- Cybersecurity Docket
- Posts
- Anthropic left details of unreleased AI model in unsecured database
Anthropic left details of unreleased AI model in unsecured database
Plus, Team Cymru research warns that exposed ICS and OT devices targeted by nation-state actors raise critical infrastructure risks.

SPONSORED BY

Good morning! Here’s what’s up.

Clips ✂️
Exclusive: Anthropic left details of unreleased AI model, exclusive CEO event, in unsecured database
AI company Anthropic has inadvertently revealed details of an upcoming model release, an exclusive CEO event, and other internal data, including images and PDFs, in what appears to be a significant security lapse.
The not-yet-public information was made accessible via the company’s content management system (CMS), which is used by Anthropic to publish information to sections of the company’s website.
In total, there appeared to be close to 3,000 assets linked to Anthropic’s blog that had not previously been published to the company’s public-facing news or research sites that were nonetheless publicly-accessible in this data cache, according to Alexandre Pauwels, a cybersecurity researcher at the University of Cambridge, who Fortune asked to assess and review the material.
After Fortune informed Anthropic of the issue on Thursday, the company took steps to secure the data so that it was no longer publicly-accessible.
Following last month’s post highlighting its capabilities for protecting ICS (industrial control systems) and OT (operational technology) environments, Team Cymru published new research examining three case studies that reveal the extent of exposed ICS and OT devices known to be targeted by hostile nation-state actors. The findings underscore a critical concern: many of these systems remain directly exposed and vulnerable to exploitation.
Through this research, Team Cymru aims to reinforce awareness that critical national infrastructure systems are still at risk, while demonstrating how its data can help organizations identify exposures, mitigate threats, and prevent adversary pre-positioning and potentially destructive cyberattacks.
…
“Best practices in industrial cybersecurity dictate that ICS devices should never be directly exposed to the public internet. The fact that thousands of unique IPs are being detected as targeted means that many organizations are still struggling with IT/OT convergence, leaving critical infrastructure dangerously exposed to remote cyberattacks, ransomware, or state-sponsored disruption.”
Cyber Incidents: Share Price Response Immediate and Sustained
[A] joint study (available for download) by ISS STOXX and ISS-Corporate recently examined just how much one type of bad news – reporting a cyber incident – impacts a company’s stock price. You might be surprised at what the summary refers to as the “depth and duration of damage.”
The study examined the impact of reported cyber incidents on share values across the U.S. Russell 3,000 index from 2022 through 2024. They found that, “while share price underperformance manifests quickly, it is also sustained and builds over time.”
Specifically:
• [F]irms reporting significant cyber incidents underperform the market (as measured by share price) by nearly 5% on average.
• This study confirms continued share price underperformance at one full year after incidents are first reported, with a peak negative average impact of nearly -4.9% after 250 trading days.
• The Finance and Banking sector, as well as the Health Care sector, show higher negative average impacts to relative share price in the months following a reported cyber incident (peaking at -8.5% and -8.3%, respectively).
Those two industries also experienced the majority of the total incidents in the three-year period.
Hackers now exploit critical F5 BIG-IP flaw in attacks, patch now
Cybersecurity firm F5 Networks has reclassified a BIG-IP APM denial-of-service (DoS) vulnerability as a critical-severity remote code execution (RCE) flaw, warning that attackers are exploiting it to deploy webshells on unpatched devices.
BIG-IP APM (short for Access Policy Manager) is a centralized access management proxy solution that enables admins to secure and manage user access to their organizations' networks, cloud, applications, and application programming interfaces (APIs).
Tracked CVE-2025-53521, this security flaw can be exploited by attackers without privileges to perform remote code execution when targeting BIG-IP APM systems with access policies configured on a virtual server.
"F5 strongly recommends that you consult your corporate security policy for guidelines about incident handling procedures including but not limited to forensic best practices, that are specific to your organization. More specifically, review the policies to ensure that they comply with evidence collection and forensics procedures for a security incident before you attempt to recover the system," the company added.
Trivy Supply Chain Breach Ripples Through CI/CD Ecosystems
According to Mandiant, over a thousand SaaS environments have been impacted by ongoing supply chain compromises of Aqua Security's open-source scanner Trivy, and researchers predict that the impact may grow by an order of magnitude.
In late February 2026 a threat actor's autonomous AI-powered bot stole one or more personal access tokens (PAT) that were then used through March to push malicious Trivy container images and force-push GitHub Actions version tags to commits that execute "TeamPCP Cloud stealer" when opened. Malicious Trivy images were also published to Docker Hub.
The malware scrapes a wide range of credentials, harvests cloud metadata, enumerates Slack and Discord webhook URLs, and exfiltrates the stolen secrets.
…
The SANS Institute's Kenneth G. Hartman and Eric M. Johnson urge users to immediately pin every GitHub action to a full commit Secure Hash Algorithm; audit every workflow that uses the pull_request_target trigger; rotate any possibly exposed credentials across all affected services; and search for exfiltration indicators to verify compromise.
Security leaders say the next two years are going to be 'insane'
Every RSA Conference has its buzzwords. Cloud. Ransomware. Zero trust. Plastered across the 87-acre Moscone Center complex on every booth, banner and bar. This year was AI, with vendors pitching AI-powered solutions to every security problem imaginable. But 2026 stood out for a different reason: Industry leaders spent the conference warning about disruption from the very technology everyone was selling.
In an exclusive discussion with CyberScoop at this year’s conference, Kevin Mandia, founder of AI security company Armadin, Morgan Adamski, former executive director of U.S. Cyber Command, and Alex Stamos, a researcher and former chief security officer at several major technology companies, said the industry is entering what they described as an unprecedented two- to three-year period of upheaval, driven by AI systems that are discovering vulnerabilities exponentially faster than defenders can respond and threatening to render decades of security practices obsolete.

SPONSORED BY

Incident Response Forum D.C. 2026 is set for Wednesday, April 22, 2026, at the historic Mayflower Hotel in Washington, D.C.!
Incident Response Forum is the only conference of its kind, bringing together hundreds of cybersecurity and incident response attorneys, in-house counsel and compliance executives, and other top professionals in the field. It is focused solely on the field of Incident Response – the work that begins after a data breach that has quickly become the fastest growing practice area at law firms and consulting firms – and is geared specifically for the legal and compliance professionals who have emerged as critical players during the aftermath of a data security incident.
Join us in person or tune in virtually to hear from nearly 50 luminaries in the incident response field—including senior officials from the DOJ and FBI, and lawyers and consultants from the best firms and in the world.
👉 Please register here.
