AI and IT News Recap: September 10, 2026: AI Agents Breach 395 Organizations in 48 Countries, Anthropic Says Attacks Have Gone Autonomous, and Cisco Firewalls Fall to Qilin and Sandworm

By Noah Smith, Owner & Consultant, KeyChange Technologies · September 10, 2026

Pen-and-ink cutaway illustration: an office worker stands beside an ordinary copier in a small room, unaware that an enormous teal root system has already spread beneath the floor and reached the foundations of distant towns and city buildings.

Twelve stories today, and most of them are the same story wearing different clothes: the attacker has stopped being a person and started being a fleet.

📌 The AI and IT news at a glance

  • A swarm of AI agents ran a real intrusion campaign against 395 organizations in 48 countries, and compromised 11 of them in 26 seconds.
  • Anthropic's new threat report says AI has moved from assistant to orchestrator in cyber operations, including malware that rebuilds itself until your antivirus stops seeing it.
  • NSA, FBI and CISA named six Chinese AI firms for industrial-scale distillation against US frontier models. Beijing told them to prove it.
  • OpenAI put Paul Christiano, one of the field's most prominent safety researchers, on its Foundation Board.
  • The Justice Department is looking at whether Nvidia's Groq licensing deal was an acquisition wearing a costume.
  • Cisco Talos confirmed Qilin ransomware and Sandworm-linked hackers are both living inside Secure Firewall Management Center. Federal deadline is Saturday.
  • A shared exploit kit called BlueMoon chained two Chrome zero-days and a Windows one, and four separate espionage crews used it.
  • A WatchGuard firewall flaw from last December is now a ransomware favorite, and roughly 9,000 boxes are still sitting on the internet unpatched.
  • September's Windows Server updates are breaking Remote Desktop Services, and the only reliable fix is removing the security patches.
  • AdaptHealth confirmed 4.1 million people were exposed in a July attack tied to ShinyHunters.
  • Harvey raised $550 million at
    5.5 billion and shipped its own model built on an open-weight Chinese base.
  • Clay raised
    15 million at $7.1 billion, more than doubling in 13 months.

🔝 Top story

AI agents ran a global intrusion campaign against 395 organizations, and did it faster than anyone could answer the phone

GreyNoise published an analysis on Thursday of a campaign in which a threat actor, likely Russian speaking, pointed hundreds of AI agents at internet-facing PaperCut NG/MF print management servers and let them work. The agents built, tested and refined exploits for CVE-2026-81578 and CVE-2026-82078, two PaperCut flaws flagged as actively exploited earlier this month. They pulled target lists from the Netlas internet scanning platform. The operator combined OpenAI's Codex with DeepSeek models and ordinary commodity offensive tooling, none of it exotic. The campaign started on August 31.

The numbers are what make this different from every other "AI-assisted attack" headline of the past year. GreyNoise counts at least 440 compromised PaperCut instances across 395 distinct organizations in 48 countries. The attacker harvested credentials from 280 victims, pulled operating system or domain secrets from 147, and reached administrator privileges at 12. Roughly half the victims were schools and universities. The United States was the most targeted country, followed by the UK, France, Spain and Canada. And then the timing: GreyNoise says the adversary went from an empty workspace to first remote code execution against a real victim in under four hours, first domain admin two hours after that, and once the campaign actually launched, compromised at least 11 organizations in 26 seconds. In one case, a US high school went from initial access to full domain administrator in seven minutes. The agents were told to avoid a list of countries including Russia, China, Iran and Ukraine. They did not consistently obey.

In short: A single operator used hundreds of AI agents to build and run a global exploitation campaign that breached 395 organizations across 48 countries, in some cases reaching domain admin in seven minutes.

What it means for your business: The window between a vulnerability being published and it being exploited against you has collapsed to hours, and the manual triage rhythm most small IT teams run on cannot cover that gap. If you run PaperCut, patch it today; if you run anything else internet-facing, the lesson is that "we'll get to it next maintenance window" is no longer a defensible plan.

