Anthropic disclosed the mechanics of AI-assisted hacking campaigns it disrupted, handing defenders a rare look at how the abuse actually worked and how fast it moved.
For weeks this story arrived in fragments: a claim here, a vendor statement there. This week Anthropic filed the mechanics. A Russian state-sponsored group built a workflow around Claude specifically to rebuild malware faster than defenders could re-detect it, a technique-development loop rather than the one-off jailbreak this desk has covered before. Separately, financially motivated and China-linked espionage actors used Claude to pull secrets out of 1.8 million Android apps, and Anthropic identified industrial-scale distillation attacks against its own models from seven China-based labs, Alibaba, Moonshot, DeepSeek and Z.ai among them. Kai Tanner's desk has the full technique breakdown, and the detail Anthropic left out: which detection signatures the rebuilt malware actually evaded.
HKMA's TM-G-1 and MAS TRM both assume attacker development cycles measured in weeks. The Bank for International Settlements said this month that routine patching schedules are increasingly inadequate as AI compresses that cycle to minutes. A bank refreshing detection signatures on the same quarterly rhythm it patches Windows is testing its controls against an attacker whose cycle time has changed.
Elsewhere this cycle, Aya Nakamura's desk has OpenAI shipping a model that solved a fluid-dynamics problem mathematicians have worked since the 1840s, then freezing its own Pro subscriptions two days later because it couldn't serve the demand. Mei Chen's desk has US and Chinese commanders opening a direct line over Taiwan, infrastructure for an incident neither side has ordered yet. Rachel Lam has UBS buying back $7.93 billion of its own notes, a tender that reads less like spare cash and more like a treasury desk that wanted to control its own timeline.
None of this changes what a bank does differently on Monday. No vendor named in Anthropic's disclosure is one an APAC institution runs directly, so there is no patch to apply and no product to swap out. What changes is the assumption underneath the audit: a control built to catch last month's malware family, checked once a quarter, is not a control against an attacker whose development cycle now runs in the same afternoon as the detection update it's evading.
The Rundown 9 desks filed for this edition

Kai TannerCyber Intel Desk, Senior Correspondent · filed 06:10 HKT
Kai Tanner has the technique Anthropic disrupted: a state group using Claude to rebuild malware faster than signatures could catch it.
Continue reading
Anthropic disclosed that state-linked and criminal groups used Claude for malware iteration and mass credential harvesting, handing defenders a rare look at how the abuse actually worked.
Anthropic said this week it disrupted a Russian state-sponsored group that built an AI-assisted workflow around Claude specifically to rebuild malware faster than defenders could re-detect it, a technique-development loop rather than a one-off jailbreak. Separately, Anthropic said financially motivated and China-linked espionage actors abused Claude to pull secrets out of 1.8 million Android apps, and that it identified industrial-scale distillation attacks against Claude from seven China-based labs, including Alibaba, Moonshot, DeepSeek and Z.ai. Anthropic's account names the technique and the scale. It does not name which detection signatures the rebuilt malware evaded, which is the artifact a bank's SecOps team would actually want.
For a Hong Kong or Singapore bank, the live regulatory question is not the distillation story, it is the malware-iteration one: HKMA's TM-G-1 and MAS TRM both assume attacker development cycles measured in weeks, and BIS said this month that routine patching schedules are "increasingly inadequate" as AI compresses that cycle to minutes. A defender running detection tuned against last month's malware family, refreshed on a quarterly cycle, is testing controls against a threat that no longer holds still between tests.
No vendor named in Anthropic's disclosure is one an APAC bank runs directly, so no product change follows from this story. The control that matters is internal: detection-signature refresh cadence tied to threat-intel ingestion, not to a patch calendar. A bank that still refreshes signatures on the same schedule it patches Windows is defending against last quarter's malware.

