger was physical. Two Amazon Web Services data centers in the UAE and one in Bahrain were damaged during Iranian attacks in March, Reuters reported. Iran later identified Stargate UAE as a potential target in a video.
Concentrating five gigawatts at one campus can lower operating complexity. Power, cooling, network connections, staff and security can be shared. Concentration also creates a visible target and a larger common failure.
Distribution reverses some of that trade. Multiple sites can reduce the share of capacity lost in one strike or utility failure. It increases network requirements, coordination, duplicated equipment and the difficulty of moving workloads between locations. Underground or hardened construction adds time and capital. Air defenses introduce military, regulatory and maintenance dependencies far outside normal data-center operations.
Cloud customers rarely price kinetic risk into an AI workload. The Gulf attacks make it part of service continuity. A model can remain available in another region while data-residency rules, latency, licensing or proprietary hardware prevent the customer's work from moving there.
Organizations with important AI services should test the exit route before an emergency. Preserve model versions, prompts, data pipelines, authentication, evaluation sets and deployment instructions. Run the minimum viable service in a second failure domain with a different power, network and administrative path.
The measure is workload recovery, not spare capacity on a diagram. Track which functions restart, how long data restoration takes, what quality is lost, which legal boundary changes and how much traffic the alternate route can carry.
The UAE plan remains under review. Its reported redesign still marks a threshold. Advanced computing now belongs on the same critical-infrastructure map as energy, communications and transport.
California Draws a Line Around Childhood
New laws reach addictive feeds, AI chatbots and connected toys
California Governor Gavin Newsom signed 13 bills Thursday addressing technology risks to children.
One law bars social platforms from exposing users under 16 to features defined as psychologically exploitative and designed to maximize engagement, including infinite scroll and algorithmic autoplay. Another requires AI chatbot operators to conduct risk assessments and add child-safety controls. Families gain the ability to decline school-issued laptops.
The package also imposes a four-year ban on manufacturing and selling toys that contain companion chatbots. A separate measure expands criminal rules on child sexual abuse material to cover digitally altered or AI-generated depictions of minors engaged in sexual conduct.
These are enacted laws, although start dates, implementing rules and legal challenges will shape their effect. Associated Press reports that large social-media companies can face penalties up to $1 million per child if found negligent in causing harm through their platforms.
The design problem now moves into ordinary product decisions. A platform has to identify a young user, remove or change specified engagement features and preserve a usable service. A chatbot company has to evaluate foreseeable harm before release and make parental controls work across devices and accounts. A toy maker has to decide whether an internet-connected voice product falls inside the temporary ban.
Age assurance can improve protection while creating new privacy risk. Collecting identification or biometric estimates can expose sensitive data. A coarse age signal may reduce collection and still produce mistakes that lock out adults or expose children. The implementation needs data minimization, appeal and deletion rules.
The feed restriction has its own trade. A following-based or chronological experience may reduce compulsive recommendation loops. It can also make discovery harder for young creators, community groups and people seeking support. Electronic Frontier Foundation has called the restriction a threat to privacy and speech. Meta says personalization can help deliver age-appropriate content and connect teenagers with relevant interests.
Those objections deserve measurement. Platforms should report how age is determined, how many people are misclassified, which features change, how often settings persist and whether self-harm exposure, unwanted contact, compulsive use and complaints move. Results should be separated by age and other relevant groups.
Schools and families can use the same discipline now. Choose one connected product and inventory what it records, where the data goes, which adult can see it, how a child exits the interaction and what happens during a crisis. A toy or chatbot built for companionship deserves a higher bar than a one-purpose learning tool.
California has moved beyond disclosure for several child-facing designs. Product teams now have to show that safety exists inside the experience a child actually receives.
Apple's Foldable Has to Earn Its Second Screen
The iPhone Duo starts at $1,999 in a category that still serves a niche
Apple introduced its first folding phone Wednesday. The iPhone Duo opens from a 5.4-inch outer display to a 7.6-inch inner screen and goes on sale October 23 after preorders begin October 16.
The 256-gigabyte model costs $1,999 in the United States. The highest storage configuration reaches $3,199. Apple demonstrated split-screen work, iPad-like applications, content creation and entertainment. Chief executive John Ternus described the device as a personal AI hub.
The hardware is substantial. WIRED reports a titanium frame, IP68 water and dust resistance, a 254-gram weight and a body measuring 11.3 millimeters when folded. The device uses Touch ID in the side button and supports Apple's USB-C Pencil, though the stylus has no integrated storage point.
