> daily_signal(2026_07_28)

The AI break-in we called years away hit a government network, private Claude chats surfaced in Google, an EMT sued over patient cameras, and a DNA drug let a boy with epilepsy walk.

PickBits Daily Signal · Tuesday, July 28, 2026

By Mark Pickering · 8 min read · July 28, 2026

// tl;dr

Story one is the arc we have been pointing at all year. When the Five Eyes agencies warned in June that AI-run cyberattacks were "months, not years" away, and when an autonomous agent spent a July weekend loose inside Hugging Face's own servers, the honest reply was always the same: alarming, but not yet a real target. Thailand's Ministry of Finance is that "not yet" running out.

The other three are quieter versions of one fault, a system reaching people who never agreed to it: Claude's Share button feeding private chats into Google, an ambulance camera recording patients in the back of a rig, and an industry that will not make a medicine because too few children need it. The last of those is the exception that proves the point, doctors building a drug for one boy's exact DNA precisely because no market ever would. What actually moved this week is the distance between a warning and an instance, and on all four it got shorter.

Today: an autonomous agent ran the break-in on Thailand's finance ministry, shared Claude chats surfaced in Google and Bing, an Oregon EMT sued over ambulance cameras, and a custom antisense drug cut two boys' seizures and put one on his feet.

1. An autonomous AI agent ran a break-in on a government network mostly by itself.

The attack the agencies kept warning about stopped being hypothetical.

The intrusion your security team keeps war-gaming—an AI that runs the whole break-in with no human at the keyboard—just happened to a real government network. Threat-intelligence firm Hunt.io uncovered an intrusion in which attackers pointed an open-source AI agent, Hermes from Nous Research, at Thailand's Ministry of Finance, and switched it into what the software literally calls "YOLO mode," letting it execute commands with no human approval.

The agent independently explored the network, searched internal files, gathered system data, and looked for ways to escalate its own privileges.

Investigators learned only because the attackers left hundreds of their own files exposed on infrastructure they controlled mid-intrusion, which is how researchers recovered a previously undocumented Windows and Linux backdoor they call Hades, along with stolen credentials and live session cookies.

The firm found no sign that data was exfiltrated, so this reads as reconnaissance and credential theft, not a completed heist; indicators point to Chinese-speaking operators, and Thai authorities were notified on July 15.

The Five Eyes advisory in June put the timeline at months rather than years, and just last week, an autonomous agent roamed Hugging Face's own systems for a weekend. What Thailand adds is a government network as the target and an agent doing the walking on its own. The tools here are not exotic either: an open agent anyone can download and a mode named after a shrug, which is exactly why it should not read as a one-off.

Screenshot of The Record's July 27 report on the Hermes AI-agent intrusion at Thailand's finance ministry.
therecord.media · July 27, 2026
Why this matters: This is plainer than the malware: the intruder in your logs may not tire, sleep, or fat-finger a command the way the human your detection was tuned to catch does, and the same agent framework your own team is piloting for support tickets points in both directions. Action this week: The answer I would get in writing is whether your security team can actually distinguish an automated intruder from a human one in the data it already collects. I would also pin down your standing policy on running agent frameworks unsupervised before you greenlight the next pilot, because "YOLO mode" is a setting a real crew just used against a treasury. Send this to whoever runs your SOC.

therecord.media: Hackers used an autonomous AI agent to spy on Thailand's finance ministry (July 27, 2026)

2. Private Claude chats, some with medical records and a child's name, turned up in Google search.

A share button that was quietly a publish button.

If you have ever hit Share on a Claude chat, check it today, because some of those conversations spent the weekend sitting in ordinary Google and Bing search results. A Reddit user flagged it first, then found more of them by simply searching. What surfaced was publicly accessible Anthropic Claude conversations and Artifacts, some carrying private company documents, health records, and even a child's name and phone number.

Claude's Share feature mints a public web page, and those pages went out without a "noindex" tag or a robots rule, the one instruction that tells a search engine to stay away, so the crawlers did what crawlers do.

By Monday afternoon, the results were gone. Anthropic's line is that shared links only appear in search if a user has posted them somewhere public.

This isn't the first time a chatbot's Share feature quietly turning private-feeling conversations into indexable public pages is a mistake the industry already made and cleaned up once. The default was a private-seeming button that published to the open web. Luckily, the fix here was fast, and the missing header was restored.

