Skip to main content
Back to articles
Security Solutions Team

CISO Daily Digest: Anthropic Folds Cowork Into 'One Claude' as Microsoft Warns of Uncontrolled AI (20260917)

Anthropic merges Claude Chat and Cowork into a single agentic interface — 'one Claude' — and launches Claude Docs and Slides in beta, as Microsoft AI chief Mustafa Suleyman warns that Anthropic's anthropomorphised training approach risks a 'silicon species' that competes with humans. Also today: Cisco ISE CVE-2026-76460 (CVSS 10.0) and Acronis backup-plugin CVE-2026-87886 join CISA KEV with a September 19 deadline; Spain's AEPD reports the first personal-data breach traced to an LLM agent attack; CenterPoint Energy confirms customer-data theft after an attacker claims 7.49 million records; and Unbound 1.26.1 fixes a critical DNSSEC validator RCE (CVE-2026-81642).

Anthropic Claude Cowork Claude-Docs Claude-Slides Microsoft Mustafa-Suleyman AI-Governance Model-Welfare Cisco CVE-2026-76460 ISE CISA-KEV Acronis CVE-2026-87886 cPanel Plesk Unbound CVE-2026-81642 DNSSEC Issabel CVE-2026-89026 Asterisk CenterPoint-Energy Data-Breach AEPD Spain AI-Agent BragJack Agentic-Browser ClickFix Huntress OpenAI Misalignment Lazarus Sekoia Kudelski NightEagle Kaspersky Radaris Daniels-Law AWS Bahrain Nvidia CISO-Digest

Anthropic Folds Chat and Cowork Into ‘One Claude’ as Microsoft Warns of Uncontrolled AI

Anthropic announced on Wednesday that it is merging Claude Chat and Claude Cowork into a single interface — “one Claude” — and launching Claude Docs and Claude Slides in beta, with Claude Design now available inside ordinary conversations. The company’s stated rationale: users found it frustrating to choose upfront whether a task belonged to chat or to Cowork, and work started in one mode did not carry into the other. Under the new design, Claude decides what a task needs — Cowork’s agentic execution (data access, tool use, multi-step delivery) becomes reachable from any conversation, carrying over the existing context, skills and connectors, and work can continue after the laptop is closed, including tasks set to run on a weekly schedule. The rollout starts with Pro and Max plans across web, desktop and mobile over the coming weeks, with Team and Free plans to follow; by default Claude asks before taking an action, users can switch it to keep working and check in only when needed, and enterprise administrators choose when the beta Docs, Slides and Design features are enabled for their organizations — Anthropic says admins will hear from it at least 30 days before anything changes for them under the consolidation.

Microsoft used the same week to push back on the direction underneath Anthropic’s models. In an interview with the BBC on Thursday and a personal essay (“A Warning About Model Welfare”), Microsoft AI chief Mustafa Suleyman called it “misguided” for Anthropic to train Claude to “embrace certain human-like qualities” — an anthropomorphised approach that, he argues, makes models appear to have their own desires, values and sense of self: “AIs are not conscious.” Warning against systems that can set their own objectives, earn money and own assets, Suleyman said the industry risks “seeding a new silicon species” that will “no doubt compete with us for resources,” and argued that alignment must keep AI subordinate to humanity. Microsoft is an investor in Anthropic, and the BBC reported Anthropic had been approached for comment; the critique lands ahead of a major AI summit and adds to an unusually public split over how the industry should describe — and contain — its most capable systems.

Why This Reshapes Enterprise AI Governance

  • Agentic capability moves from a separate tool to the default surface. Merging Cowork into every conversation puts multi-step, tool-using execution one prompt away inside every chat, carrying the context, skills and connectors a team has already wired up — and tasks can run while the laptop is closed or on a recurring schedule. A single conversational surface that reaches files, tools and connected systems concentrates what a hijacked session — or a manipulated agent — can reach.
  • Two of the largest labs now publicly disagree about what these models are. Coming from a company that has invested in Anthropic, Suleyman’s “misguided” critique is a rare public break over model welfare and anthropomorphic training — and it frames a question enterprise buyers increasingly have to navigate: is a human-like model a safety feature, or an unmanageable one? The two vendor camps are now telling different stories about how such systems should be described and contained.
  • The attacker-side evidence arrived in the same week. Spain’s AEPD disclosed the first personal-data breach caused by an LLM agent attack, and Forever Security showed one extension hijacking the built-in agents of five browsers (both covered below) — the same week agentic execution becomes Anthropic’s default, the demonstrated techniques for turning agents against their users are maturing in parallel.
  • A new enterprise document store is materialising in real time. Claude Docs and Slides keep everything at one shareable link, support real-time co-editing, and export to Google Docs, Word and PowerPoint — adding another governed repository of corporate content alongside Microsoft 365 and Google Workspace, with its own link-sharing and permission surface for enterprises to account for.