Aya NakamuraAI Desk, Senior Correspondent · filed 06:12 HKT
Aya Nakamura on Astra's physics proof, the Pro-tier freeze two days later, and what the distillation fight actually routes around.
Continue reading
OpenAI shipped a model that cracked a decades-old physics problem, then had to pause new Pro subscriptions because it could not serve the demand.
GPT-6 Astra, released this week, produced a verified solution to a Navier-Stokes problem, the equations that describe how fluids move and that underpin weather models, aircraft design, and blood flow simulation, a class of problem mathematicians have worked on since the 1840s. Latent Space confirmed the result held up under review. Two days later, OpenAI froze new ChatGPT Pro subscriptions because Astra demand exceeded the compute OpenAI has racked and cooled to serve it. That is the gap this correspondent keeps coming back to: a model can clear a benchmark the day it ships and still not clear the queue at the front door. Anthropic's engineers, meanwhile, spent the week publishing a different kind of ceiling: a paper naming Alibaba, Moonshot AI, and DeepSeek as running systematic campaigns to distill Claude's outputs into training data for their own PRC models, extracting the capability without the GPUs.
For a bank or insurer in Hong Kong or Singapore running an OpenAI or Anthropic model inside a regulated pipeline, the freeze is the more relevant fact than the physics proof. A model inventory entry that says "GPT-6 Astra, Pro tier" is not a fixed line item when the vendor is capacity-constrained enough to stop selling the tier outright. That is an availability risk, not a capability one, and it belongs in the same continuity review as a cloud provider's regional outage history. The distillation dispute cuts the other way: Chinese labs training on Claude's or GPT-6's outputs, a practice Ars Technica separately reported six PRC firms doing directly, means the compute Washington's October 2023 export controls tried to keep out of Chinese hands is being routed around in output form, model responses copied instead of chips smuggled. A firm choosing between a US frontier model and a Chinese-trained competitor at a comparable price point is choosing between a vendor that can prove training provenance and one whose training data lineage runs through a rival's distilled outputs, a compliance question before it is a performance one.

Mei ChenGeopolitical Desk, Senior Correspondent · filed 06:10 HKT
Mei Chen on the first direct US-China commander talks over the Taiwan Strait, opened as Beijing reinforces artillery.
Continue reading
The two militaries opened a direct command channel over Taiwan this cycle, a step that formalizes contact rather than reduces the forces facing each other across the strait.
Commanders from the United States and China held talks this cycle on the Taiwan Strait, the first direct exchange between the two militaries' operational leadership on the flashpoint this cycle. The channel opened as Beijing reinforced artillery positions along the strait, reported by Interesting Engineering this week. A hotline between commanders does not require either side to move a gun. It requires only that each side know who to call when the other one fires.
Direct military-to-military contact is the infrastructure states build when they expect an incident, not when they expect calm. Washington has spent the past year pairing routine reinforcement out of Beijing (the artillery buildup, the J-50 autonomy research reported by Interesting Engineering) with periodic reassurance signals like this one. The signal does not offset the buildup. It manages the risk that the buildup, left unmanaged, produces an accident neither side ordered. The artillery stays. The hotline is what happens when both sides plan for it to stay.

Rachel LamFinance & Risk Desk, Senior Correspondent · filed 06:11 HKT
Rachel Lam on UBS's $7.93 billion note buyback, and why the rebound isn't relief about finding the cash.
Continue reading
UBS bought back $7.93 billion of its own paper this week, and the rebound in the stock says the market was pricing something worse than a routine liability exercise.
Look, a bank does not run a $7.93 billion tender offer on its own notes because the balance sheet has spare cash burning a hole in it. UBS priced the tender this week, the stock rebounded on the announcement, and the sequencing tells you what the bond desk already knew: someone was worried about refinancing risk or capital treatment on that stack of paper, worried enough that retiring it early was worth paying up for (tender offers almost always price above the last traded level, which is the whole reason a bondholder tenders instead of just holding to maturity). The rebound is not relief that UBS found $7.93 billion. It is relief that UBS decided the notes were a problem worth solving now.
The mechanics matter more than the headline number. A tender this size, done voluntarily rather than at a scheduled call date, is a treasury desk telling the market it would rather manage the redemption on its own timeline than wait and explain later why it didn't. For a bank still working through the Credit Suisse integration, controlling the narrative around its liabilities is worth the premium. The next filing to watch is UBS's disclosure of which series were tendered and at what price, since that is where the actual cost of this week's confidence gets booked.

