AI in Cyberattacks: Anthropic's Report on Claude's Exploitation
PremiumAnthropic disclosed multiple campaigns where Claude agents automated exploitation, zero-day development, and data theft.
§Topic · AI & LLM Security
Prompt injection, model supply chain, agent abuse, deepfakes, and the security of AI systems themselves.
All dispatchesResearchers demonstrate a WeChat zero-click worm capable of hijacking phones via crafted calls using AI tooling.
Infostealer logs reveal replayable AI tokens and API keys that attackers reuse to access model providers, bypassing MFA protections.
DeepSeek Harness flaw allowed sandboxed AI agents to disable their file sandbox, risking arbitrary access to host files.
Researchers describe workflow identity hijacking where AI automation's privileged identities are abused to exfiltrate sensitive data.
Actor used hundreds of AI agents to craft exploits for PaperCut NG/MF flaws and breached over 440 vulnerable instances.
A ChatGPT sandbox flaw allowed covert cross-account channels to exfiltrate Gmail data from connected accounts via hidden communications.
OpenAI's GPT-6 Astra can find zero-days autonomously, raising detection and monitoring challenges for security teams.
A planted prompt in ChatGPT could cause hidden actions that read Gmail data and exfiltrate it to another ChatGPT account.
Get these articles delivered to your inbox.
Subscribe free