My take: I have been skeptical of AI-attack stories because most of them turn out to be a human doing the hard parts and an LLM writing the phishing email. This one is not that. The tell is the 26 seconds, and the fact that the agents ignored their own geographic exclusion list. That is machine execution with a human only setting the goal. What strikes me most is how unglamorous the target was. Print management software. Not a firewall, not a VPN, not a domain controller. The thing nobody has on their asset inventory because it manages printers. That is where this goes next, and it means the boring stuff on your network just got promoted to the top of the list.

Source: BleepingComputer, "AI-powered attack exploited PaperCut flaws to hack 395 organizations"


🤖 The AI and IT news in artificial intelligence

Anthropic's threat report: AI has gone from assistant to orchestrator

Anthropic published its September 2026 threat intelligence report on Thursday, covering operations it disrupted between December 2025 and August 2026 across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation. The company says the abuse involved Claude Haiku, Sonnet and Opus models, and that no misuse was found on its Fable or Mythos class models with the exception of a single illicit distillation case. The framing in the report is blunter than previous editions. Anthropic's position is that the bigger danger is not AI writing novel exploits, it is AI compressing every step of the attack chain so that adversaries move faster, across more surface area, with fewer people.

The standout case study is GTG-20006, a Russian espionage operator whose attribution Anthropic says is consistent with public reporting on Midnight Blizzard. The group targeted Ukrainian and European government military intelligence, plus diplomatic and defense organizations and individuals connected to US foreign policy, scanning email and remote access systems across more than two dozen Ukrainian government organizations. What makes it notable is the feedback loop: the actor ran AI agents that monitored whether their own malware was being flagged by security products, and when it was, the agents automatically modified and rebuilt the malware until it went undetected again, then staged it for live operations. Anthropic's own summary of what that means is the sharpest line in the report, that AI "has inverted the cost back onto defenders." A new detection signature used to buy defenders weeks. Now it buys them an afternoon.

In short: Anthropic disclosed nine months of disrupted misuse cases and reported that attackers are now using AI agents to autonomously rebuild their malware whenever a security product detects it.

What it means for your business: If your security posture depends mostly on signature-based detection, whether that is traditional antivirus or an EDR product you have never tuned, the ground under it is moving. Behavior-based detection, identity controls and MFA matter more than ever, because the malware file itself has become a moving target.

My take: The self-rewriting malware loop is the detail I would want every business owner to sit with for a minute. Not because you can do anything about it directly, but because it changes what you should expect from your security vendor. It is worth asking whoever runs your endpoint protection what happens when the signature stops working, and whether they can answer that question without a sales deck. Credit where it is due, too: Anthropic did not have to publish this level of operational detail about its own product being misused, and the industry is better for it.

Source: Anthropic, "Detecting and countering misuse of AI: September 2026"


NSA, FBI and CISA name six Chinese AI firms over industrial-scale distillation

A joint advisory from CISA, the NSA and the FBI, released Wednesday and catalogued as AA26-251A, accuses DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI of extracting billions of tokens through millions of requests against frontier models from Anthropic, OpenAI, Google and xAI, going back to at least late 2024. Distillation itself is a legitimate and widely used technique where a smaller model learns from a larger one's outputs. The agencies' argument is about scale and intent: they say these firms distributed requests across fraudulent and shared accounts, aggregators, cloud services and proxy "transfer stations" specifically to evade geographic restrictions, usage limits and detection, and that some prompts were engineered to pull out restricted chain-of-thought reasoning. Automated systems reportedly failed over between providers when one blocked them, and ran quality checks to detect when a defender had started degrading responses.