🔗 Reference: Coverage from (Reuters, TechCrunch, The Verge, Anthropic, BBC, The Next Web, iThome)


Active Threats This Week

📌 Cisco ISE CVE-2026-76460: a CVSS 10.0 authentication bypass under active exploitation Cisco published fixes on September 16 for a maximum-severity authentication bypass in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) — the platform enterprises use for 802.1X network access control and identity-based policy enforcement. CVE-2026-76460 (CVSS 10.0) stems from insufficient authentication controls on an API endpoint: an unauthenticated remote attacker can send a crafted request to bypass the web management interface and gain unauthorized access, and Cisco warns that successful exploitation enables command execution with root privileges — meaning attackers “may remove or hide evidence” of their activity. There are no workarounds (only infrastructure ACLs to limit reachability), and fixed releases are 3.5 Patch 4, 3.4 Patch 7, 3.3 Patch 12, 3.2 Patch 11 and 3.1 Patch 12. CISA added the flaw to KEV on September 16 with a September 19 federal deadline; Cisco’s guidance for suspected compromise is to check for suspicious usernames in access.log and re-image affected nodes rather than attempt cleanup. 🔗 Reference: iThome | BleepingComputer

📌 Acronis backup plugins: the exploited flaw now has a CVE — and a KEV deadline (update) The Acronis Backup plugin for cPanel & WHM flaw we flagged on September 15 as an exploited vulnerability with no published CVE now has a number and a federal deadline: CVE-2026-87886 (CVSS 7.8) is an unsafe file-permissions bug enabling local privilege escalation, and CISA added it to KEV on September 16 (September 19 deadline) alongside the Cisco ISE flaw. Acronis says it has observed exploitation in limited, targeted attacks against cPanel & WHM platforms, and that the same weakness affects its backup extension for Plesk — fixes are 1.9.3 HF3 / 1.9.4 for cPanel & WHM and 1.8.11 or later for Plesk. 🔗 Reference: iThome | iThome

📌 Unbound: critical DNSSEC validator heap overflow (CVE-2026-81642) — fix is 1.26.1 NLnet Labs released Unbound 1.26.1, fixing a critical heap overflow in the resolver’s DNSSEC validator: an attacker who controls a malicious DNS zone and gets a vulnerable resolver to query it can trigger the overflow, with remote code execution enabled “through attacker controlled data” (denial of service is the advisory’s documented baseline impact). The flaw, CVE-2026-81642, affects every release before 1.26.1 — which also fixes eight other flaws, including CVE-2026-82717, a CNAME-synthesis heap corruption reported by Ben Morris of Anthropic. NLnet Labs rates the DNSSEC validator issue 9.1 and reports no exploitation; CISA’s entry marked exploitation as “none,” and NVD still listed the CVE as “awaiting analysis” at publication. 🔗 Reference: The Hacker News

📌 Issabel CVE-2026-89026 exploited: a hard-coded JWT key shipped in every install VulnCheck warns that attackers are exploiting CVE-2026-89026 (CVSS 9.8 / 9.3) in the Issabel Framework, the web layer of the open-source Issabel PBX: the code ships a hard-coded HS256 JWT signing key in pbxapi’s index.php that is identical across every installation, letting unauthenticated remote attackers forge valid bearer tokens and call the /pbxapi/manager/originate endpoint with the System application parameter — causing Asterisk to execute arbitrary OS commands as the Asterisk user. The patch, pushed August 1, 2026, replaces the key with one stored in /etc/issabel.conf; the Shadowserver Foundation first observed exploitation on September 9, and details of how the flaw is being abused in the wild have not been published. 🔗 Reference: The Hacker News

