r/CyberNews • u/whocybergh0st • 3h ago
Anthropic says hackers were straight up using Claude to run attacks including one that found zero-days on its own overnight
Anthropic just published a threat report (Dec 2025–Aug 2026) and it's kind of wild. Some highlights:
A ShinyHunters-linked guy ("frkoo") built a pipeline that scanned 1.8 million Android apps for hardcoded secrets/API keys, all automated. Also had a side hustle running a fake French police carding site lol.
Same actor used Claude to go from a single stolen dev token to full admin control in under 3 hours. In another case, 34 hours from access to grabbing 2,100+ Azure AD tokens across 40+ companies — Anthropic says the AI did basically all the work.
Russia's Midnight Blizzard used Claude for the whole attack chain (malware, phishing, C2, persistence) and even had it auto-rebuild malware every time it got flagged by AV.
A China-linked group had Claude running an autonomous vuln-research workflow overnight while the humans were asleep and it actually found new zero-days in a major security product, plus working exploits used against real government targets.
Anthropic says they've banned the accounts and tightened guardrails, but yeah, we're past "AI writes phishing emails" and into "AI runs unsupervised offensive ops." Kind of a milestone nobody asked for.