The advisory names DeepSeek and Moonshot AI as the top offenders, distilling multiple Claude, GPT, Gemini and Grok models, with MiniMax next, and Alibaba, StepFun and Z.AI targeting narrower sets. The agencies assess that the scale and sophistication indicate Chinese government awareness and that this is likely a core development strategy for the firms involved. China's Ministry of Commerce rejected the accusations on Thursday, calling them factually and legally groundless, arguing distillation is standard practice across the global industry, and warning that Beijing could retaliate if Washington uses the findings to justify new restrictions on Chinese AI companies. Notably, Anthropic's own threat report published the same week lists illicit distillation as one of its seven harm areas.

In short: US intelligence and cyber agencies formally accused six Chinese AI companies of running industrial-scale distillation campaigns against American frontier models, and China rejected the claim and threatened retaliation.

What it means for your business: Directly, very little today. Indirectly, this is the opening move in a fight over model access and API restrictions, and if you have standardized on a Chinese open-weight model in your stack, procurement questions about provenance are going to get harder over the next year.

My take: The advisory reads less like a criminal referral and more like a policy argument being built in public, which is fine, but worth naming. Distillation is not illegal, and the agencies are careful to say the technique itself is legitimate. What they are really describing is terms-of-service violation at nation-state scale, and the remedy list at the end is all detection guidance for AI companies, not enforcement. The interesting question nobody has answered yet is what happens to the open-weight models already in production everywhere, including Harvey's, if the provenance argument sticks.

Source: BleepingComputer, "US says Chinese firms extracted billions of tokens from frontier AI models"


OpenAI adds Paul Christiano to its Foundation Board

OpenAI announced on Wednesday that Paul Christiano is joining the OpenAI Foundation Board and its Safety and Security Committee, chaired by Zico Kolter. He will also sit as a non-voting observer on the OpenAI Group PBC board. Christiano worked at OpenAI from 2017 to 2021 leading alignment research, where he contributed foundational work on reinforcement learning from human feedback, the technique behind most modern chat assistants behaving the way they do. He later founded the Alignment Research Center and currently serves as a Senior Technical Advisor at the US government's Center for AI Standards and Innovation.

The appointment lands in a specific context. Christiano has been publicly and repeatedly clear that he assigns meaningful probability to catastrophic outcomes from advanced AI if safeguards lag capability, a position that has earned him the "doomer" label in some coverage. Putting him inside the governance structure at a moment when the company is fielding questions about agent behavior during cybersecurity testing is either a real commitment or a very well-chosen signal, and reasonable people will read it both ways. The Safety and Security Committee has governance authority over safety practices across all of OpenAI, including the PBC.

In short: OpenAI appointed alignment researcher Paul Christiano to its Foundation Board and Safety and Security Committee, with a non-voting observer seat on the commercial board.

What it means for your business: Nothing operational, but governance appointments at frontier labs are a leading indicator of how aggressively models will be released and restricted, which eventually shows up in your vendor's roadmap and your compliance paperwork.

My take: Board seats are cheap signals and hard commitments at the same time, and you cannot tell which one this is from the announcement. The thing I would watch is whether the Safety and Security Committee ever publicly slows something down. That is the only evidence that will settle it. Worth noting he is a non-voting observer on the commercial board, which is where the money decisions actually happen.

Source: OpenAI, "Paul Christiano joins OpenAI Foundation Board"


DOJ examines whether Nvidia's Groq deal dodged antitrust review

The New York Times reported Wednesday that the Justice Department is investigating whether Nvidia structured its licensing transaction with AI chip startup Groq to avoid antitrust scrutiny. Groq presented the December arrangement as a nonexclusive license giving Nvidia access to chips optimized for AI inference. As part of the same deal, Groq founder and CEO Jonathan Ross and COO Sunny Madra moved to Nvidia while Groq remained a separate company. The department opened the inquiry shortly after the announcement and has sent Nvidia a formal demand for information. Later reporting put the total package somewhere in the

7 billion to 0 billion range.

