LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
security

Latest Anthropic horror story chills with tales of kamikaze drone swarms and bioweapons research

Everyone from ShinyHunters to Russian freelancers is in on the illicit model fun

zeroday.news ·

Anthropic has issued a new warning detailing how its Claude AI models are being misused by various malicious actors, including state-sponsored groups and cybercriminals, for purposes ranging from automating cyberattacks to developing biological and conventional weapons. The report, which covers activity observed and disrupted between December 2025 and August 2026, identifies seven key areas of misuse: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation.

The company noted that while its most powerful Claude Fable or Mythos-class models were largely unaffected, with only one instance of distillation identified, its Claude Haiku, Sonnet, and Opus models were implicated in numerous incidents. This marks a significant expansion from an earlier report in November, which primarily focused on Chinese espionage groups using Claude for digital intrusions.

Among the confirmed incidents, a Russian state-sponsored cyber espionage group, identified by Anthropic as GTG-20006 (also known as Midnight Blizzard, APT29, or Cozy Bear), utilized AI to automate the entire kill chain of its cyberattacks. This accelerated their operations from development and infrastructure acquisition to phishing, persistence, command and control, and data exfiltration. Anthropic observed over 20 organizations targeted by GTG-20006, including embassies, think tanks, defense-industrial companies, and government, defense, and intelligence agencies across Ukraine, Europe, the Middle East, Asia, and North Africa.

Separately, multiple clusters linked to the ShinyHunters data-theft-and-extortion gang employed Claude to scale their operations. One affiliate specializing in supply-chain attacks breached a software-as-a-service provider, subsequently stealing data from approximately 200 of the SaaS company’s customers. This included a session-store dump containing over 2,100 Azure AD token sets across more than 40 corporate tenants, all executed by AI agents over roughly 34 hours.

Anthropic’s report also highlighted five cases of users in "unsupported regions" attempting to leverage Claude for biological weapons development. One instance involved a scientist using Claude to draft a grant application for research into the chikungunya virus, focusing on its transmissibility and immune evasion properties. While such research could aid vaccine development, Anthropic expressed concern that it could also be used to enhance the pathogen's danger, particularly given the military research institute involved. In another case from May, a user outside the US used Claude in research on adaptations of highly pathogenic avian influenza (bird flu), specifically H5 viruses, which are known for causing severe neurological involvement in various species, including some human cases.

New categories of misuse identified since the November report include the development of software for conventional weapons. Anthropic detailed six such cases: three in China, two in Russia, and one in Yemen. In Yemen, a weapons development program used Claude to develop guidance, navigation, and control (GNC) software for flying vehicles and attempted to develop guided weapons. Although Anthropic's safeguards blocked many requests, the team reportedly test-fired a guided rocket and built an offline simulation toolkit.

In China, an individual believed to be associated with a Chinese defense industry manufacturer used Claude to draft a Chinese-language specification for an anti-torpedo fire control system and benchmark it against US anti-torpedo and anti-submarine programs. The actor used Claude to refine the acquisition proposal and to build components of the fire control software and a test matrix. Additionally, a likely Russian "freelance team" used Claude to write and test code for a full-stack autonomous first-person-view (FPV) kamikaze drone swarm. Anthropic banned accounts associated with these activities and shared threat intelligence with partners.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.