The market evidence is narrower than the attention around the launch. Foldables are on track to represent under 3% of global smartphones in 2026, according to IDC data cited by Reuters. Counterpoint estimates Apple could sell close to 6 million Duo units by year-end through pent-up demand and brand strength. That is an analyst forecast, not an observed result.
Repairability remains a material risk. Folding screens, hinges and tightly packaged components have improved, but iFixit's Elizabeth Chamberlain told WIRED that her organization has yet to dismantle a foldable it would call truly repairable. Leasing can spread the purchase cost while placing return-condition risk on the user.
For a professional, the business case is specific. A field inspector may value plans, forms and photos on one pocketable device. A salesperson may run a call beside account notes. A creator may review a rough cut or storyboard without carrying a tablet. Each workflow needs an application that uses the larger canvas and a work setting where a separate laptop or tablet is inconvenient.
The sensible test compares the complete kit. Include the phone, protection plan, case, accessories, repair downtime, battery life and any computer or tablet it truly replaces. Measure completed field work, time saved, errors, files transferred and devices carried.
A $1,999 phone can be economical for a high-value mobile workflow. It can also be an expensive way to watch a larger video. Apple's initial sales will reveal desire. Repeat use of the inner screen will reveal purpose.
Opportunity Radar
Fast containment for agent-speed attacks
Small and midsize organizations increasingly depend on cloud identities, SaaS integrations and developer tokens while lacking a team that can investigate a three-hour escalation. A managed security provider or identity specialist could offer containment built around one high-risk credential path.
The service would map which tokens can reach customer data, establish normal behavior, add export limits and step-up approval, and automatically suspend access when a new credential begins rapid privilege escalation or bulk collection. Software companies, professional firms, healthcare suppliers and nonprofits could pay for shorter exposure and a response record they can show customers.
The provider must validate false-positive rates, authority to suspend service and the time needed to restore legitimate work. Time to containment, data exported, downstream customers reached, manual investigations and business interruption provide a useful scorecard.
Foldable workflow design for field teams
The expanding foldable market creates a small, testable service opportunity for consultants and software developers who support field sales, inspection, logistics, healthcare or maintenance teams. Many existing mobile applications simply stretch across a larger screen.
A provider could redesign one task so the user can view evidence beside the form, compare an image with instructions or keep a call beside customer records. Employers benefit if the device replaces paper, a second screen or a return trip to a desk.
Validation starts with workers in the field, not a device demo. Completion time, errors, training, battery use, repair downtime and the number of devices carried should improve enough to cover hardware and development costs.
What You Can Do With This
If you manage cloud accounts
Pick one privileged token and trace everything it can access. Add a limit on bulk export, a trigger for unusual privilege changes and a tested suspension path. Time how long your team takes to contain a simulated three-hour escalation.
If you buy AI capacity
Separate contracted demand from delivered service and delivered service from business return. Attach prepayments, idle capacity, engineering, data movement and switching work to one accepted workload before committing at scale.
If your product serves children
Test the experience through a child's actual account. Record how age is established, which data is collected, how parents intervene, how a user exits and what occurs during a safety crisis. Prepare for rules to reach engagement design as well as content.
If you're considering a foldable for work
Name the task that needs two panes before buying the device. Compare it with a current phone plus tablet or laptop for two weeks. Count completed work, errors, charging, repairs and the devices you still carry.
The Bigger Picture
Anthropic's report shows what happens when AI can keep a hostile workflow moving. The attacker provides direction. Agents explore, modify, collect and retry. A defense designed around one human operator can lose the race.
Oracle's numbers show the capital version of the same pressure. Demand can rise faster than capacity, and fulfillment pulls customers into prepayments and hardware commitments. The backlog grows before the infrastructure turns the contract into service.
The UAE's review carries computing into physical security. Distribution, hardening and backup systems add cost because a five-gigawatt concentration can fail in one place. California's laws carry safety into feeds, chatbots and toys. Apple carries a second screen into the pocket and asks the buyer to find a purpose worth $1,999.
Scale moves constraints into the surrounding system. Faster attacks require faster containment. Larger backlogs require financing and delivery. Concentrated computing requires physical resilience. Child-facing software requires enforceable boundaries. New hardware requires a repeated job.
The test is concrete in every case. Can the organization stop the credential before export? Can Oracle convert contracts while funding the build? Can a workload survive the loss of one site? Can a child use a service without manipulative design? Can a foldable replace another device or finish work faster?
Capability answers what technology can attempt. Durable systems decide which attempts people can afford, trust and recover from.
References
WIRED: iPhone Duo specifications, release timing and repairability concerns, September 9, 2026
AI Next Wave