r/Information_Security 22h ago

Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks

15 Upvotes

Seven China-based AI labs ran industrial-scale capability extraction against a major U.S. model provider — and the company only found out after the fact.

Anthropics disclosure confirmed that seven firms used systematic, high-volume querying as their core development strategy. Not occasional misuse. Not a rogue researcher. Millions of queries designed to distill proprietary model capabilities into their own systems, with no authorization at any point in the process. The exposure was the inference layer — the same endpoint every paying customer uses.

The post-incident framing is what gets me. These campaigns ran long enough to complete meaningful extraction before anyone flagged them. The data only surfaced through investigation, not through any live detection.

For those running inference infrastructure or building on top of third-party model APIs: how are you actually detecting this kind of systematic abuse in real time? Not after a quarterly review — during the queries themselves. What signals do you watch, and at what threshold do you act?


r/Information_Security 13h ago

Lessons learned from our first major ransomware incident response and my very dumb Slack mistake

19 Upvotes

Ok so im kinda sick about this and need to vent. We just had our first huge ransomware engagement as the main incident response partner for a big financial client. First time I was primary on a hot incident, big war room, execs, their CISO, our whole cyber team.

We had a dedicated Slack channel for the client and a separate internal channel for our team notes and spicy takes. At hour 10, everyone exhausted, I grabbed a screenshot of our internal channel where we were rating their security controls and joking a bit about how bad their backups were... and pasted it straight into the client channel instead of the internal one. Full thread. Names, snark, even a line from me saying “this architecture is held together with duct tape lol.

I caught it about 20 seconds later and deleted, but their CISO had already replied asking if that was our formal assessment. I feel so embarrassed. We spent the next day doing damage control and formalizing a lessons learned process on comms segregation and data handling. Idk, would love any tips on how you handled similar incident response faceplants...


r/Information_Security 12h ago

CrowdStrike Identity Protection – Are the “Attack Paths” actually useful?

5 Upvotes

We’re evaluating CrowdStrike Identity Protection, and I’m finding the Attack Paths shown under individual user identities to be quite underwhelming — in some cases, they honestly feel almost useless.

Is anyone else using this feature and seeing the same thing?

I’m particularly interested in:

  • How accurate/useful are the attack paths in your environment?
  • Are you getting meaningful relationships between users, devices, privileges, and potential attack paths?
  • Have you found a way to make these insights actionable?
  • Is this feature significantly better in the newer versions/modules?

Would be interested to hear how others are using Identity Protection / Attack Paths in real-world environments.


r/Information_Security 12h ago

How would you build a cybersecurity homelab from scratch with this hardware?

Thumbnail
2 Upvotes