A botnet is turning home and office routers into relay nodes, Twitch has switched on AI training for every account unless you opt out, and Anthropic has published how its text watermark works

A botnet is taking over routers, cameras and network drives — check yours

A Linux botnet active since at least July is breaking into internet-facing network equipment and using it to relay other people's traffic. The published analysis names gateway devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare and D-Link, with newer versions of the malware also going after Hikvision cameras, TP-Link routers and D-Link network storage drives. It is not using a new flaw. It works through known vulnerabilities in devices that were never updated, and through administrator passwords that were never changed from the factory default.

A device used as a relay does not usually look broken. It carries someone else's traffic alongside yours, which can mean a slower connection, and it means activity that traces back to your internet address.

Why it matters: the box in the corner that has been running for six years without a thought is exactly the target here. Do four things this week: install the firmware update in your router's settings page, change the administrator password if it is still the one printed on the label, switch off remote management or remote access to the admin panel unless you genuinely use it, and replace any device the manufacturer no longer supports with updates — an unsupported router cannot be secured, only replaced.

Twitch has been training Amazon's AI on your channel — the opt-out is new

Twitch has added a setting that lets account holders refuse the use of their content for training Amazon's generative AI models. The toggle arrived switched on for every account, so every creator was already enrolled before the option to decline existed, and it covers streams, recordings, clips, chat, and text and photos posted to a channel.

To switch it off: on the web, go to your avatar, then Settings, then Security and Privacy, and scroll to "Training for Generative AI". In the mobile app it is Profile, then Settings, then Security and Privacy, and the choice syncs across your devices. Two limits are worth knowing. The setting applies to future training, and nothing has been said about content already used. And it does not switch off every use of machine learning on the service — captions, recommendations and the automated moderation tools carry on, that data simply is not kept for training generative models.

Why it matters: the pattern matters more than the platform. A service you already use can change what it does with the material you upload, switch the change on by default, and put the control somewhere other than where you manage your content — this one sits in account security settings, not the creator dashboard. If you post to Twitch, go and set the toggle now. If you post anywhere else, this is your reminder to open the privacy section of that account's settings and read what is currently switched on.

What Claude's new invisible watermark can and cannot tell you

Anthropic has published an explanation of the watermark now embedded in text written by its Claude models. The company's own description is that the model subtly steers its word choices using a hidden key, in a way that leaves a detectable statistical pattern without changing the meaning or quality of the writing, and that it does so to comply with European transparency rules the company signed up to in July. The mark carries nothing about the person using the service.

The published limits are the useful part. A detection service is described as coming, not available, so nobody can check anything yet. The mark is thinner in short or factual passages where there are fewer word choices to make, so short extracts may not register. Light editing probably will not remove it, but a full rewrite will. Translations keep it, because the model chooses every word. Code is largely exempt, because there is often only one correct output. And a positive result means the model was likely involved somewhere in producing the text — not that a person did not write it.

Why it matters: if you use AI to help draft anything, assume the output can eventually be identified as machine-assisted, including work you edited afterwards. That is not a reason to stop, but it is a reason to know your employer's or client's position before it comes up rather than after. And if you are on the receiving end — reviewing a submission, an application, a piece of work — a detection result of this kind is evidence of a tool being involved, not proof of who wrote something, and it should never be treated as an accusation on its own.

How to check whether your AI accounts have been broken into

AI accounts now hold a running record of work, clients and personal circumstances, which makes them worth stealing, and most people have never looked at who is logged into theirs. A published walkthrough covers the main services: in ChatGPT the list is under Settings, then Security and Login, then Active Sessions; in Claude it is Settings, then Account, then Active Sessions; and Perplexity does not show individual sessions at all, so the only option there is signing out of everything and logging back in. Each service lets you end a session you do not recognise, or end all of them at once.

Why it matters: an intruder in one of these accounts reads everything you have ever typed into it, which for most small businesses is a substantial amount about customers, pricing and plans. Open the active sessions list on every AI service you pay for and end anything you cannot account for, then turn on two-step verification where the service offers it and give the account its own password rather than one reused from elsewhere.

The company behind the Cursor coding tool has been bought for 60 billion dollars

Cursor, the AI coding tool used by a large number of software developers, has been acquired by SpaceX. The deal is reported at 60 billion dollars in SpaceX stock, completing a process that started as a training partnership earlier in the year. Cursor's own announcement says the product continues, and points to access to a very large amount of computing hardware as the reason it expects to offer more capable models at lower cost. No pricing or product changes have been announced.

Why it matters: if you pay a developer or an agency to maintain your website, app or internal tools, there is a reasonable chance this is the tool they work in, and the software your business runs on now depends on a supplier owned by a rocket company. Nothing needs doing today. It is worth asking at your next check-in which paid development tools your work depends on and what happens if one of them changes terms — the answer is a small business continuity question, not a technology one.