The pattern at issue, a license plus the acquired company's leadership team plus a large payment, without a merger filing, is exactly what lawmakers have started calling a stealth acquisition. People briefed on the matter told the Times that unwinding the deal is unlikely, though officials could seek a fine if they conclude the structure was designed to sidestep review. Nvidia's response was that the Groq story is "a prime example of the American system working as designed." For the wider market, the significance is less about this specific deal and more about whether the license-and-hire structure remains a viable exit for chip startups.

In short: The Justice Department is investigating whether Nvidia's roughly

7 to 0 billion licensing arrangement with Groq was an acquisition structured to avoid merger review.

What it means for your business: If you are buying AI compute or building on inference infrastructure, the consolidation question matters, because fewer independent inference chip vendors eventually means less pricing pressure on the compute line in your budget.

My take: Whatever the legal outcome, the structure is now expensive to use, and that is probably the point of the inquiry. For founders building inference silicon, the quiet exit just got louder. I would not expect a dramatic remedy here, but I would expect the next three deals to look different.

Source: The New York Times, "Justice Dept. Investigates Nvidia's Deal With A.I. Chip Start-Up Groq"


🛡️ IT and security

Qilin ransomware and Sandworm-linked hackers are both inside Cisco firewall managers

Cisco Talos published findings on Thursday confirming that two Secure Firewall Management Center vulnerabilities have been exploited by three separate threat clusters. The flaws are CVE-2026-20079, a maximum-severity CVSS 10.0 authentication bypass that lets an unauthenticated remote attacker run scripts as root, and CVE-2026-20316, a CVSS 5.3 static credential flaw that Cisco rates as High severity because it chains cleanly with other FMC bugs to escalate privileges. Talos tracks the clusters as UAT-11988, UAT-11823 and UAT-12197. The first is attributed with high confidence to Qilin ransomware affiliates, who logged in using the static credentials, used FMC's own built-in tools to map the victim network, staged the harvested data in publicly readable files on the compromised appliance, pulled it down over plain HTTP GET requests, then deployed a SOCKS5 proxy and reverse SSH tunnel before encrypting endpoints.

The second cluster overlaps in tooling with Sandworm, the Russian GRU-linked group known for destructive attacks on critical infrastructure. It modified a license.tmp file to establish a Netcat reverse shell, executed it as root through Cisco's own legitimate package_info.pl utility, and ultimately deployed a variant of Cyclops Blink, a modular Linux backdoor that provides persistent access, credential theft and network traffic sniffing. The third cluster dropped a JSP web shell into the Cisco Security Manager Tomcat webroot and used it to install a malicious JAR file for querying internal databases and stealing credentials. Cisco has hotfixes out for both flaws and says a more comprehensive hardening release lands next week. Separately, CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog on Wednesday alongside a Citrix NetScaler auth bypass (CVE-2026-19490, CVSS 9.3) and a Fortinet FortiOS heap overflow (CVE-2025-25249, CVSS 7.3), with a federal patch deadline of Saturday, September 12.

In short: Cisco Talos confirmed three separate groups, including Qilin ransomware affiliates and a Sandworm-linked APT, have been exploiting two Cisco Secure FMC flaws, and CISA has set a September 12 federal patch deadline.

What it means for your business: The device managing your firewalls is a higher-value target than the firewalls themselves, and if yours is a Cisco FMC you should be applying hotfixes now rather than waiting for next week's fuller release. If you outsource this, ask your provider today whether it is done, not whether it is scheduled.

My take: The detail that stuck with me is that the Qilin affiliates did most of their reconnaissance using FMC's own built-in tools. No custom malware, no exotic tradecraft, just using the security appliance's legitimate features against the network it protects. That is a reminder that "we bought the good firewall" is a statement about your attack surface, not a defense of it. Management planes deserve the same isolation and monitoring you give a domain controller.

