Yazılar

US Says Chinese Hackers Targeted Justice Department, NASA, Federal Reserve and Senate

The United States said it has disrupted a China-linked cyber operation accused of targeting sensitive government agencies including the Justice Department, NASA, the Federal Reserve and the U.S. Senate.

The Justice Department said it seized domains connected to two hacking platforms, QScan and QTRouter, which were allegedly used in cyber campaigns against government institutions, critical infrastructure and private companies.

Authorities linked the platforms to Nanjing Xinjiuwei Network Technology Company, a China-based firm whose clients allegedly included China’s Ministry of State Security and the People’s Liberation Army.

According to U.S. court documents, the hackers have operated since at least 2018, exploiting vulnerabilities to access sensitive networks. Some attempts failed, including an effort to compromise NASA systems in 2019 and unsuccessful attempts against Senate networks in March 2026.

Other operations allegedly resulted in data theft from defense contractors, financial institutions and universities, while additional targets included Energy Department laboratories, the National Institutes of Health and healthcare-related agencies.

China’s embassy in Washington said Beijing opposes cyberattacks and accused the United States of using cybersecurity allegations to discredit China.

The case highlights continued concern in Washington over Chinese-linked cyber campaigns targeting government agencies, telecommunications networks and other strategically important systems.

Anthropic Plans to Give Enterprise Customers More Control Over Data Retention

Anthropic is reportedly preparing changes to its enterprise data retention policy that would give business customers greater control over where sensitive information is stored when using advanced Claude models.

Under the proposed system, enterprise users would still be required to retain data for 30 days, but they could choose to keep that information on their own cloud infrastructure rather than relying solely on Anthropic’s systems.

The company is also expected to introduce a new safety framework later this year. Anthropic has reportedly been working with more than 100 enterprise customers, including Salesforce, to develop the updated approach.

The move follows Anthropic’s earlier decision to require 30-day retention of enterprise traffic on its more powerful Fable and Mythos models, a measure designed to help detect potential cyber misuse.

The policy shift comes as competition intensifies around AI security and enterprise privacy. OpenAI recently announced a safety system designed to identify misuse without retaining customer data, increasing pressure on rivals to offer stronger privacy controls.

China’s Z.ai Says GLM-5.3 Nears Anthropic’s Mythos 5 in Cybersecurity Tests

Chinese AI startup Z.ai says its upcoming open-source GLM-5.3 model is approaching the cybersecurity capabilities of Anthropic’s restricted-access Mythos 5, strengthening its position as a lower-cost challenger in advanced AI development.

According to Z.ai, GLM-5.3 scored 84.5% on CyberGym, a benchmark measuring whether models can review code, identify software vulnerabilities and verify that those flaws are real. That slightly exceeded the 83.8% score Z.ai reported for Mythos 5, although the results have not been independently verified.

GLM-5.3 remained significantly weaker in turning discovered vulnerabilities into working exploits. Z.ai said the model scored 54.4% on ExploitBench, compared with 78% for Mythos 5, while Anthropic’s model also completed more attack-development tasks in timed testing.

Z.ai plans to release GLM-5.3 publicly after additional security assessments, while its most sensitive cybersecurity capabilities will be restricted to verified users through a trusted-access program. The company says it has added safeguards to identify risky requests, monitor model behavior and reject malicious tasks.

The approach reflects growing debate over how powerful cybersecurity AI should be distributed. Z.ai argues that advanced defensive tools should remain accessible to open-source developers and smaller security teams rather than being limited to a small number of closed AI providers.

The company is also launching an Open Source Shield initiative that will use its models to audit selected open-source projects and expand security capabilities in its ZCode programming platform.