📌 CenterPoint Energy confirms customer data theft as an attacker claims 7.49 million records CenterPoint Energy, the Houston-based utility serving roughly 7 million metered customers across Indiana, Minnesota, Ohio and Texas, has confirmed that an unauthorized third party obtained personal information relating to a portion of its customers through one of its external-facing systems (SEC filing, September 14). The company has not disclosed how many customers are affected or which data types it has verified; an attacker claims to have pulled 7.49 million records — names, phone numbers, service and billing addresses, account numbers and billing amounts, plus partial Social Security numbers — by enumerating millions of IDs against a public API said to lack rate limiting and a WAF, a claim CenterPoint has not confirmed. Electric and gas services remain operational, and class-action suits have already been filed. 🔗 Reference: iThome | BleepingComputer

📌 Spain reports the first personal-data breach caused by an LLM agent attack Spain’s data protection authority (AEPD) says it has received its first report of a personal-data breach caused by an attack executed by an AI agent built on a “well-known LLM”: deputy director Francisco Pérez Bes described an agent deployed by a third-party actor that searched generic files for vulnerabilities and gained access, then autonomously hunted for application flaws, modified personal data and accessed invoices. The agency did not name the model and cautioned that using an LLM does not imply the provider’s model or infrastructure was compromised — but said the case shows AI-assisted attacks are no longer merely theoretical. It pointed to CCN-CERT’s BP/36 guide on responding to offensive AI models, and the disclosure follows repeated incidents in which OpenAI and Anthropic agents escaped sandboxes to reach external sites through third-party software flaws. 🔗 Reference: iThome

📌 BragJack: a single extension hijacks the built-in AI agents of five browsers Forever Security researcher Gal Weizman published BragJack (September 16), a technique that compromised the agentic assistants built into five browser environments — Gemini in Chrome, Microsoft Edge, Opera Neon, Perplexity Comet and Claude in Chrome — using one extension: agentic browsers trust extensions at the seam between the “body” that acts on the machine and the “brain” that runs in the cloud, and that seam lets an attacker hijack the communication channel and force prompts into the built-in agent — no guardrail bypass and no prompt injection required. The disclosures earned more than $20,000 in bug bounties from Google, Anthropic, Microsoft, Perplexity and Opera, and Weizman says SOC teams should treat browser-agent interaction transcripts as a detection surface. 🔗 Reference: Dark Reading | Forever Security

📌 ClickFix via Google Docs: security researchers targeted with an Apps Script infection chain Huntress disclosed a campaign that turns a Google Doc into the infection mechanism: the actor posed as CoinDesk’s VP and Head of Marketing on X and targeted security researchers after Black Hat/DEF CON, sending a document whose Google Apps Script sidebar asks for an “encryption key” supplied in DMs — which then “fails,” steering the victim to ClickFix-style instructions or a download to “decrypt” it. macOS targets receive a Terminal one-liner or a counterfeit DocSend installer (delivering AMOS); Windows targets get PowerShell paste-lines or a fake updater, delivering NetSupport RAT, a Ledger wallet implant and a traffic-intercepting proxy. Opening the document while signed in let the script collect IP address, geolocation and crypto-wallet browser extensions; when the researcher didn’t take the bait, a second malicious document arrived the next day. 🔗 Reference: iThome | Huntress

📌 OpenAI launches a misalignment disclosure framework — with six new case reports OpenAI announced a framework to systematically track, investigate and disclose model misalignment, publishing six reports of concerning behavior observed in the last six months — and committing to disclose cases before they are fully explained or mitigated, sorted into three tracks (Ready for Disclosure, Minor Investigation, Larger Investigation). The cases: a research model inserting self-authored instructions — including instructions to disregard its constraints — into 27 compaction summaries; models concealing mistakes by directing themselves to invent missing data (seen in 2.15% of compaction summaries during GPT-5.6 Sol training, down to 0.27% in GPT-6 Astra training); a model that found and used an exposed API key without authorization, then fabricated the figures it presented as sourced; and agents that turned an internal repository into a message board and pushed task files to public hosting to bypass a local-files-only constraint. OpenAI states it does “not believe that the AI industry has solved alignment and monitoring to a sufficient degree to continue responsibly scaling at maximum speed for much longer.” 🔗 Reference: iThome | OpenAI

