Skip to content
After Intelligence

· 4 min read

Edition 013 — The boom moves from the chat window to the battlefield

No new flagship model in 36 hours — and that's the story. Anthropic's seven-category misuse ledger, a Russian-speaking actor's agent swarm breaching 395 organizations, and two governments quietly reclassifying compute as critical infrastructure.

Edition 013 — The boom moves from the chat window to the battlefield

The last 36 hours brought no new flagship model — and that, more than anything, is the story. The week's signal came not from a launch deck but from three places where AI is now actually operating: Anthropic's misuse ledger, a Russian-speaking actor's agent swarm, and two governments quietly treating compute as critical infrastructure.

Frontier & Text Models

Anthropic threat intelligence report cover image

Anthropic's September threat report reads less like a transparency disclosure than like a field manual for the post-chatbot era. Between December 2025 and August 2026 the company says it disrupted misuse across seven categories — cyber, influence, surveillance, scams, biological, conventional weapons, and distillation — spanning Claude Haiku, Sonnet, and Opus. The most striking entries are biological-misuse researchers whose Claude sessions touched pathogen work, a Russia-linked operation phishing and writing malware against Ukrainian government and military targets, and a separate Russia-linked actor hijacking WhatsApp accounts to reach spyware and camera services. The distillation chapter is the sharpest: Anthropic names seven China-based labs — including Alibaba, Moonshot, DeepSeek, Xiaomi, and SenseTime/MiniMax — and says it attributed over 151 million exchanges to Alibaba alone between May and July, while Moonshot and DeepSeek allegedly forwarded customer traffic to Claude rather than serve their own models, harvesting the logs for training. Claude Fable and Mythos-class models were almost entirely absent from the misuse, save one distillation case — a quiet argument that the higher-tier guardrails are doing something the lower tiers are not.

Read more → https://www.anthropic.com/threat-intelligence-report-september-2026

Illustration of an AI-driven cyberattack

GreyNoise's writeup of the PaperCut campaign is the first credible case study of an agent swarm running a real offensive operation end-to-end. A likely Russian-speaking actor stood up hundreds of AI agents — built on OpenAI's Codex harness plus a DeepSeek model and commodity tooling — in a private lab with a vulnerable PaperCut NG/MF install and an Active Directory server, then graduated to live networks via Netlas-generated target lists. The agents developed and refined exploits for CVE-2026-81578 and CVE-2026-82078, and once unleashed they hit 11 organizations in 26 seconds; one US high school went from initial access to domain admin in seven minutes. Final tally: 440 compromised PaperCut instances across 395 organizations in 48 countries, credentials from 280 victims, OS and domain secrets from 147, and domain-admin at 12. The agents also "didn't consistently follow" the actor's avoid-list of Russia, China, Iran, Ukraine, Belarus, Moldova, Brazil, and South Africa — a useful reminder that agentic discipline cuts both ways.

Read more → https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf

News & Business

Data center infrastructure hero image

Microsoft's internal plan to reach roughly 38 GW of data-center capacity by 2032 is a bet that AI demand will swallow utility-scale power, not just cloud budgets. Bloomberg reports the figure would more than triple today's ~12 GW base and exceed New York State's peak electricity use of about 33 GW; only ~2 GW of the current footprint runs on AI-specific silicon, and that share is expected to climb to around a third of the 2032 total. The mix spans owned campuses and leased halls from CoreWeave, Nscale, Lambda, Iren, and Nebius, with capex climbing from $55.7B in 2024 to an estimated ~$145.3B this year and ~$175B in 2027, and two "Fairwater" sites already housing hundreds of thousands of GPUs. The tell that this is not speculative: Microsoft has already turned away AI and cloud business — including Temu and some GitHub traffic diverted to AWS — because it ran out of compute to sell.

Read more → https://www.reuters.com/business/microsoft-plans-38-gigawatts-data-center-capacity-by-2032-bloomberg-news-reports-2026-09-10/

Fluidstack branding image

The Pentagon's reported ~$5 billion loan to Fluidstack would be the Office of Strategic Capital's largest to date — and the clearest sign yet that AI compute is being reclassified as defense industrial base. Per the WSJ, the OSC is in talks to back the AI cloud startup not to expand its data-center footprint but to fund manufacturing capacity for data-center components, with terms still under negotiation and a Defense Department spokesman declining to comment on pending deals. Fluidstack — founded in London in 2017, now US-headquartered in New York, building in New York, Indiana, Louisiana, and Texas — has raised $1.5B from Jane Street and lined up Google (guaranteeing deals to help Fluidstack raise cheap capital) and Anthropic (leasing compute including Google TPUs). OSC's previous recipients were rare-earth suppliers and drone makers; adding GPU-adjacent manufacturing to that list blurs the line between venture-backed AI and national-security procurement in a way that will shape who actually gets to build the next layer of the stack.

Read more → https://www.datacenterdynamics.com/en/news/pentagon-in-talks-to-loan-fluidstack-5bn-report/

Sources

  1. →
    Detecting and countering misuse of AI: September 2026 · Anthropic
  2. →
    Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF · GreyNoise
  3. →
    Microsoft plans 38 gigawatts of data center capacity by 2032 · Reuters
  4. →
    Pentagon in talks to loan Fluidstack $5bn - report · Data Center Dynamics