TigerTiger tiger holding a padlock

What changed

Anthropic just published what criminals are doing with Claude

The report covers December 2025 to August 2026. Its headline finding is that the tools have closed the gap between state-backed groups and people working alone. You no longer have to be sophisticated to run a sophisticated attack. One operation it describes produced more than 8,900 articles across 70 fake news sites.

Skip the espionage sections. Three patterns are worth your attention.

1. Your AI logins are worth stealing. Treat them like the keys to your bank, not like a Netflix password. Stolen keys get resold, then used on the accounts they came from.

2. The way in was often a supplier. Several breaches reached their target through a vendor who was compromised first.

3. A single login becomes full control, fast. One case went from a stolen developer token to full administrative access in about three hours.

Try: open a note and list every place an AI login of yours is stored. A teammate's laptop, a shared spreadsheet, an automation tool you set up once and forgot. Bring that list to whoever handles your accounts this week and ask them to replace any you can't account for.

Your AI costs can finally match your admin's numbers

This one is for companies running their own shared Claude gateway. Whoever set it up can now publish the real rates to everyone using it, so the running total you see comes from the same numbers as the spend meter your admin watches.

That ends a specific argument, the one where somebody reports what a piece of work cost, the admin's dashboard says something else, and nobody can explain the difference.

Try: ask whoever set up your company's AI access one question, whether your team runs its own Claude gateway. If it does, ask them to switch on published rates, so the cost figures your people see match the meter they track.

You can sketch at ChatGPT now, instead of describing

ChatGPT Images 2.5 landed on 8 September. You can now draw a rough shape directly in ChatGPT and have it build from that, which beats hunting for words to describe a layout.

Three other ways to ask came with it. You can start from a format like a poster or a product photo. You can point at one part of an image and comment on it, the way you would mark up a document.

Editing is also more reliable. Ask it to change one thing and the rest of the picture usually stays put, which is the part that used to make this so frustrating.

Three Gemini releases since July, and a reason to sit still

Gemini 3.8 Flash arrived on 2 September, after updates on 21 July and 13 August. Each one came with benchmark scores showing it ahead of whatever shipped before it.

None of that is a reason to move your team. The cost of switching is never the subscription, it's the month your people spend relearning where everything is and rebuilding the habits that made the last tool useful. A model that scores a little higher on a test somebody else designed doesn't cover that.

The teams getting value out of AI right now are mostly the ones who picked something reasonable a year ago and got good at it.