Source: BleepingComputer, "Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers"


A shared exploit kit called BlueMoon chained two Chrome zero-days and a Windows one

Proofpoint and Volexity both published research on Thursday describing BlueMoon, a modular exploit kit used by multiple cyber-espionage groups. It chains three flaws: CVE-2026-85046, a type-confusion bug in Chrome's V8 JavaScript engine that grants arbitrary memory access inside the V8 sandbox; CVE-2026-87491, a V8 sandbox escape that corrupts WebAssembly metadata to run embedded shellcode; and CVE-2026-85880, a heap-based buffer overflow in Windows ALPC used for local privilege escalation. The kit runs its exploit inside a Web Worker with up to five retries, fingerprints the machine, elevates the Chrome renderer process, injects into Chrome's parent process, and by default uses curl to drop a malware loader into %TEMP% and execute it.

The operating model is the part worth noting. Researchers say BlueMoon's maintainers deliberately exploit the delay between a fix landing in public Chromium source and that fix reaching stable Chrome, reverse-engineering the published code changes to build working exploits against everyone still on the older build. Proofpoint observed the kit in spearphishing since August 28 by JungleBamboo, a China-associated actor also tracked as APT31 and Violet Typhoon. Volexity saw a different actor, UTA0560, using it against non-governmental organizations from September 1 with donation-themed lures delivering an in-memory JScript backdoor called Grimwedge. Two more clusters were identified: UNK_LateNight, deploying the ShadowPad backdoor against US aerospace and defense-industrial-base companies, and UNK_DoubleCheck, hitting Vietnamese manufacturers with an in-memory Rust loader. Proofpoint expects the kit to spread to financially motivated crews.

In short: Four separate espionage groups have been using a shared exploit kit, BlueMoon, that chains two Chrome zero-days and a Windows privilege escalation flaw to run malware on fully patched-looking machines.

What it means for your business: Browser updates are a security control, not a convenience setting. If your organization defers Chrome updates or leaves them to individual users, you are living inside the exact gap this kit was built to exploit.

My take: The reverse-engineering-the-public-fix technique is not new, but seeing it industrialized into a kit that four unrelated groups share is a genuine escalation. It also quietly undermines one of the arguments for open-source security patching, which is uncomfortable but worth saying honestly. The practical takeaway is boring and correct: turn on automatic browser updates, enforce restarts, and stop treating the browser as a user preference.

Source: BleepingComputer, "New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws"


A nine-month-old WatchGuard firewall flaw is now a ransomware favorite

CISA updated its Known Exploited Vulnerabilities catalog on Thursday to confirm that ransomware gangs are now exploiting CVE-2025-14733, a critical out-of-bounds write in WatchGuard Firebox firewalls that allows unauthenticated remote code execution in low-complexity attacks. The flaw affects Fireware OS 11.x and later including 11.12.4_Update1, 12.x and later including 12.11.5, and versions 2025.1 through 2025.1.3. WatchGuard patched it in December and confirmed active exploitation at the time, noting that devices are exposed if configured for IKEv2 VPN, and warning that a box could still be compromised even after deleting the vulnerable configuration if a branch office VPN to a static gateway peer remains configured.

Here is the uncomfortable part. Shadowserver counted over 115,000 unpatched Firebox firewalls exposed online back in December. Nine months later, nearly 9,000 are still sitting there unpatched. WatchGuard serves more than 250,000 small and mid-sized companies through a network of over 17,000 resellers and managed service providers, which means most of those 9,000 boxes belong to a business that assumed someone else was handling it. This is also the second nearly identical Firebox RCE in about a year; CVE-2025-9242 was patched in September 2025 and added to KEV a month later, at which point Shadowserver found more than 75,000 vulnerable devices.

In short: CISA confirmed ransomware gangs are exploiting a critical WatchGuard Firebox flaw patched last December, with roughly 9,000 vulnerable firewalls still exposed on the internet.

What it means for your business: If you have a WatchGuard Firebox, confirm the firmware version yourself today rather than assuming your MSP did it. Firewalls are the single most common device to be bought, installed, and then never updated again for years.

