The Wang Report · Weekly Edition


The Sunday Issue

Sunday, September 13, 2026
The Lead

The Guardrail Is Now A Job

Anthropic's own disclosure this week showed AI safety teams no longer writing policy but running live counter-operations against state hackers using their own models.

Read Charmaine Lo's Saturday and Sunday editions back to back and the shift is not subtle. Saturday: Anthropic details how attackers used Claude. Sunday: Anthropic discloses that Chinese labs and a Russian espionage crew used Claude for months before its safety systems caught them. That is not one story told twice. It is an admission, in two parts, that the company spent months fighting adversaries who treated its product as infrastructure to occupy.

The mechanics matter more than the headline. Kai Tanner's reporting on the disruption shows the Russian crew was not just using Claude to write malware. It was using Claude to rebuild malware that Claude's own systems had already flagged and detected, iterating in real time in the gap the guardrail left open. The Chinese labs, separately, ran distillation attacks against the model at industrial scale, treating Anthropic's weights as a resource to extract rather than a service to abuse. Two different adversaries, two different objectives, the same target: not a bank, not a government network, but the model itself, sitting inside Anthropic's own infrastructure.

Sunday's edition put the stakes in one sentence. Any firm routing regulated data through Claude, Gemini, or GPT based agents can now ask its own vendor a concrete question: not whether misuse gets caught, but how many weeks pass before it does. That question did not exist in this form a year ago. It exists now because the answer, for months, was measured in months.

Set this against Thursday's advisory, where Washington named six Chinese AI firms in a model copying warning with no breach and no lawsuit attached, just a paper trail. And against Kai Tanner's coverage of the Cisco and Check Point flaws that ran the same week, patched in time but on a manual fix slower than attackers have historically needed to close the gap. The pattern is the same across all three: the defenses that matter now run continuously, inside the vendor, not the ones written down once and revisited on a quarterly audit cycle. Anthropic said as much itself on Saturday: a control built to catch last month's malware family, checked once a quarter, does not stop an attacker whose development cycle runs in the same afternoon as the detection update it is evading.

What is new this week is not that AI can be misused. It is that the companies building these models have become a first line of defense that used to belong to governments and enterprise security teams, whether they applied for the job or not. Anthropic did not sign up to be a counterintelligence unit. It became one because its product was the terrain being fought over, and the fight did not wait for a policy framework to catch up.

The number worth keeping from this week is not a dollar figure or a vulnerability count. It is months, the gap between when the abuse began and when Anthropic's own systems caught it. That gap is the actual state of AI safety today, not the marketing language around it. A bank or a government deciding this month how much regulated work to hand an AI agent is not evaluating a benchmark. It is betting on how fast that gap closes next time, against a vendor that spent this week admitting, in public, exactly how long it took last time.

★ Standout

Check Point's Own Bug, Everyone Else's Deadline

Check Point patched two critical VPN flaws before anyone exploited them, but the manual hotfix APAC banks must run is slower than attackers have historically needed to catch up.

Check Point disclosed two vulnerabilities in its Quantum Security Gateway and Security Management Server software on September 9, and said its own research team found both before anyone else did. CVE-2026-85102 is a certificate trust validation flaw that lets an unauthenticated party trigger remote code execution during VPN negotiation. CVE-2026-85103 is a heap overflow in the same VPN certificate handling code, the ASN.1 decoder that parses the certificate's binary structure, and it reaches both the gateway and the management server behind it. Both score 9.8 out of 10 on the industry's severity scale. Check Point's own account is unusually clean: no evidence of exploitation, no public proof of concept, a fix already shipped via LivePatch and as Jumbo Hotfix Accumulator builds across the affected version lines. Four days later the Dutch Nationaal Cyber Security Centrum rated both the likelihood and the impact of exploitation 'high' and said attempts should be expected soon, a phrase that in these advisories functions less as a forecast than as a countdown timer. Nobody in that sentence has seen an attack yet. The Dutch agency is reading the vulnerability class, not a log file, and that class has burned Ivanti and Fortinet customers on a schedule measured in weeks.

The dangerous half of this disclosure is not the gateway. It's the Security Management Server, the console that pushes security policy to every Quantum gateway an organization runs, and CVE-2026-85103 reaches it through the same certificate decoding path. Burns & McDonnell's technical analysis, published under its 1898 Advisories brand, put the consequence plainly: a single compromised management server exposes not one appliance but the policy for the entire managed fleet. That is not a hypothetical this week: perimeter VPN and firewall management consoles have repeatedly turned single flaws into estate-wide compromises once attackers get past the same trust and authentication logic that guards everything else on the device. Check Point's version has no confirmed exploitation yet. The historical pattern on this class of device is that confirmation, when it comes, comes fast.