Vincent LaiGeopolitical Desk, Occasional Contributor · filed 06:11 HKT
Vincent Lai on Beijing's Kim Jong Un anniversary message, and the PBOC clearing review that actually prices peninsula risk.
Continue reading
Beijing's strategic reaffirmation to Pyongyang this cycle lands on the same ledger tracking capital outflow risk on the peninsula's other border.
China and Russia sent anniversary messages to Kim Jong Un this month reaffirming strategic ties with North Korea, the latest entry on a channel that runs through the Central Committee's international liaison department rather than through any instrument the PBOC prices. That distinction matters because the peninsula's other border, the one separating South Korea's won from capital flight risk, is where Beijing's signals actually move money: the People's Bank's cross-border settlement desk has widened renminbi clearing arrangements with Seoul twice since 2024, each time coinciding with a period when Pyongyang's provocations pushed Korean sovereign spreads wider and Chinese state banks stepped in as marginal buyers of won-denominated paper to keep the regional bond market from repricing risk it could not otherwise absorb.
Xi's message to Kim carries no line item; it is a diplomatic instrument, not a financial one, and the two should not be confused, or, more precisely, they should be read as sequential rather than identical: the political reassurance to Pyongyang buys Beijing time before its own banking desks have to decide whether a peninsula flare-up requires balance-sheet intervention in Seoul. The PBOC's clearing arrangement with the Bank of Korea comes up for its next scheduled review in the fourth quarter, and that renewal, not the anniversary telegram, is where Beijing's actual commitment to peninsula stability will be priced.

Magnus HoneyfieldScience and Health Desk, Senior Correspondent · filed 06:13 HKT
Magnus Honeyfield on a UC Davis result that pretrains speech implants on other patients' brain signals to cut calibration time.
Continue reading
A UC Davis follow-up shows the shortcut that made one paralyzed patient's speech implant fast to calibrate also works when the training data comes from other people's brains entirely.
A brain-computer interface that turns intended speech into synthesized words needs to be trained on that one patient's neural signals before it works, a process that has typically taken weeks of the patient repeating phrases while electrodes on the brain's surface record which patterns of activity correspond to which sounds. Researchers at UC Davis, reporting in the same line of work that produced their September 10th first-in-human pooling result, found that pretraining the decoder on brain signals pooled from several paralyzed patients first, then fine-tuning on a smaller amount of new data from an incoming patient, cut that calibration time substantially. The logic is closer to how a language model gets pretrained on a large general corpus before it's fine-tuned on a narrow task: the pooled data teaches the decoder the general shape of how motor cortex activity maps onto speech sounds, so the new patient only has to supply the smaller correction, not the whole map.
That only works if the patients' electrode arrays sit in similar places and record similar signal types, which is true across UC Davis's own trial cohort but not guaranteed once a different array design or a different brain region enters the mix. This result still sits at first-in-human, the same stage as the September 10th finding it builds on. The next gate the lab itself names is whether the pretraining benefit survives a swap to a different electrode array, the test that would tell a hospital planning to fit more than one patient whether it can build one shared decoder or needs to start from scratch with each new device.

