Cozy Bear
18
MENTIONS
11
EPISODES
10
PODCASTS
Search complete. 18 mentions across 11 episodes found for "Cozy Bear".
Sep 18, 2026
Is AI the new Ultimate Spy?
N
17:36Neil BissonHOST
Anthropic tracks the actor behind this operation as GTG-20006.
N
17:42Neil BissonHOST
According to Anthropic, its attribution is consistent with public reporting connected to the actor named Midnight Blizzard, the Russian-linked cyber espionage group also known as APT-29 or Cozy Bear.
N
17:56Neil BissonHOST
Midnight Blizzard has previously been attributed by Western governments to Russia's Foreign Intelligence Service, the
S
18:01speaker_0NARRATOR
SPR.
Passkey phishing attack, Anthropic's blockbuster report, airline cybersecurity loophole
S
1:25Steve PrenticeHOST
In a somewhat blockbuster threat report covering activity between December 2025 and August of this year, Anthropic says it, quote, "detected and disrupted a Russia-linked cyber espionage group that used its AI tool, Claude, in a hacking campaign targeting more than 20 government, intelligence, diplomatic, and defense organizations," end quote.
S
1:47Steve PrenticeHOST
Anthropic said the activity aligned with Midnight Blizzard, which used to be known as Cozy Bear, a group attributed to Russia's foreign intelligence service.
S
1:56Steve PrenticeHOST
In one instance, the group, quote, "targeted members of the Ukrainian government, military, and diplomatic staff, alongside entities involved in the drone supply chain.
S
2:05Steve PrenticeHOST
They were able to steal a complete proprietary software development kit for a drone vision system and then used Claude to reverse engineer that vision system, recovering its product architecture, its hardware bill of materials, its supplier dependencies, and details of an unannounced product." Shiny Hunters also abused Claude to extract secrets from Android apps.
Cyber Mornings Daily - September 14th, 2026
S
14:54speaker_0HOST
Who are they?
S
14:55speaker_1HOST
Anthropix Telemetry shows they have distinct ties to the Russian state-sponsored group Midnight Blizzard, also known as APT29.
S
15:03speaker_0HOST
Wow.
S
15:04speaker_0HOST
So nation states are leaning in.
🔴 Sep 14's Top Cyber News NOW! - Ep 1243
S
20:16Steve PrenticeSOUNDBITE_SPEAKER
tropic caught russia linked spies using claude in hacking operations In a somewhat blockbuster threat report covering activity between December 2025 and August of this year, Anthropic says it, quote, detected and disrupted a Russia-linked cyber espionage group that used its AI tool Clawed in a hacking campaign targeting more than 20 government, intelligence, diplomatic, and defense organizations, end quote.
S
20:44Steve PrenticeSOUNDBITE_SPEAKER
Anthropic said the activity aligned with Midnight Blizzard, which used to be known as Cozy Bear, a group attributed to Russia's Foreign Intelligence Service.
S
20:54Steve PrenticeSOUNDBITE_SPEAKER
In one instance, the group, quote, targeted members of the Ukrainian government, military and diplomatic staff, alongside entities involved in the drone supply chain.
S
21:03Steve PrenticeSOUNDBITE_SPEAKER
They were able to steal a complete proprietary software development kit for a drone vision system and then used Claude to reverse engineer that vision system, recovering its product architecture, its hardware bill of materials, its supplier dependencies, and details of an unannounced product.
Cyber Mornings Daily - September 12th, 2026
S
14:55speaker_1HOST
And this cluster aligns with broader reporting linking them to the group known as Midnight Blizzard.
S
14:59speaker_0HOST
Also tracked as APT29 or Cozy Bear.
S
15:01speaker_0HOST
Right.
S
15:02speaker_1HOST
This is a highly resourced, highly capable, advanced, persistent threat.
You might want to watch what you say.
D
6:58Dave BittnerHOST
Anthropic says it disrupted a Russia-linked cyber espionage group using Claude in attacks against more than twenty government intelligence, diplomatic, and defense organizations.
D
7:09Dave BittnerHOST
The activity aligned with Midnight Blizzard, also known as APT29 or Cozy Bear, which Western intelligence agencies attribute to Russia's SVR.
D
7:20Dave BittnerHOST
According to Anthropic, the hackers compromised hotel Wi-Fi providers, targeted Ukrainian officials and organizations in the drone supply chain, and stole a drone vision system's software development kit.
D
7:34Dave BittnerHOST
They then used Claude to reverse engineer the technology and modify hacking tools after security products detected them.
AI Doomers, Death Cults, and a Million-Dollar WeChat Worm Exploit
C
19:42Costin RaiuHOST
There were some surprises that I was, um, thinking about.
C
19:46Costin RaiuHOST
So for instance, they talk about this, uh, APT29 captive portal, uh, attacks that we discussed before, and they had some, some new details.
R
19:55Ryan NaraineHOST
Captive portal, right.
R
19:55Ryan NaraineHOST
This is the-
R
20:01Ryan NaraineHOST
... by the MSPs, the whole supply chain piece of it, right?
C
20:03Costin RaiuHOST
Mm-hmm.
C
20:04Costin RaiuHOST
The new dark hotel from, uh, APT29 and-
R
20:06Ryan NaraineHOST
Anthropic had something new there
Don't Make It Easy for Them - Ep 577
D
17:12Donna GrindleHOST
And I like the fact that they've taken this approach where it's people.
D
17:19Donna GrindleHOST
Well, except for cozy bear, but that would have been complicated if they made.
D
17:24David SimsHOST
Again, I'll run the bear.
D
17:25Donna GrindleHOST
Yeah.
10 MINS LATER
D
27:08Donna GrindleHOST
And then I'll go and check your passwords.
D
27:09Donna GrindleHOST
Right.
D
27:13Donna GrindleHOST
And then the next one is cozy bear.
D
27:16Donna GrindleHOST
And it's literally a bear wearing glasses and headphones at a computer.
Stylo News Intel Update | Cyber Domain | 11 September 2026
S
5:03speaker_1HOST
Yeah, they're hitting NATO and European Union government websites, financial hubs, transport sites.
S
5:08speaker_0HOST
But there's also a much more sophisticated Russian intelligence cluster operating in parallel, right? APT29.
S
5:14speaker_1HOST
Also tracked as ICE-like, yes.
S
5:17speaker_1HOST
They're actively mapping the transatlantic policy response.
Log4Shell Is Almost Five Years Old. Most Teams Still Can't Answer "What's In Our Software?"
A
4:47Artificial IntelligenceNARRATOR
SolarWinds is the second structurally different pattern.
A
4:50Artificial IntelligenceNARRATOR
Between roughly September twenty nineteen and March twenty twenty, attackers, later attributed to Russia's SVR, APT29, compromised SolarWinds' build environment itself using malware tracked as SunSpot that watched for the Orion product's build process and injected the SunBurst backdoor directly into the compiled output before it was signed.
A
5:11Artificial IntelligenceNARRATOR
SolarWinds has stated the attackers did not modify the source repository.
A
5:15Artificial IntelligenceNARRATOR
The tampering happened inside the automated build pipeline.
1 more episode mentions Cozy Bear.
Create an account to see the whole feed, search across every transcript, and follow the entities you care about.