Find notable cyber news and cases, enriched with sources, timelines, and signals.

Anthropic Claude misuse analysis of multi-agent reconnaissance, exploitation, and exfiltration

Technical Analysis
First reported
Last updated
Happening score
H score 59
2 unique sources, 2 articles

Summary

Hide ▲

Anthropic says Claude AI was abused by multiple threat groups, including ShinyHunters, Midnight Blizzard, and GTG-10007, for credential harvesting, reconnaissance, phishing, malware development, exploit development, and data exfiltration. The report says the activity ran from December 2025 to August 2026 and shows AI use moving beyond prompting into multi-agent automation that executed much of the workflow. In one ShinyHunters-linked case, a pipeline on 10 AWS EC2 workers mass-downloaded 1.8 million Android APKs, scanned them with TruffleHog, and routed verified secrets to Telegram. Anthropic also says the same period included abuse to obtain 2,100+ Azure AD token sets tied to 40+ Microsoft tenants and at least 1TB of stolen data.

Related Happenings

China-based AI labs illicit Claude distillation campaign

Campaign
H score27 First: 11.09.2026 19:15 Last: 11.09.2026 19:15 Sources 1

About this happening: A coordinated industrial-scale distillation campaign against Claude is extracting reasoning and tool-use outputs to train competing models, increasing the risk of unauthor...

UNC6780 open-source software supply chain campaign targeting AI environments

Campaign
H score45 First: 08.09.2026 15:02 Last: 08.09.2026 15:02 Sources 1

About this happening: UNC6780 is running a large-scale open-source supply-chain campaign that targets AI-assisted coding tools and software dependencies across PyPI, npm, and Docker Hub...

AIR Security emerges from stealth with $50 million funding and AIR firewall

Commercial Activity
H score18 First: 03.09.2026 15:00 Last: 03.09.2026 15:00 Sources 1

About this happening: AIR Security has emerged from stealth with $50 million in funding and the launch of AIR, a firewall built for AI agents. The rollout expands the market for agent s...

Aurora campaign expands across multiple victims

Campaign
H score24 First: 31.08.2026 14:47 Last: 31.08.2026 14:47 Sources 1

About this happening: The Aurora (aka Aur0ra) ransomware operator used Cursor Agent with Claude Sonnet to assist hands-on exploitation against 10 targets between April 8 and May 21, 2...

Aurora ransomware Cursor Agent exploitation campaign

Campaign
H score24 First: 28.08.2026 11:00 Last: 28.08.2026 11:00 Sources 1

About this happening: Aurora ransomware operators used Cursor Agent and Claude Sonnet to support post-compromise exploitation against 10 victims between April 8 and May 26, 2026...

Timeline

  1. 11.09.2026 17:29 3 articles · 10d ago

    Anthropic warns Claude models are being used for cyber attacks and mass surveillance

    Initial Disclosure

    Anthropic warned that Claude models were being used by cybercriminals and state-sponsored hackers for cyber attacks, weapons design, propaganda, and mass surveillance, and said the use of AI had gone beyond simple chatbot prompting into multi-agent frameworks executing reconnaissance, exploitation, credential harvesting, and data exfiltration.

    Show sources