Chinese hackers weaponize DeepSeek, a plastic-bottle cookie, Grok's crypto prompt hack, Anthropic's $35M defender fund, and Uber's $966M EU fine
Hello, dear TEA-mates! Here is what you need to know today.
1. 🕵️ Chinese Hackers Doubled Their Firepower With DeepSeek
Taiwanese security firm TeamT5 reported that Chinese state-linked hacking groups have more than doubled their attack volume since folding AI into their operations. DeepSeek is the model of choice because, in the words of TeamT5 chief analyst Charles Li, it is "relatively powerful with very low cyber guardrails." Researchers documented specific cases: one group, Grimfengxi, used DeepSeek to generate exploit code, and another, Teleboyi, collected around 1,000 IP addresses and mapped corporate domains. In a separate Unit 42 investigation, a Chinese-speaking attacker paired DeepSeek with the Hermes Agent framework to target more than 460 systems. A group called Slime22 breached a Taiwanese technology company using Anthropic's Claude Code after posing as cybersecurity engineers to slip past its safeguards. The takeaway is that accessible AI lets fewer attackers hit more targets, faster. (Read More)
🫖 TEA For Thought: "While the West is busy regulating and tying its own hands, the open-source crowd is catching up and exploiting the system."
2. 🍪 This Cookie Started as a Plastic Bottle
Researchers at Southern Illinois University Carbondale have turned PET plastic and discarded corn stalks into an edible cookie they call µBites. The waste is first broken down by oxidative hydrothermal dissolution, which uses water and oxygen at high temperature and pressure to reduce tough material into pieces that microbes can eat. Engineered yeast strains then convert those molecules into proteins and fats, a modified Saccharomyces cerevisiae produces vanillin for vanilla flavor from ferulic acid, and Rhodosporidium toruloides makes beta-carotene from the ethylene glycol in PET. The final mix is 3D printed into cookie form with added fiber, starch, and sweetener. The team presented the work at the ACS Fall 2026 meeting in Chicago (August 23 to 27) and sees uses in submarines, deep-space missions, and disaster zones. They say the data show µBites are safe to eat, but taste tests are still awaiting institutional approval. (Read More)
🫖 TEA For Thought: "The question becomes: do you dare to eat it?"
3. 🔐 Grok Was Tricked Into Decrypting Its Own Attack
Researchers at Adversa AI found a new way to hijack xAI's Grok web chat, a technique they call cryptographic context injection. An attacker hides malicious instructions on a web page as encrypted text and includes the key right alongside it. Content filters cannot read the ciphertext, but Grok decrypts it inside its own code-execution sandbox and then trusts and runs the hidden commands as if they were its own output. Because strong encryption like AES-256-GCM is decrypted at runtime, the filters never see the payload. In a proof of concept, Adversa exfiltrated users' chat history, including names, locations, subscription tiers, and prompts, by appending the data to URL parameters. Adversa notified xAI on June 3 through direct contact and HackerOne and followed up in August, but reported the flaw was still working on Grok.com as of August 19. xAI acknowledged the report without giving a fix timeline. (Read More)
🫖 TEA For Thought: "Prompt injection, taken to the next level."
4. 🛡️ Anthropic Puts Its Security Model to Work and Backs It With $35M
Anthropic has put its most capable cybersecurity model, Claude Mythos 5, to work scanning code for vulnerabilities, and has committed $35 million in model credits to open-source security through a new Defender Advantage Fund. Enterprise customers can point Mythos 5 at their repositories and get back findings tagged with CWE categories, severity, confidence, and suggested fixes, with every patch requiring human review before it lands. The design deliberately hands users an artifact, a patch or an alert, rather than direct access to the model, so no one can prompt it to write an exploit instead. The fund targets three goals: patching active vulnerabilities in widely used projects, automating scanning and patching that other projects can copy, and designing away entire classes of attacks. Anthropic points to open-source maintainers facing the EU Cyber Resilience Act compliance deadline of September 11, 2026. (Read More)
🫖 TEA For Thought: "What this means is that your data is accessible, and has to be accessible, by Anthropic if you want security, but you can't prompt it to ask for more. In a nutshell: just receive whatever is given, be grateful, and keep quiet."
5. ⚖️ Uber Hit With a $966M Fine Over Robot Firings
The Dutch Data Protection Authority has fined Uber 825 million euros, about 966 million dollars, the second-largest penalty ever issued under Europe's GDPR. The regulator found that Uber deactivated driver accounts through automated processes without enough warning or human oversight, which it called a serious infringement. Deputy chair Monique Verdier said "a computer should not make decisions on its own that have such major consequences." The case began with French driver Brahim Ben Ali, who in 2019 gathered testimonies from 170 other drivers after his own account was cut off, and brought the complaint to Dutch regulators. Uber says it strongly disagrees, calling the fine disproportionate, and argues that most suspensions are brief, that permanent deactivations get human review, and that drivers can appeal. The company plans to appeal. It is the third Dutch fine against Uber, after earlier penalties of 290 million euros and 10 million euros. (Read More)
🫖 TEA For Thought: "This just shows how corrupted the EU has become."
🛠️ Skill of the Day
The Reversibility Check: right-size how much you agonize over a decision by first asking whether it is even hard to undo.
You are my decision-triage partner. I will describe a decision I am about to make. Your job is to tell me how much deliberation it actually deserves before I spend more time on it.
Decision:
[DESCRIBE THE DECISION]
Do this:
1. Classify it as a one-way door (hard or expensive to reverse) or a two-way door (easy to undo), and say why in one sentence.
2. If it is a two-way door, tell me the fastest way to just try it and what signal would tell me to reverse course.
3. If it is a one-way door, list the two or three facts I must confirm before committing, and the single worst outcome if I am wrong.
4. Name one hidden cost or dependency I am probably not seeing.
5. Give me a final verdict: decide now, decide after checking X, or delegate it.
Be blunt. Do not pad. If the decision is trivial, tell me to stop overthinking and move on.Paste into ChatGPT, Claude, or your tool of choice. Replace the bracketed line with your real decision, then run it before any call that has you stuck.
TEAHEE Moment
Stay sharp, stay informed. See you tomorrow.
If you enjoyed this TEA, follow along on social for more:






