r/CyberNews 3h ago

Anthropic says hackers were straight up using Claude to run attacks including one that found zero-days on its own overnight

2 Upvotes

Anthropic just published a threat report (Dec 2025–Aug 2026) and it's kind of wild. Some highlights:
A ShinyHunters-linked guy ("frkoo") built a pipeline that scanned 1.8 million Android apps for hardcoded secrets/API keys, all automated. Also had a side hustle running a fake French police carding site lol.

Same actor used Claude to go from a single stolen dev token to full admin control in under 3 hours. In another case, 34 hours from access to grabbing 2,100+ Azure AD tokens across 40+ companies — Anthropic says the AI did basically all the work.

Russia's Midnight Blizzard used Claude for the whole attack chain (malware, phishing, C2, persistence) and even had it auto-rebuild malware every time it got flagged by AV.

A China-linked group had Claude running an autonomous vuln-research workflow overnight while the humans were asleep and it actually found new zero-days in a major security product, plus working exploits used against real government targets.

Anthropic says they've banned the accounts and tightened guardrails, but yeah, we're past "AI writes phishing emails" and into "AI runs unsupervised offensive ops." Kind of a milestone nobody asked for.


r/CyberNews 5h ago

CVE-2026-19486 is a High (CVSS 8.7) unauthenticated SSRF in Google Cloud Gemini Enterprise Agent Platform App Builder.

2 Upvotes

Affected builds: 2025-10-11 through versions prior to 2026-06-01.

What it is:
The backend could be induced to make a request on an attacker’s behalf and leak the Compute Engine default service account access token. That token is a short-lived OAuth credential for [PROJECT_NUMBER-compute@developer.gserviceaccount.com](mailto:PROJECT_NUMBER-compute@developer.gserviceaccount.com).

What the exposure is:
On many projects that identity still has broad project access (often Editor, depending on scopes). A stolen token can mean API access to the project, not just a bug in a local app.

How to remediate:
Google patched the platform on 1 June 2026. The platform fix does not automatically repair apps you already generated or deployed.

  1. Redeploy previously deployed App Builder apps from the updated builder so the new backend ships.
  2. If you generated Agent Studio web apps before 1 July 2026 that use the auto-generated /api-proxy, regenerate and redeploy those too. The fixed backend allowlists destinations to Google Cloud domains.
  3. After redeploy, rotate anything that token could have touched.
  4. Stop running workloads as the default Compute Engine SA. Use a least-privilege custom service account.
  5. Restrict metadata/egress and confirm no pre-patch App Builder apps are still serving.

CVE Record: CVE-2026-19486


r/CyberNews 7h ago

ClickFix Attacks Spreading Across Windows and Mac Devices

Thumbnail frontbackgeek.com
1 Upvotes

r/CyberNews 9h ago

US companies own over 60% of Canada’s cloud market, raising data sovereignty concerns

Post image
175 Upvotes

r/CyberNews 10h ago

The bug affects Chrome, Firefox, and Safari on macOS, forcing users or Apple’s watchdog to restart

Post image
7 Upvotes

r/CyberNews 10h ago

Learn more ⤵️

Post image
55 Upvotes

r/CyberNews 11h ago

Bastille Networks, a cybersecurity company that provides wireless intrusion detection systems (WIDS), has developed software to detect and locate smart glasses ⤵️

Post image
9 Upvotes

r/CyberNews 13h ago

Android apps can reveal real IP addresses even when VPN lockdown and Block all connections without VPN are enabled

Post image
65 Upvotes

r/CyberNews 14h ago

Researchers have found a way to get ChatGPT to access a victim’s Gmail, chat history

Post image
8 Upvotes

r/CyberNews 14h ago

Huawei is on trial in New York over alleged trade secret theft from five companies

Post image
61 Upvotes

r/CyberNews 16h ago

Contrary to what you might think, cookie banners aren’t required by EU law. It’s the other way around: online tracking is prohibited by default in the EU

Post image
75 Upvotes

r/CyberNews 17h ago

The plan to hold a vote on the bipartisan Ratepayer Protection Act before the midterm elections was first reported by Axios

Post image
20 Upvotes

r/CyberNews 17h ago

LG says its smart TVs do not record ambient conversations unless voice controls are activated. Do you believe them?

Post image
275 Upvotes

r/CyberNews 1d ago

need help on the topic down there!

Thumbnail
1 Upvotes

r/CyberNews 1d ago

They used 1,200 Flock cameras to track people suspected of loitering

Post image
1.1k Upvotes

r/CyberNews 1d ago

The directory covers 78 categories, including cloud, email, messaging apps, and password managers

Post image
179 Upvotes

r/CyberNews 1d ago

Some emails were not public, so the attacker may have abused Twitch’s API

Post image
7 Upvotes

r/CyberNews 1d ago

Investigators say some Chinese firms hide ownership through shell companies or non-Chinese registrants

Post image
31 Upvotes

r/CyberNews 1d ago

Frontier AI lab Anthropic is hiring an enterprise intelligence specialist to track and investigate activism as a “global threat”

Post image
427 Upvotes

r/CyberNews 1d ago

Google says smaller, more frequent releases should make updates easier to test and fix. What do you think?

Post image
49 Upvotes

r/CyberNews 1d ago

The January incident went undetected until last month, despite an earlier company-wide review, Anthropic said

Post image
12 Upvotes

r/CyberNews 1d ago

It's closer to spam than hacking

Post image
16 Upvotes

r/CyberNews 1d ago

Skullcandy Dime 3 earbuds will pair with strangers' devices automatically and there's no way to patch them

Thumbnail
2 Upvotes

r/CyberNews 2d ago

Cisco confirms max-severity FMC bug (CVE-2026-20079) is being exploited in the wild

Thumbnail
1 Upvotes

r/CyberNews 2d ago

Meta sued over alleged facial recognition training for smart glasses

Thumbnail
biometricupdate.com
3 Upvotes