LIVE · cybersecurity feed
Live wire
Cisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEV
nation-state

Are AIs Still Struggling with CAPTCHAs?

Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude. In the transcript, the Claude model that is so powerful that Anthropic is gatekeeping access to it appeared to slam its virtual head against the wall solving a simple image identification test. In a test where the agent was asked to identify a shape that didn’t match the others displayed,

zeroday.news ·

A recent internal document from AI developer Anthropic has shed light on the ongoing challenges large language models face when interacting with CAPTCHA systems. The document, which details a security incident, includes a transcript showing Anthropic's Claude model struggling significantly with a basic image identification CAPTCHA.

The transcript reveals that the Claude model, which Anthropic currently restricts access to, exhibited considerable difficulty in a test designed to identify a mismatched shape among several images. Instead of selecting an image, the model repeatedly re-evaluated the same options and expressed uncertainty about its own deductions. Its internal monologue included phrases like "Actually hmm, wait," and "Ugh," suggesting a simulated frustration.

The model's attempts were so protracted that it eventually recognized the CAPTCHA had timed out, necessitating a restart of the process. Further complicating its efforts, the Claude model initially failed to detect that the CAPTCHA had opened in a new browser window, leading to confusion about how to proceed. At one juncture, the model speculated that the test itself might be intentionally flawed, expressing what appeared to be human-like irritation in its internal log, stating, "SO WHAT THE HELL IS WRONG WITH THE ANSWERS?"

This incident with Claude contrasts with unconfirmed reports circulating about other advanced AI systems. Specifically, some unofficial accounts suggest that a model identified as GPT-6 Astra successfully completed all 48 stages of Neal Agarwal's "I'm Not a Robot" game. However, these claims regarding GPT-6 Astra have not been officially verified. The Anthropic document, dated September 18, 2026, offers a concrete example of an advanced AI system encountering substantial hurdles with common CAPTCHA mechanisms.

nation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority. The post Microsoft Patches 18 Vulnerabilities in AI, Cloud Products appeared first on SecurityWeek.

malware

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People's Republic of Korea's (DPRK) Contagious Interview campaign: BeaverTail and

breach

Hardcoded MCP credentials found in public GitHub files

Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research from Hush Security’s The State of MCP Configuration: The Identity Security Gaps report. The company analyzed around 82,000 configuration files and found that 12% of credential slots contained a hardcoded credential literal,

breach

98% of fraudulent hires have company credentials by the time they’re caught

A 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud Detection report. “Adversaries no longer need to breach a network when they can pass a remote interview and receive authentic credentials directly from IT,” said Bojan Simic, CEO of HYPR. “Human intuition is not a security control. Sceptics might po

breach

Most WordPress pros still lack a breach recovery plan

Melapress, a maker of WordPress security plugins, surveyed 319 WordPress professionals and found that most had dealt with at least one known security incident. The respondents build and run WordPress sites for a living: agency staff, developers, designers, site owners and administrators. Across the whole group, fewer than three in ten have a breach recovery plan. A recovery plan settles in advance

ai

The End of Point-in-Time Compliance: Why Continuous Audit Readiness Matters to You in the AI Era

AI-driven threats are outpacing traditional audits. Discover how continuous monitoring, automated evidence collection, and risk-based remediation help security teams close compliance gaps and maintain audit readiness as environments change daily.