Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 114+ sources across the spectrum — sources linked so you can verify it yourself.
Beijing Says It Opposes Hacking After U.S. Domain Seizures as ARTEX AI Tool Goes Closed-Source Over Korean Bank Attacks

Since the Justice Department said Thursday, Oct. 8, that it had seized seven internet domains used to scan and hack U.S. and foreign critical infrastructure, three more developments have landed in the Chinese-hacking file. Beijing has responded. An AI hacking tool has gone dark. And a U.S. security firm has detailed a spying campaign aimed at American AI experts.
Beijing's response
China's foreign ministry said Friday that it "firmly opposed" hacking activities, as well as the "ill-intended spread of misinformation." Spokesperson Mao Ning told a regular briefing in Beijing that China would seek to jointly tackle such internet risks and establish mutual respect with the U.S. on the issue.
That is the position of the Chinese government. Beijing routinely denies carrying out hacking operations.
The Justice Department's account is different. It said the seized domains helped Chinese hackers working with Integrity Technology Group. It called the action the second public effort to disrupt that company's infrastructure. The first came in September 2024, when the department disrupted a botnet of more than 250,000 compromised consumer devices. At the time, then-FBI Director Christopher Wray said Integrity Tech was behind the hacking group nicknamed "Flax Typhoon" and was doing intelligence collection and reconnaissance for Beijing's security agencies.
ARTEX goes closed-source
The second development is in South Korea. At least nine South Korean banks have disclosed, or been reported by local media as, targets of cyberattacks since late September. Police opened a probe this week, and President Lee Jae Myung called for robust response measures.
On Wednesday, Oct. 7, U.S. cybersecurity firm CrowdStrike said the suspect behind the attacks, which aimed to steal customers' personal data, was likely a China-based 26-year-old. According to CrowdStrike, that person used the ARTEX AI agent along with Anthropic's Claude Code.
ARTEX was released on GitHub this year as an open-source tool to automate penetration testing. It is not its own large language model. It connects to outside models such as ChatGPT, Claude and DeepSeek to help organizations probe their networks for weaknesses.
The developer, who goes by "Autumn-27" on GitHub, announced Thursday that the project is going closed-source. "Given the misuse of the tool, the ARTEX project will no longer be updated and will be converted to closed source. No further versions will be released to the public nor will maintenance support be provided," the developer wrote.
The developer did not address the bank attacks directly. They said ARTEX was meant to help enterprises improve security testing, that they oppose illegal use, and that they bear no responsibility for conduct that violates laws and regulations. The project's GitHub page has been taken down.
Mao Ning said Thursday that the ministry was not familiar with the case, adding that China consistently opposes and combats hacking.
Spies posing as a former White House official
The third item comes from Silicon Valley firm Proofpoint, which said suspected Chinese hackers impersonated an Anthropic employee and former U.S. officials in an espionage campaign aimed at learning about American AI work.
The targets were email accounts of experts on AI export controls and military uses of AI at U.S. universities, think tanks and law firms. The activity occurred in February and July.
In one case, the hackers posed as Lynne Parker, a senior White House tech official under both Donald Trump and Joe Biden. They emailed someone at a U.S. law firm with an invitation to an "AI policy advisory committee," then followed up with a malware-laced document supposedly offering more details.
Proofpoint found no evidence of successful breaches of the targeted organizations. CNN reported that the firm may have uncovered only part of the activity. Proofpoint researcher Mark Kelly said the firm is "confident" the group is a Chinese government-aligned threat actor, based on targeting that tracks Chinese government interests, observed infrastructure and technical artifacts, and corroboration from industry partners.
The wider AI backdrop
The campaign targeted people shaping U.S. AI policy. CNN reported that Trump discussed AI with Xi Jinping at the White House last week, without producing a substantive accord. It also reported that Trump has resisted guardrails on advanced AI models out of concern the U.S. will fall behind China.
Britain's MI5 said Wednesday that British academics have contributed AI and cybersecurity research to a Chinese institute with close ties to Chinese intelligence. In some cases, MI5 said, the academics may not have known about the connection.
Nothing in the reporting ties the domain seizures, the Korean bank attacks and the Proofpoint campaign to one operation. They are separate cases with separate actors. They do show the same pressure on two fronts: state-linked intrusion into infrastructure and policy circles, and commercially available AI tooling that a single suspect can allegedly turn against banks.
South Korean police are still investigating the bank attacks, and CrowdStrike's identification of the suspect is a private firm's assessment, not a finding by investigators. ARTEX was publicly available for months before the developer pulled it. Who else downloaded it is unknown.
The Justice Department's seven-domain seizure is its second public effort to disrupt Integrity Tech's infrastructure, following the September 2024 botnet disruption. Beijing's reply is again a denial.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.