Today's briefing
Your staff's AI logins are being stolen, and passwords won't help
Anthropic warned Claude users that malware on their own computers took live login sessions. Plus: Sony sues, ChatGPT ads hit $1B, agents get browsers.
The one that matters
Anthropic tells Claude users: malware on your own computers is stealing live logins
Anthropic has warned Claude users that a number of accounts were compromised by information-stealing malware. The important detail is where the theft happened: not inside Anthropic, but on the users' own computers. The malware collected saved passwords and, more usefully for an attacker, live session tokens. A session token is the small file your browser holds after you sign in that tells a service you are already logged in. Whoever holds that file is you, for as long as it stays valid. No password required, and at that point no one-time code either, because the login already happened.
What this actually means if you run a business
Start with a plain question: what is sitting in your team's AI chat history? At a 600-student school it is probably fee-defaulter lists, parent complaints, draft staff appraisals, and at least one admissions spreadsheet someone pasted in to clean up. At a 30-bed clinic it may be patient summaries reworded for an insurance form. At a workshop with 40 staff it is quotations, supplier prices and margin calculations. Nobody decided those chats would become an archive of the business. They became one anyway.
So an AI account is now a records system that nobody classified as one. It has no retention rule, no access log your office manager ever reads, and very often one shared login used by three people because seats cost money. A rich archive, a session that can be lifted off any infected laptop, and no oversight: that is the exposure here. It has almost nothing to do with artificial intelligence and almost everything to do with the machines your staff use.
What this does not mean
Claude was not broken into. Several headlines this week read as though hackers targeted the platform; they did not. Information stealers are cheap, ordinary malware that has been harvesting browser sessions for years, from banking portals to email. An AI account is simply a newly valuable thing to find on a machine that was already infected. Switching from one AI vendor to another fixes nothing, because the problem is the laptop, not the vendor.
Expect a wave of pitches for AI security platforms, AI posture monitoring and similar products off the back of this. For a business under a few hundred staff, that spending is premature. The fix is unglamorous endpoint hygiene you should already be buying.
What a sensible owner should do this month
- Sign out of all sessions, everywhere, today. Every serious AI tool has a log out of all devices option in account settings. It costs nothing, takes ten minutes, and immediately kills any stolen session.
- End shared logins. Give each person a named account tied to your Google Workspace or Microsoft 365 sign-in, roughly ₹700 to ₹1,500 per user per month in India, CAD $10 to $20 in Canada. Then removing a departing employee actually removes their access.
- Put real endpoint protection on every machine used for work, including the personal laptops your accountant and your marketing freelancer use. Roughly ₹200 to ₹500 per device per month, or CAD $4 to $8.
- Write one page on what must never be pasted into an AI tool. Named student records, patient identifiers, bank details, signed contracts. One page, stuck on the wall, is worth more than a policy document nobody opens.
- Ask your IT person one question: if a staff laptop is infected today, how would we find out? If there is no clear answer, that is your real gap, and this incident is just the first bill for it.
All of that together costs less than one replacement laptop. The archive it protects is worth considerably more than that.
Also worth knowing
-
Sony and Warner sue Anthropic over music used to train Claude
Two of the largest music companies have sued Anthropic over songs used in training, with reporting citing internal staff chats about pirated libraries. This changes nothing about your right to use AI tools this week, but it signals that training-data claims will keep landing in court for years. If your agency generates jingles or background tracks for your ads, keep written proof of what was licensed and from whom.
trendingtopics.eu ↗ -
Ads inside ChatGPT reach a $1 billion annual run rate
OpenAI says its advertising business is now running at a billion dollars a year and expanding to more countries. Practically, that means the answers your customers get from ChatGPT will increasingly sit next to paid placements, and a new ad channel is coming for you to buy. There is nothing to act on yet, but budget for the sales pitch and treat early performance claims with the same suspicion you gave Google Ads in year one.
OpenAI ↗ -
Claude gets its own browser to carry out web tasks
Anthropic has given Claude a browser so it can work through websites rather than just talk about them, aimed at repetitive online chores. The honest framing is that you are handing an automated worker your logins to a portal, so scope it like you would a new temp: one account, one task, limited permissions. Worth a pilot on something low-stakes and boring; not worth pointing at your banking or payroll portal.
eWeek ↗ -
Hidden instruction slipped past the auto-approve mode in Claude Code
Researchers showed a concealed attack getting through the automatic approval setting in Anthropic's coding tool, which is the mode that lets an agent act without asking each time. Most owners will never touch this, but your software vendor might be running exactly that mode against your systems. One question for your next call: which approvals have you turned off, and on which of our servers?
BankInfoSecurity ↗ -
Instagram limits the reach of AI profiles that do not disclose themselves
Instagram is throttling accounts that present AI-generated personas without saying so, after growing user frustration. If your marketing uses a synthetic presenter, an AI avatar or generated influencer content, label it before the platform decides to quietly bury your reach. Disclosure is cheap; rebuilding an account that has been algorithmically demoted is not.
TechCrunch AI ↗ -
Apple underestimated how many people want Mac Minis and Studios for AI
Demand for Apple's small desktop machines has run ahead of supply, driven largely by people running AI models locally rather than in the cloud. For a clinic or a law practice that cannot send client data off-premises, a desktop-sized box costing a few thousand dollars is now a serious option instead of a science project. The catch is staffing: someone has to keep it patched, backed up and updated, and that person costs more per year than the hardware.
Hacker News ↗ -
Japanese municipalities use AI to search their own administrative records
A vendor case study describes local governments in Japan using AI to search and reuse their accumulated administrative knowledge. Discount the public AI infrastructure framing, but note the underlying task, because searching your own pile of documents remains the most reliable AI win available to an ordinary organisation. A school with twenty years of circulars or a factory with a decade of maintenance logs gets more from this than from any chatbot on the website.
OpenAI ↗ -
Microsoft executive asks staff to stop sending him AI-generated filler
A senior Microsoft leader publicly asked employees to stop forwarding him long AI-written documents with little content in them. It is a small story with a real lesson: AI makes producing internal volume free, so the cost lands on whoever has to read it. Set the rule now, before it spreads through your office, that drafting with AI is fine but the sender owns every word and must cut it in half before hitting send.
tech.yahoo.com ↗
How this briefing is put together
Every morning we read the day's AI announcements and reporting from the companies themselves and from the technology press, then pick the handful that actually change something for a working business. The analysis is ours and it is written for owners and managers, not engineers. Every story links to its original source above — read them, and disagree with us where we've got it wrong.