Screenshot of TechCrunch's July 27 PSA that shared Claude chats and Artifacts turned up on Google.
techcrunch.com · July 27, 2026
Why this matters: The default on a Share link was public and indexable, and nobody who tapped that button was told so. That is the real failure, not a breach but a design choice that treated a private-feeling action as a public one, on a tool people pour genuinely sensitive things into. My own read is that "only if a user posts them somewhere public" is carrying a lot of quiet weight, because a link a search engine can crawl is public the moment it exists, whether or not you meant it that way. Action this week: The good news is the lever is in your hands, not theirs. I would open Claude, go to Settings, then Privacy, then Shared Chats, and revoke anything I would not tape to a lamppost, and I would stop treating any chatbot's Share as private until the "noindex" default is one you can actually see. Send this to anyone who pastes real life into one of these.

techcrunch.com: PSA: Your Claude shared chats and Artifacts may have ended up on Google (July 27, 2026)
fortune.com: A trove of users' seemingly private Claude conversations showed up in Google search results (July 27, 2026)
the-decoder.com: Shared Claude chats were reportedly showing up in search engines (July 27, 2026)

3. An EMT covered the camera filming patients in her ambulance, and says it cost her the job.

A monitoring rollout meets the people it recorded.

An Oregon EMT's $800,000 lawsuit is the exact fact pattern that turns an employee-monitoring program into a courtroom. Brittany Martin, an EMT for Portland-area operator Metro West, filed a wrongful-termination suit in Multnomah County Circuit Court, alleging she was fired for disabling in-ambulance cameras that recorded patients' video and audio without their consent.

The cameras ran in the back of the rig where patients are treated; Martin raised the privacy problem, but supervisors did not act, so she covered the lens and switched off the microphone in her assigned truck.

She says the company fired her for it, and that the always-on monitoring violated Oregon patient-privacy and data-privacy law.

The tools to watch people at work have gotten comprehensive, from keystroke logs and screenshots to microphones and webcams a platform can switch on itself, and the friction that used to limit them is gone. What is unusual here is that patients were never asked, and the worker who noticed and was shown the door for saying stop.

Screenshot of PetaPixel's July 27 report on an EMT suing after being fired for disabling ambulance cameras.
petapixel.com · July 27, 2026
Why this matters: My own read is that Metro West's problem was never the camera; it was who the camera was pointed at. An employer can usually monitor its own workers; recording a patient in the back of an ambulance who never agreed is a different body of law entirely, and confusing the two is how a monitoring vendor's tidy demo becomes a settlement. When I have asked always-on-recording vendors where third-party consent actually lives in their system, the honest answer has been some version of "that part is on you." Action this week: Before your own cameras go live, the two answers I would insist on in writing are whether recording third parties without consent is legal in every state you operate in, and whether a worker who raises a privacy objection gets treated as a compliance signal or a discipline problem. Get both onto paper, and send this to whoever signs off on your monitoring policy.

petapixel.com: Ambulance worker sues after being fired for disabling cameras that filmed patients without consent (July 27, 2026)

4. Doctors built a medicine for one boy's exact DNA, and he walked on his own for the first time.

Frontier medicine, aimed at the patients the market skips.

A teenage boy with a rare, severe epilepsy walked independently for the first time because doctors built a treatment for his exact genetic mutation. He and a nine-year-old both live with SCN2A-related developmental epileptic encephalopathy, a childhood epilepsy that steals development and that the drug industry mostly passes over because too few children have it.

A team led by UC San Diego and Rady Children's Institute for Genomic Medicine, with principal investigator Olivia Kim-McManus, MD, built each child a personalized allele-selective antisense therapy matched to that child's single mutation.

Published in Nature Medicine on July 21, the results cut seizures by 26% for one boy and 90% for the other, and the older boy took his first independent steps.

It is, on the researchers' own framing, an early result: two children, one study, not a therapy a neurologist can prescribe next week.

The slow arrival of n-of-1 genetic medicine, drugs designed for a single patient's mutation, is the same idea behind ARPA-H's recent funding for custom genetic medicines and the therapeutic-genetics centers standing up this month. What Kim-McManus and her team did was take that idea from a mission statement and apply it to two kids whose seizures actually fell.

Screenshot of UC San Diego Today reporting the personalized antisense therapy that helped a teen with SCN2A epilepsy walk.
today.ucsd.edu · July 2026
Why this matters: Olivia Kim-McManus and her team did the thing the drug market is built not to do: spend years on a medicine that will ever help exactly two people. Keep it honest first: this is two children in one study, an antisense therapy tuned to a single mutation, not a cure your own neurologist can write down. What moves me is less the result than the model behind it, because the reason a drug like this normally never gets made is brutally simple: there is no market in a disease only a handful of kids will ever have. Action this week: There is no button to push on this one, so what I am watching is whether the n-of-1 approach industrializes past a single heroic study, and the tell is the money and the institutions: ARPA-H's funding for custom genetic medicines and the new therapeutic-genetics centers lining up behind exactly this idea. Follow that thread with us.

medicalxpress.com: Personalized gene therapy helps teen with rare form of severe epilepsy walk independently (July 2026)
today.ucsd.edu: Personalized gene therapy helps teen with a rare form of severe epilepsy walk independently (July 2026)
nature.com: A tailored treatment reduced seizures and improved development in two boys with a neurological disorder (July 2026)

» What to watch this week

Tomorrow's signal lands here.