Criminals move AI into daily operations, Flashpoint finds
A Thursday where AI crossed deeper into both crime and enforcement: Flashpoint's midyear threat report finds criminals now run stripped-down models as everyday tools, while the White House is building an AI "detective border" to catch tariff-dodging transshipment. DeepSeek, meanwhile, open-sourced an agent harness that developers adopted within hours.
Criminal groups have moved AI out of the experimental phase and into day-to-day operations, according to Flashpoint's 2026 Global Threat Intelligence Report: Midyear Edition, released Thursday. The threat-intelligence firm's analysts worked through 3.9 petabytes of material from illicit forums, encrypted channels, and attacker infrastructure — and criminal AI toolkits showed up in more than 22 million posts. Much of that tooling has since vanished from public view: criminals are running custom language models with safety guardrails stripped out, on private infrastructure they control, for target profiling, malware-evasion scripts, phishing content, and exploit generation. Flashpoint CEO Josh Lefkowitz says AI is "compressing the time between opportunity and exploitation" — tools that once demanded real expertise now take much less of it.
The report's numbers show a cybercrime economy that has industrialized: infostealer malware hit 7.4 million hosts and harvested 1.7 billion credentials; verified ransomware victims rose 45% to 6,256, with Qilin alone claiming 901; and nearly one in five vulnerability disclosures now ships with working exploit code. Yet the business itself is getting squeezed — on-chain ransom payments fell about 8% to $820 million, the share of victims who paid slid to 28% (a possible all-time low), and automation has driven the average price of initial access down 69% to $439. The direction of travel is what should worry defenders: Flashpoint expects the next step to be agentic frameworks that scrape data, adjust messaging per target, and rotate infrastructure without constant human involvement — activity that is hard to spot from outside and leaves security teams with a growing visibility gap.
DeepSeek open-sourced its own agent harness on Thursday — DeepSeek Harness, or dsh — and the repo went viral within hours, passing 20,000 GitHub stars by mid-afternoon. The developer-preview tool is built on an "everything is a plugin" architecture powered by the Cordis framework, ships under an MIT license, and launches a local web UI for running and managing agents; DeepSeek is inviting third-party plugins through a dedicated dsh-plugin topic and warns openly that compatibility-breaking changes are coming. It is the clearest signal yet that DeepSeek is entering the agent-tooling race against Claude Cowork, OpenAI's Codex, and the Gemini CLI — and the adoption curve suggests developers were waiting for exactly this.
The White House is building an AI-powered "detective border" to catch goods illegally rerouted through third countries to dodge US tariffs on Chinese products. A report from the White House Office of Trade and Manufacturing Policy, released Thursday, names more than 40 countries as transshipment enablers — Mexico, Canada, the European Union, India, Japan, and South Korea among them. The system cross-references shipment data, routing histories, production capacities, ownership ties, and packaging patterns, and adds X-ray imaging at ports to compare declarations against container contents; AI supply-chain firm Exiger estimates roughly $75 billion in goods were transshipped between February 2025 and February 2026, costing the Treasury between $19 billion and $34 billion in lost tariff revenue. Trade enforcement is becoming a machine problem — and the countries and companies that optimized supply chains around tariff loopholes are about to face a very different risk calculus.
What to watch: the DeepSeek Harness plugin ecosystem — whether third-party builders turn it into a real platform within weeks.
If criminals and customs agents both run AI around the clock, is security now a machine-speed race? Tell us in the comments.
Sources: SiliconANGLE · Flashpoint · DeepSeek Harness (GitHub) · Hacker News · Crypto Briefing · RFI