A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.

Reports indicate that users of Anthropic's Claude AI platform have been targeted in a series of infostealer attacks. The attacks reportedly involved a threat actor deploying various infostealing malware to compromise user systems, subsequently collecting session information, and then using this data to gain unauthorized access to the affected users' Claude accounts. The scope of the compromise, including the number of users impacted, has not been disclosed.
The technical mechanism behind these attacks centers on the use of infostealers, a broad category of malware designed to exfiltrate sensitive data from compromised machines. In this specific instance, the focus was on session information. Session tokens or cookies are small pieces of data that a web server sends to a user's browser, allowing the server to remember the user's state and authenticate them across multiple requests without requiring re-entry of credentials. When an infostealer successfully extracts these tokens, an attacker can effectively "replay" the session, impersonating the legitimate user to access their account without needing their password.
The affected product in this incident is Anthropic's Claude, an artificial intelligence chatbot. As a cloud-based service, access to Claude accounts is typically managed through web browsers or dedicated applications, both of which rely on session management for user authentication and continuity. The compromise of session information directly impacts the security of these accounts, regardless of the strength of the user's password, as the attacker bypasses the traditional login process.
The likely scope of such an incident can vary widely, but it typically depends on the distribution method of the infostealer and the vigilance of users. Infostealers are commonly spread through phishing campaigns, malicious downloads, drive-by downloads from compromised websites, or bundled with pirated software. Users who fall victim to these distribution methods would have their systems compromised, leading to the exfiltration of their session data.
Mitigation guidance for this class of issue generally emphasizes robust endpoint security and user awareness. Users are typically advised to maintain up-to-date antivirus and anti-malware software, exercise caution when opening attachments or clicking links from unknown sources, and avoid downloading software from unofficial repositories. For services like Claude, enabling multi-factor authentication (MFA) is a critical defense, as it introduces an additional verification step that would ideally prevent an attacker from using stolen session tokens alone to gain access. Regularly clearing browser cookies and logging out of sessions when not actively using a service can also reduce the window of opportunity for stolen session data to be exploited.
This incident underscores the persistent threat posed by infostealing malware, which continues to evolve in its sophistication and targeting. As more critical services migrate to cloud platforms and rely on session-based authentication, the compromise of session information represents a significant risk. It highlights the shared responsibility between service providers, who must implement robust security measures, and users, who must adopt best practices for digital hygiene to protect their accounts and data in an increasingly complex threat landscape.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets