Today in AI: AI-Powered Cyberattacks Scale, Prompt Injection Expands OWASP Top 10 — September 11, 2026

September 11, 2026 — curated links and takeaways.

1. Attacker Used AI Agents to Hack 395 Organizations via PaperCut Print Flaws

A single attacker weaponized OpenAI's Codex and a DeepSeek model to automate exploitation of PaperCut vulnerabilities across 395 organizations starting August 31, 2026. This signals that commodity AI agents now compress reconnaissance, exploitation, and privilege escalation from hours to minutes—forcing practitioners to adopt pre-authorized isolation and aggressive internet-exposure reduction as baseline controls.

2. Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion

Anthropic's September 2026 threat intelligence report documents Russian criminal groups targeting AI vendors' infrastructure directly, including attempts to steal pre-release Claude models. Practitioners building on third-party AI platforms now face secondary supply-chain risk where adversaries attack the vendors themselves.

3. The New OWASP GenAI Top 10 and Why Network Security Matters

OWASP's 2026 GenAI Top 10 redefined Prompt Injection to explicitly cover multimodal inputs, persistent memory, RAG tool outputs, obfuscated payloads, and cross-session propagation. Developers must expand validation beyond text-only injection patterns and enforce isolation between LLM sessions and vector stores.

4. 6 TB of data leaked from Chinese LLM router, exposing secret keys

An unpatched Chinese LLM router exposed 6 TB of request logs containing active API keys for Anthropic Claude and other models. Organizations routing requests through third-party routers now face credential leakage at rest; practitioners must assume any key sent through external infrastructure can be compromised.

5. Detecting and countering misuse of AI: September 2026

Anthropic's September 2026 threat report covers 4 separate unauthorized access incidents to Claude models and documents disrupted misuse cases spanning biological weapons research, espionage, and credential theft from December 2025 through August 2026. This establishes that frontier models remain targets for state and criminal actors regardless of safety layers.