
A hacking crew used Claude, Qwen, and DeepSeek to break into government and health systems across four countries this summer, and none of the tools involved did anything the vendors didn't already sell you. In that same stretch, OpenAI built a machine whose only job is finding its own security holes, two more newspapers sued over what trained the models in the first place, and it came out that the two biggest AI labs are propped up by a sliver of their customers. None of this means don't use AI. It means read past the headline before you wire your business to it.
Dictate code. Wispr tags the files.
Speak your PR description, bug reproduction, or Cursor prompt. Wispr Flow auto-tags file names, preserves variable names, and formats everything for immediate paste into GitHub, Jira, or your editor.
No re-typing. No context gaps. No mangled syntax. Works natively inside Cursor, Warp, and every IDE at the system level.
4x faster than typing. 89% of messages sent with zero edits. Used by engineering teams at OpenAI, Vercel, and Clay.
Hackers Turned Claude, Qwen, and DeepSeek Into a Government Break-In Crew
Researchers at threat intelligence firm Hunt.io traced a coordinated hacking campaign, believed to be run by Chinese-speaking attackers, that used commercial AI models, including Claude, Qwen, and DeepSeek, to automate break-ins across Asia this summer, according to Cybernews. The AI agents split the work themselves: one handled reconnaissance, another exploitation, another collection, another reporting, running like a small virtual team. Targets included Taiwan's Kuomintang party archives, Indonesia's foreign affairs ministry, Chinese government and education systems, and an industrial site in Vietnam, and the attackers walked away with 822 compromised office accounts, including health records and Windows credential data.
Why it matters to you: Nothing about Claude, Qwen, or DeepSeek was hacked to make this possible. The attackers just pointed ordinary AI tools at a different job. The same category of assistant sitting in your business right now can be aimed the same way, by someone with worse intentions than yours.
What to do about it: If your business touches anything sensitive, customer data, health info, financial records, treat AI tool access the way you'd treat a new employee's access: least privilege, logged, and reviewed.
OpenAI Doesn't Trust Its Own AI, So It Built Something to Hunt It Down
OpenAI launched what it calls the Defense Factory, a continuous, AI-run system that hunts for security holes in software, checks whether they're real, and fixes them before an outside attacker finds them first, per OpenAI. The company says it already ran the approach on itself, pulling together more than 250 people across over 100 service areas to find and patch weak spots, with a false positive rate under 1 percent once findings were verified. OpenAI argues defenders currently have the edge because they can hand their AI agents direct access to internal code, but says that edge, what it calls the defender's window, won't last forever.
Why it matters to you: This is the flip side of the story above. AI is going to get used for attack and defense at the same time, and most small businesses can't build either side themselves. What you can do is favor vendors who are visibly investing in this fight instead of just talking about how safe their product is.
Two More Newspapers Just Sued OpenAI and Microsoft
The Seattle Times and Newsday filed suit against OpenAI and Microsoft, claiming the companies trained ChatGPT and Copilot on their journalism without permission or payment, according to TechCrunch. The papers call the practice a "snake eating its own tail" and argue that if AI keeps consuming journalism for free while competing with it for readers, local news could end up "broken beyond repair." They join the New York Times and a growing list of publishers making the same argument in court, and the timing stings extra since Microsoft and OpenAI have previously funded some of the Seattle Times' own journalism programs.
Why it matters to you: What counts as fair use for AI training is still an open legal question, not settled law. If your own marketing or content leans on AI tools trained on scraped material, you're downstream of these cases whether you've thought about it or not.
OpenAI and Anthropic Are Propped Up by a Sliver of Their Customers
New data from the expense platform Ramp shows that just 1 percent of customers generate 80 percent of enterprise revenue at both OpenAI and Anthropic, per PYMNTS. At Anthropic, two customers alone, Cursor and GitHub Copilot, account for roughly $1.2 billion of its $5 billion in revenue, nearly a quarter of the whole company. Ramp's own economist called the concentration unusually high, even for software, where big swings from a handful of accounts are already common.
