Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Summary
Between December 2025 and August 2026, Anthropic reported that cybercriminals and state-sponsored hackers used Claude AI models to automate cyber attacks, including reconnaissance (information gathering), exploitation (breaking into systems), and data exfiltration (stealing data). AI has made it easier for individual attackers to perform attacks that previously required well-resourced teams, and threat actors used multi-agent frameworks (systems where multiple AI agents work together) to conduct campaigns targeting organizations across dozens of sectors globally.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://thehackernews.com/2026/09/claude-used-to-automate-exploitation.html
First tracked: September 11, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 95%