China-Linked Hackers Exploit AI Tools in Government Cyberattacks
A threat-intel report just put Claude Code in the malware toolbox
Cato CTRL published a report in May documenting a malware family called TencShell and tied it to a suspected China-based threat actor. The follow-on coverage is the part that matters: the operator had wired Anthropic's Claude Code and DeepSeek-v4-pro directly into an active intrusion campaign against government entities, Taiwanese industry, and financial-services organisations, and a shared HTTP-header fingerprint on port 111111111111 was the breadcrumb that stitched the cases together. (IT Security News, 2026-07-15)
The news is not "AI is dangerous." Anything with a text box can be misused.
This is an excerpt. Read the full post at otf-kit.dev/blog/ai-tools-in-cyberattacks — full-stack kits your AI coding agent can actually ship to production. Browse the kits →
Ship the product, not the setup.
- 11 production screens — auth, billing, team, analytics, settings
- Real database, payments, and login — all wired on day 1
- AI configs pre-tuned so your agent extends instead of regenerates