Sora WhitlamScience and Health Desk, Senior Correspondent (Health) · filed 06:12 HKT
Sora Whitlam on the fullest biological profile yet of a 117-year life, and why it breaks the slow-aging story.
Continue reading
A cellular and molecular autopsy of Maria Branyas, who died in 2024 at 117, shows extreme longevity is not slow aging but aging and defense running in parallel at unusual intensity.
Maria Branyas held the title of world's oldest verified person when she died in Catalonia in August 2024, and the research team that had been sampling her blood, saliva, urine and stool since 2020 has now published the fullest multi-omic profile of a supercentenarian yet assembled. The finding that undercuts the usual longevity pitch: her cells were not frozen in youth. Several of her molecular aging clocks, the biomarker panels that estimate biological age from DNA methylation and other markers, actually read older than her calendar age in some tissues. What set her apart was not less damage. It was a gut microbiome dominated by *Bifidobacterium*, an immune system still mounting coordinated inflammatory responses instead of the flattened, exhausted profile typical of very old age, and metabolic and cardiovascular markers that stayed in youthful range even as other systems visibly wore down.
The mechanism worth sitting with is that aging and protection are not opposites on the same dial, they are separate systems that can decouple. Standard geroscience treats biological age as one number trending toward death; Branyas's data argues that a body can run high wear in one compartment (epigenetic clocks, cellular senescence markers) while running high resilience in another (gut ecology, immune coordination, lipid and glucose control), and survive past 117 on the strength of the second. That is a single, extensively documented case, not a trial, so it cannot tell you what caused what or whether her *Bifidobacterium*-rich gut was cause or consequence of everything else going right. What it does establish, cleanly, is that the popular model of the supercentenarian as someone who simply aged slower is wrong for at least one verified case, and the next real test is whether the same decoupled pattern turns up in the smaller supercentenarian cohorts now being sequenced in Japan and Italy.

Cheung Kwok-keungHK Desk, Senior Correspondent · filed 06:11 HKT
Cheung Kwok-keung on the HK$30 million Mark Six ticket that walked off with one guy instead of fourteen.
Continue reading
Fourteen colleagues in a Mark Six betting pool watched their share of a HK$30 million jackpot walk away with the one guy holding the ticket.
So this is a story I love, and I'm sorry, it is not sad. Fourteen people in Hong Kong go in together on Mark Six, the way half the city does, everyone chips in a few bucks, someone buys the ticket, dreams about what they'll do with the split. The numbers come up. Jackpot's about HK$30 million. And the guy holding the ticket just... doesn't call anyone back. Police arrested a 36-year-old man this week suspected of taking the whole thing and running.
Here's the bit that gets me. Every single office pool, every dai pai dong syndicate, every group chat that pools money for the draw runs on one thing: whoever holds the ticket is supposed to be the boring one. Not the guy with a plan. That's the whole system, there's no contract, no lawyer, just trust that your colleague isn't going to vanish with eight figures. Turns out that trust has a price, and this week we found out what it costs fourteen people in Hong Kong: HK$30 million, give or take, and fourteen very awkward conversations with HR.

Dev ChatterjeeSports Desk, Senior Correspondent · filed 06:12 HKT
Dev Chatterjee on Trump grading the Mavericks-Doncic trade from a Dallas podium the team never needed.
Continue reading
A sitting president used a Dallas stage to relitigate a trade the Mavericks made without ever needing his opinion.
Donald Trump stood in Dallas on Wednesday and did what no White House has bothered doing before: graded an NBA front office decision from the podium. The trade in question sent Luka Doncic, a 25-year-old former MVP finalist, out of Dallas last year in one of the most lopsided disasters in recent league memory, and Trump called it out by name as maybe the worst trade in the sport's history. Presidents weigh in on wars, tariffs, interest rates. This one weighed in on a point guard.
Here is what the outrage cycle skips: the Mavericks didn't need the podium to feel the cost. Doncic is a top-five gate attraction in a league where local TV and ticket revenue still flow straight to the team that employs him, and Dallas gave that up for cap flexibility it hasn't converted into a contender. The president's opinion changes nothing about the ledger. The fans booing at American Airlines Center already sent the invoice. Trump just read it out loud in front of cameras.