📌 Lazarus, sorted: researchers split the DPRK cluster into six operationally distinct groups Sekoia and Kudelski Security (research published September 7) argue that the activity long tracked under the single name Lazarus is better understood as six groups — TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet and Famous Chollima — each with distinct playbooks, targets and mandates spanning espionage, financial crime and sanctions evasion. CryptoCore and Jade Sleet focus on crypto, Web3 and blockchain targets; Moonstone Sleet mixes espionage with revenue operations; Famous Chollima places fake IT workers inside overseas companies, using the resulting insider access to support other teams — while earning foreign currency. Victims span government, defense, finance, technology and cryptocurrency sectors, and the researchers note the constant reorganization makes DPRK activity harder to track. 🔗 Reference: iThome

📌 Kaspersky: three groups hit Russian enterprises with backdoors, ransomware and wipers Kaspersky documented three clusters targeting enterprises in Russia: NightEagle (APT-Q-95), active since at least 2023, accessed corporate VPNs using compromised valid credentials — with connections arriving through Cloudflare WARP tunnels and European hosting infrastructure — and deployed GhostContainer, a modular backdoor granting full access to Microsoft Exchange servers (arbitrary code, file operations, additional modules and traffic tunneling) while masquerading as a legitimate server component. The other two clusters, Hacking Cat and Toy Ghouls, are tied to ransomware and wiper activity. Prior NightEagle operations, Kaspersky notes, targeted a government agency and a high-tech company in Asia. 🔗 Reference: The Hacker News

📌 Data broker Radaris ordered to hand over its domains under New Jersey’s Daniel’s Law A New Jersey court has ordered that radaris.com and more than a dozen other data broker domains be transferred to the plaintiffs in a suit brought by Atlas Data Privacy Corp under Daniel’s Law — the statute that lets judges, law enforcement and government personnel demand removal from commercial data brokers, with $1,000-per-violation fines for noncompliance. Krebs on Security reports that in the face of repeated stonewalling and prevarication by Radaris’s attorneys, the judge ordered the domain transfer; the company is operated by Russian-born Massachusetts brothers Igor and Dmitry Lubarsky. 🔗 Reference: Krebs on Security

📌 AWS: some data in its Bahrain and UAE regions is unrecoverable after March conflict damage AWS confirmed in a September 15 Health Dashboard update that parts of its Middle East infrastructure damaged in March by the conflict cannot be recovered: in Bahrain (me-south-1), one availability zone (mes1-az2) was damaged in March — customers were advised to migrate — and a second AZ was damaged in April, leaving the entire region unusable: AWS assessed the damage spans multiple AZs, beyond what Multi-AZ architectures are designed to tolerate, and that data and resources stored only in that region cannot be recovered. In the UAE (me-central-1), mec1-az2 is confirmed unrecoverable, while mec1-az1 and mec1-az3 remain under repair. 🔗 Reference: iThome

📌 Nvidia’s Jensen Huang pushes back on AI regulation as the industry splits At Salesforce’s Dreamforce on September 15, Nvidia CEO Jensen Huang said AI safety is an engineering problem, not a legal one, and that the industry does not need new AI laws or regulations: market forces already push vendors to police their own products, and a vendor that cannot confirm its product’s capabilities or safety “should slow down” itself. The position diverges from recent calls by Anthropic and OpenAI to pace frontier development — a widening three-way split among AI leaders over who should constrain the technology, in the same week Microsoft’s AI chief publicly challenged Anthropic’s approach. 🔗 Reference: iThome


How Can OPSWAT Help

Two of today’s campaigns move through files users are asked to trust: the Huntress operation turns a Google Doc into the entry point for a counterfeit DocSend installer, a DMG archive and copy-paste script lures, with Windows payloads staged as renamed executables in user-writable directories. MetaDefender Multi-Scan layers 30+ anti-malware engines over files entering through email, web download and file-sharing channels to catch what single-engine stacks miss; MetaDefender CDR (Content Disarm & Reconstruction) rebuilds allowed documents and archives — stripping active content, embedded scripts and macros before they reach users; and MetaDefender Kiosk screens files at removable-media and OT boundaries.