My take: Nine thousand unpatched boxes nine months after a public patch and confirmed exploitation is not an awareness problem, it is an ownership problem. Somebody sold the firewall, somebody installed it, and nobody agreed in writing who patches it. If you cannot name the person responsible for firmware on your perimeter device, that is the actual finding here, and it will be true of more than just the firewall.

Source: BleepingComputer, "CISA: WatchGuard RCE flaw now exploited in ransomware attacks"


September's Windows Server updates are breaking Remote Desktop

Administrators across Windows Server 2019, 2022 and 2025 are reporting that this month's cumulative updates are breaking Remote Desktop Services. The pattern is consistent: servers run normally for a few hours after the update, then connections start failing. Existing sessions cannot disconnect or log off cleanly, new connection attempts hang and eventually time out, and in many cases only a hard reset restores service. One administrator investigating on Server 2022 reported that the RDP service becomes unresponsive as users start logging out and that debugging suggested a deadlock between Remote Desktop and the Local Session Manager, with the service hanging at RDPSERVERBASE!WDLIB_Close with no timeout. Microsoft has not confirmed a cause.

The affected updates are KB5122876 on Server 2019, KB5122882 on Server 2022 and KB5122871 on Server 2025. Administrators who rolled the updates back say Remote Desktop functionality returns, but rolling back also removes this month's security fixes, which is a genuinely bad trade in a week when three separate actively-exploited flaws hit the federal patch list. Microsoft had not responded to press inquiries as of Thursday afternoon.

In short: September 2026 cumulative updates are causing Remote Desktop Services failures on Windows Server 2019, 2022 and 2025, with rollback the only confirmed fix.

What it means for your business: If your staff connect to a terminal server to work, test this before Monday rather than discovering it at 9am. And if you do roll back, treat it as a temporary state with a calendar reminder, not a decision.

My take: This is the ordinary tax of running Windows infrastructure and it is not a scandal, but the timing is genuinely awkward. Being asked to choose between "people can work" and "the server is patched" in the same week that Cisco, Citrix and Fortinet flaws are under active exploitation is a bad position. If you are affected, the least-bad path is usually to roll back on the RDS hosts specifically, keep everything else patched, and isolate those hosts more tightly until Microsoft ships a fix.

Source: BleepingComputer, "September Windows Server updates break Remote Desktop Services"


AdaptHealth confirms 4.1 million people exposed in a July attack

Healthcare company AdaptHealth confirmed on Wednesday that the personal data of 4.1 million people was exposed in a cyberattack discovered in July, and the intrusion has been attributed to the ShinyHunters threat group. AdaptHealth is a home medical equipment provider, which means the affected population skews toward people managing chronic conditions, and the data involved in that line of business is the kind that combines identity details with health information.

ShinyHunters has been a recurring name in this recap for months, and the pattern is by now familiar: get in through credentials or a third-party platform, go straight for the customer database, then extort. What is notable here is the gap. The attack was discovered in July and the scope was confirmed in September, which is a normal timeline for breach forensics and a terrible one for the 4.1 million people who spent those weeks not knowing.

In short: AdaptHealth confirmed that 4.1 million people had data exposed in a July cyberattack attributed to the ShinyHunters group.

What it means for your business: Two things. If you handle health-adjacent data, the notification clock and the forensics clock run at different speeds and you need a plan for the gap. And if you are a customer of a vendor like this, your exposure is inherited, which is why vendor security questionnaires exist even when they feel like theater.

My take: Four point one million is a large number that will be forgotten by Monday, which is itself the story. Breach fatigue is real and I do not have a clever answer for it. The only useful posture I know is to assume your personal data is already out there, freeze your credit, and spend your attention on the controls you actually own.

