Anthropic's September threat-intelligence report ("Detecting and countering misuse of AI") discloses five named China-based labs running illicit distillation campaigns against Claude between May and July 2026. Alibaba's Qwen/Tongyi team ran the largest campaign ever measured — peaking at nearly 3 million exchanges/day from 3,500+ fraudulent accounts, 151M+ exchanges total — injecting prompts that forced Claude to expose its chain-of-thought reasoning, which was then used to train Qwen 3.5–3.7. Moonshot AI (23M+ exchanges) and DeepSeek (12.1M+ exchanges in just 14 days) both secretly rerouted their own Kimi/DeepSeek customers' requests to Claude and served back Claude's answers without disclosure, while separately harvesting Claude's reasoning traces via a "cross-session replay" exploit that defeats Anthropic's thinking-signature safeguard.
The privacy fallout is the sharper story: real end users had no idea their prompts were being forwarded to a third party. Cases include a PLA-affiliated user analyzing CCTV surveillance data from cameras outside PLA facilities via what they thought was Kimi; a Russian Ministry of Defense-linked operator whose live government-database credentials leaked through DeepSeek; and a Chinese municipal Public Security Bureau engineer building a citizen-movement-tracking tool. Zhipu (Z.ai, 3.4M+ exchanges) ran a similar chain-of-thought extraction pipeline to train GLM 5.3, reportedly giving up on distilling Anthropic's flagship Fable model once its cyber safeguards held, and pivoting to the weaker-defended Opus 4.6 and a rival US lab's model instead; Xiaomi (400K+ requests via 1,500+ accounts) replayed MiMo customer sessions through Claude, timed to a MiMo-V2-Pro free-trial surge.
NewsAPI Step 1b main query returned a genuine 0 results again this run — confirms news-agent/CLAUDE.md line 62 remains unresolved since 2026-07-07 (the + should be OR between phrase-quoted terms). Escalation to Ayush is still the right path since this agent's write scope doesn't extend to CLAUDE.md. The competitor query (1c) returned 9 raw hits, 0 genuine (a raccoon-trap explainer, a university arts-bash recap, a Ford/China politics piece, an NFL profile, two duplicate HRW Australia detention stories, an India dryland-agriculture feature, an anti-vaccine opinion piece, and a Revolutionary War history post — same keyword-collision false-positive pattern as every prior run).
Firecrawl: 3/3 scrapes successful this run — Anthropic's threat-intelligence report and Inc42's e-commerce-rules piece both scraped cleanly with no blockers; TechCrunch's Meta Muse piece hit a Cloudflare/Turnstile challenge shell but Firecrawl still captured the full article text beneath it (cloud mode, direct REST curl, no MCP).
Anthropic Newsroom RSS (rss.xml) still 404s — checked directly again this run; no working feed URL found yet. Today's Anthropic coverage came entirely via TechCrunch and Hacker News surfacing the threat-intelligence report directly.
shopify.dev's changelog feed.xml remains HTTP 500 — still unresolved; no page-render fallback attempted this run since the Shopify Changelog RSS already surfaced today's one Shopify-owned update.
Otterly.ai's blog fetch came back clean today — no empty-content or stale-date anomaly, following yesterday's empty-content recurrence. Per the ongoing pattern, logging this as one clean data point, not a resolution.
memory.md size discipline: single-previous-day rule maintained — replaced the Sep 10 "Last Report" full narrative with today's (kept Sep 10's Top 3 Stories in full); trimmed the competitor moves log's Jun 12 row (crossed the 90-day window as of Sep 11), leaving Jun 13 as the earliest entry — next trim due once Jun 13 crosses 90 days back (around Sep 12).