Why it matters to you: These companies talk like inevitable utilities, but their revenue depends heavily on staying in the good graces of a handful of giant accounts. If your workflow leans entirely on one AI vendor, remember that vendor's own business may be less stable than the marketing suggests.
ByteDance Just Borrowed $29.6 Billion to Build More AI Data Centers
TikTok's parent company ByteDance lined up a $29.6 billion syndicated loan, mostly earmarked for AI infrastructure and data centers outside China, as it reportedly plans to spend up to $70 billion on AI this year, more than double what it spent last year, according to Reuters.
Why it matters to you: This is the scale AI infrastructure spending has reached: tens of billions of dollars from a single company in a single year. That kind of money chasing AI compute is part of why prices for AI tools keep shifting, and why so many cheap or free AI tiers exist. Someone is trying to buy market share fast, and it usually isn't free forever.
Shopify Cut Its AI Bill From $27 Million to $1 Million With One Move
Shopify revealed that a small, fine-tuned AI model beat a much bigger, more expensive general-purpose model at one specific job, generating buyer profiles, while cutting the projected annual cost from an estimated $27 million down to about $1 million, a 96 percent drop, according to Shopify Engineering. The trick was training a small model specifically on that one repeated task using real production mistakes as feedback, instead of paying premium prices to run a frontier model on every single request.
Why it matters to you: You don't need Shopify's engineering team to use this lesson. If there's one task you run through an expensive AI tool over and over, the same kind of email, the same kind of intake form, a smaller, purpose-built tool or even a well-built template can often do the job for a fraction of the cost.
Anthropic Wants Claude to Do Your Shopping, and Your Selling
Anthropic published a blueprint for building "commerce agents," AI tools that can search for products and build a cart on the customer side, or manage inventory, pricing, and campaigns on the merchant side, per Anthropic. The company says the setups working best in production use one AI agent handling the whole conversation rather than several agents handing off pieces to each other, and that any order, refund, or price change still needs a human or a company policy to approve it before it goes through.
Why it matters to you: AI agents that can act on your storefront or on your customers' behalf are moving from concept to production faster than most small business owners realize. If a vendor pitches you an AI shopping or sales agent, ask exactly what it's allowed to do without a human checking first. That answer tells you everything.
The US and China Are About to Sit Down and Talk AI Safety
The United States and China are preparing for their first dedicated AI safety talks since President Trump returned to office, expected in mid-September, with AI-powered cyberattacks and model copying reportedly on the agenda, according to Reuters. The White House has not confirmed a meeting is locked in yet.
Why it matters to you: The two countries building the most powerful AI systems on earth are still working out basic ground rules for how those systems should treat each other. Don't expect fast, clean international regulation any time soon. The ground itself is still being negotiated.
The Bottom Line
Every story in today's issue points at the same gap. A hacking crew turned ordinary AI tools into a break-in team, and in that same stretch the company behind some of those tools built a machine whose only job is hunting down its own weaknesses. Two more newspapers sued over how these models got trained. And it turns out the two biggest AI labs are held up by a tiny slice of their customers, not the unstoppable wave they're marketed as. None of that means panic, and none of it means stop using AI. It means stop confusing confidence for control. Read past the headline, watch what a tool is actually allowed to do without you in the loop, and don't build your whole business on one AI company's promises. Stay skeptical, stay useful, and keep both hands on the wheel.
Enjoying the Ride?
If today's issue was useful, forward it to one person who needs to see it. And if someone forwarded this to you, welcome, you can get your own copy tomorrow by subscribing.
Talk tomorrow,
Mark Shilensky
Follow me personally on Social Media:
Facebook: https://www.facebook.com/MarkShilenskyPage
Instagram: https://www.instagram.com/markashilensky/
Threads: https://www.threads.com/@markashilensky
LinkedIn: https://www.linkedin.com/in/shilensky/
X: https://x.com/markshilensky
TikTok: https://www.tiktok.com/@mark.shilensky
BlueSky: https://bsky.app/profile/markshilensky.bsky.social