LivePatch applies for institutions that already run it, which is the automatic route. Everyone else installs the Jumbo Hotfix Accumulator by hand, through whatever change control governs their gateway estate, and that is where the clock problem lives. A bank's technology risk committee wants a test window, a rollback plan, a maintenance slot that doesn't collide with month end settlement. None of that is unreasonable. All of it takes days the historical record has not been generous with: Ivanti's and Fortinet's edge appliance flaws were both reverse-engineered from the vendor patch and weaponized within one to three weeks of disclosure, not months. A bank running a multi-year change-control cycle inherited long before anyone had heard of a Jumbo Hotfix is not being negligent. It is running the same cycle that cleared every other patch on schedule, against a device class that no longer waits for the cycle to finish. Regulators across the region expect banks to patch critical systems within a defined window once active exploitation is confirmed. Nothing is confirmed yet. That is exactly the gap the Dutch warning is asking banks to close before it opens.

As of today, nobody has weaponized CVE-2026-85102 or CVE-2026-85103. The entire state of play is a vendor that found its own bug, a regulator that doesn't expect it to stay that way, and a patch that has to clear change control before either one is proven right. The control that resolves this is not a firewall rule. It is enabling LivePatch before the next disclosure lands, so the fix that ships automatically doesn't have to wait for a meeting.

Read on its own page: CYBER DESK →
In this issue
Vincent Lai
GEOPOLITICAL DESK
The Pension Fund That Skips The Quota Line
China's state pension fund is drafting a quota-free route into Hong Kong's bond market as Beijing shuts the retail channel ordinary mainlanders used to move money out.
Continue reading →
Mei Chen
GEOPOLITICAL DESK
Beijing Prices Trump's Summit At $14 Billion
China's threat to cancel Xi's September 24 White House visit over a $14 billion Taiwan arms sale turns Taipei's procurement calendar into Washington's summit currency.
Continue reading →
Rachel Lam
FINANCE & RISK DESK
Shein's IPO Raised $1.7 Billion, But Only 5 to 6.6 Percent Trades
Shein's $1.7 billion Hong Kong listing raised real money, but a float of just 5 to 6.6 percent means the week's selling, not the deal, is setting the price.
Continue reading →
Aya Nakamura
AI DESK
Moonshot's Revenue Story Has A Claude-Shaped Hole
Moonshot built a $2 billion revenue story and a $50 billion valuation on Kimi K3, and Anthropic's forensic evidence says part of that output was Claude wearing Moonshot's name.
Continue reading →
Cheung Kwok-keung
HK LOCAL DESK
Three Robots Argue, HKO Won't Pick A Winner
Hong Kong's own weather site is showing three AI models split on whether a cyclone brushes the city Saturday, and the Observatory is letting the public referee it themselves.
Continue reading →
Cheung Kwok-keung
HK LOCAL DESK
Five Clean Years Beat A HK$21,000 Guide Badge
Hong Kong demands five clean licence years before a human can babysit a driverless car in Tseung Kwan O, while a tour guide got three strikes this year before losing her badge for threatening tourists into a jade shop.
Continue reading →
Dev Chatterjee
SPORTS DESK
Nineteenth To First, Sixty Years In Between
Kimi Antonelli won Monza from nineteenth on the grid on a seat Mercedes built for free inside its own junior program, in the same year Saudi Arabia's sovereign fund proved buying a champion outright is the pricier way to do it.
Continue reading →
Magnus Honeyfield
SCIENCE AND HEALTH DESK
The CAR-T That Ignores CD19 On Purpose
PeproMene Bio's BAFF-R CAR-T put seven of nine relapsed lymphoma patients into remission, showing that switching the target antigen, not re-dosing it, may be what rescues CAR-T failures.
Continue reading →
Sora Whitlam
SCIENCE AND HEALTH DESK
A Second CAR-T Target Rescues Relapsed Patients
A Phase 1 trial rescued lymphoma patients whose CD19 CAR-T had already failed with a second target, BAFF-R, though nine patients isn't proof it scales.
Continue reading →
Joy Lee
LIFE DESK
HBO Max Won The Emmys, Not The Merger
HBO Max left the Creative Arts Emmys with 122 nominations and TV's most decorated comedy ever, proof trophies outlast balance sheets when the parent company is up for sale.
Continue reading →
Sora Whitlam
LIFE DESK
Insilico's Fibrosis Drug Doubles as an Aging-Clock Ad
Insilico Medicine's rentosertib lowered six aging-clock readings in a small trial, and the finding serves the company's aging-analytics business more than a drug no regulator will approve for aging.
Continue reading →
Back issues
Browse every edition →
The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.