Source: BleepingComputer, "AdaptHealth confirms 4.1 million people exposed in July cyberattack"


🧰 New tools and AI for the business

Harvey raises $550 million at
5.5 billion and ships a model built on a Chinese open-weight base

Legal AI company Harvey announced on Wednesday a $550 million round at a

5.5 billion valuation, co-led by Diffusion and Lightspeed Venture Partners, with Sequoia, Kleiner Perkins, a16z, Coatue, Goldman Sachs Alternatives and others participating. That brings total funding past
.5 billion since the company launched in 2022. Harvey says it has crossed $400 million in annual recurring revenue and serves more than 3,000 customers, including 80% of the top 100 law firms and 20% of the Fortune 500.

The more interesting item is the model. The raise follows Harvey Tenet, the company's first post-trained open-weight model, alongside Harvey LAB, its Legal Agent Benchmark. Tenet starts from a Kimi K3 base, the open-weight model from Moonshot AI, and was post-trained with Fireworks for long-horizon legal work across roughly 1,750 agentic legal task environments on about 150 NVIDIA B300 GPUs over two months. That is a specific architectural bet: take an open-weight foundation, post-train it hard on your vertical, and stop paying frontier-model rent on every query. It is also, as of this week, a bet with a geopolitical asterisk, given that Moonshot AI was named in the US distillation advisory two days before the round was announced.

In short: Harvey raised $550 million at a

5.5 billion valuation and has shipped Harvey Tenet, its own legal model post-trained from Moonshot AI's open-weight Kimi K3 base.

What it means for your business: The vertical AI playbook is now legible and repeatable: open-weight base, heavy domain post-training, proprietary benchmark, own the workflow. If you are evaluating an AI vendor in your industry, ask which of those four they actually have, because "we call an API" is no longer a moat.

My take: Two hundred million dollars of ARR growth and a self-built model in the same year is a real business, not a valuation story, and I say that as someone generally allergic to legal-tech hype. The Kimi K3 dependency is the thing I would want a straight answer on if I were a large firm signing with them. Not because there is anything wrong with it today, but because the US government spent this week arguing that model's lineage is contested, and enterprise procurement does not enjoy surprises like that.

Source: LawSites, "Harvey Raises Another $550M At A

5.5B Valuation"


Clay raises
15 million at $7.1 billion as AI sales agents keep compounding

Go-to-market platform Clay announced a

15 million Series D on Wednesday at a $7.1 billion valuation, led by Wellington with participation from Sequoia, StepStone and Andreessen Horowitz. The company says it now serves more than 17,000 customers, including Anthropic, Google, OpenAI, Stripe, ElevenLabs, Workday and Siemens, and 80% of the Forbes AI 50. Clay crossed
00 million in annual recurring revenue in December 2025.

The valuation trajectory is the story. Clay was marked at

.1 billion in August 2025, repriced to $5 billion in a DST Global-led employee tender in January 2026, and has now more than doubled from its August 2025 mark in thirteen months. The product sits in the unglamorous middle of the sales stack, enriching and orchestrating prospect data so AI agents can actually do outbound work with correct inputs, which is precisely why it keeps growing. Garbage data has always been the reason sales automation disappoints; the agent layer just makes the failure faster and more expensive.

In short: Clay raised

15 million at a $7.1 billion valuation, more than doubling its mark from thirteen months earlier, with over 17,000 customers.

What it means for your business: If you have tried AI-powered outbound and it underperformed, the model was probably not the problem. Data enrichment and routing is where these systems break, and it is worth auditing before you buy another agent.

My take: I like this category more than I expected to, because it is a data-quality business wearing an AI costume, and data quality is the thing that actually determines whether any of this works. The valuation is aggressive against

00 million-plus ARR, and it is priced for the assumption that every company will run agentic outbound within two years. That may well happen. It also may run into the wall where everyone's inbox is full of agent-written email and response rates go to zero, which is a risk nobody in this category likes discussing.

Source: Yahoo Finance, "Clay Raises

15M to be the AI Growth Engine for Every Company"


That is today's AI and IT news. The previous edition is here if you missed it: AI and IT News Recap: September 7, 2026.