LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
ai

Anthropic: AI Misuse Is Entering a New Phase: From Cybercrime to Surveillance, Propaganda and Weapons

AI is becoming an operational force for cybercrime, surveillance, propaganda, fraud and weapons development, lowering the cost and scale of attacks. Artificial intelligence (AI) is becoming more than a tool for people who want to do something malicious. It is increasingly becoming part of the operational machinery itself. That is the main message emerging from […]

zeroday.news ·

Artificial intelligence (AI) is transforming malicious activity, shifting from being merely a tool for bad actors to becoming an integral part of operational machinery across various attack chains. This is the central finding of a recent threat intelligence report from Anthropic, covering activity identified and disrupted between December 2025 and August 2026. The report highlights AI's role in cyber operations, influence campaigns, surveillance, fraud, biological research, conventional weapons development, and attempts to extract capabilities from frontier AI models.

The report notes that AI is not necessarily introducing new attack techniques but is fundamentally altering the economics, speed, and scale of malicious operations. AI systems are now contributing across nearly the entire attack chain, from reconnaissance and tool development to exploitation, credential theft, data processing, and exfiltration. Anthropic observed instances where AI executed commands against victim networks, harvested credentials, and exfiltrated information. In more autonomous scenarios, multi-agent frameworks conducted reconnaissance, exploitation, and data theft against multiple targets simultaneously, sometimes for extended periods with minimal human intervention.

This operational shift means that sophisticated attacks no longer exclusively require sophisticated attackers. AI is narrowing the gap between well-funded state operations and smaller criminal groups by automating tasks that previously demanded multiple specialists, such as reconnaissance, exploitation, coding, and data analysis. While underlying attack methods like stolen credentials, exposed services, vulnerable edge devices, phishing, and SQL injection remain prevalent, AI significantly reduces the cost of orchestrating these at scale.

One clear example cited in the report involves a financially motivated operation that harvested credentials from software and online services. Attackers downloaded and analyzed 1.8 million Android application packages (APKs) to find hardcoded secrets, while simultaneously collecting GitHub-related credentials. This operation, attributed to a French-speaking operator using aliases such as MeowSHA, frkoo, and blazespider, utilized a distributed credential-harvesting pipeline across 10 AWS EC2 workers. This pipeline mass-downloaded, decompiled, and scanned Android APKs from various app stores using TruffleHog. Verified findings were routed in real time to a Telegram group, and a parallel GitHub email harvester fed a second stream of stolen GitHub Personal Access Tokens. These two credential pipelines supplied initial access for confirmed breaches linked to frkoo.

Anthropic confirmed that its Claude AI model was used by attackers to engineer and test tooling for such operations. The report details how stolen tokens were replayed against Microsoft services to access mailbox contents, including deleted messages, with techniques designed to mimic legitimate Microsoft client traffic. The significance lies not in AI inventing new attacks, but in its ability to automate existing processes, enabling smaller teams to conduct operations that previously required a much larger workforce.

Beyond cybercrime, the report also details the use of AI in surveillance. Anthropic identified nation-state actors and commercial surveillance operators using Claude to build systems for monitoring populations, profiling individuals, and analyzing social media activity. These cases involved actors linked to China, Iran, and West Africa, as well as the commercial "surveillance-for-hire" market. Anthropic's Usage Policy explicitly prohibits using Claude for non-consensual surveillance and profiling, or for violating civil liberties and human rights, and the threat actors in these cases attempted to circumvent controls designed to detect such misuse.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.

vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]