Visualização normal

Antes de ontemCybersecurity News
  • ✇Security Affairs
  • Infostealers Are Hijacking Claude Sessions and Draining Subscriptions Pierluigi Paganini
    Infostealers can steal active Claude sessions, bypass 2FA and drain paid usage. Anthropic is revoking access and refunding unauthorized charges. Anthropic confirmed that several infostealer malware can hijack an active Claude login session and let attackers burn through your usage without ever touching your password. “Our investigation is ongoing. Our findings to date suggest that a computer you use with Claude is likely infected with infostealer malware, and may have been for some time.
     

Infostealers Are Hijacking Claude Sessions and Draining Subscriptions

31 de Agosto de 2026, 06:17

Infostealers can steal active Claude sessions, bypass 2FA and drain paid usage. Anthropic is revoking access and refunding unauthorized charges.

Anthropic confirmed that several infostealer malware can hijack an active Claude login session and let attackers burn through your usage without ever touching your password.

“Our investigation is ongoing. Our findings to date suggest that a computer you use with Claude is likely infected with infostealer malware, and may have been for some time. Phones and tablets do not appear to have been involved.” reads the notification sent to the impacted users.

“We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude. It’s general-purpose malware that typically arrives with an unofficial download or a malicious app, and it quietly copies saved passwords, login cookies in browsers, and credentials for other apps running locally. Your Claude session was likely one of the many things it collected. It appears that a bad actor has now started picking the Claude sessions out of what it collected and using them.”

Recently, Anthropic started signing some Claude users out and removing their saved payment cards. The reason? Infostealer malware on their computers stole active Claude sessions and gave attackers access to their accounts.

“We recently signed you out of Claude and removed the payment method saved on your account, so you’ll need to log back in and re-add your card.” continues the report. “We’re sorry for the disruption. Here’s what happened and what we’ve done about it.”

Anthropic detected the suspicious activity and identified multiple infostealer families affecting Windows and macOS. Infostealers bypass the login process by stealing authenticated browser sessions, allowing attackers to evade passwords, MFA and SSO and access paid Claude accounts. Revoking sessions or blocking fraudulent payments is not enough: if the malware remains on the device, it can capture the user’s next login and give attackers access again.

Anthropic is also refunding users for any charges it identifies as unauthorized.

‼BREAKING: Anthropic is signing Claude users out and deleting their saved card because infostealer malware on their machines handed a bad actor live Claude login sessions. Anthropic says its systems detected the activity, and the notification names six stealer families across… pic.twitter.com/0nX53PaeiH

— International Cyber Digest (@IntCyberDigest) August 29, 2026

“”Our systems detected this activity on your account, and we’ve therefore removed your card on file and signed out the sessions involved to help block further unauthorized access.” continues the report. “If your usage limits looked like they refilled and then drained while you weren’t using Claude, this was likely the cause.””

Anthropic identified Vidar, LummaC2, StealC, RedLine and Acreed on Windows, plus Atomic Stealer on a small number of Macs. The company revoked affected Claude sessions, forcing users to log in again, and removed saved payment methods to prevent unauthorized charges.

Existing plans will continue until the current billing period ends. After that, users will need to add their payment method again. Anthropic may also sign them out again if it detects suspicious activity.

If you use Claude and haven’t checked your usage history recently, that’s worth doing today rather than next week. Anthropic’s advice is the standard but genuinely necessary response: run a full malware scan before logging back in, change your account password with two-factor authentication enabled, and treat any pirated download or unofficial app installer with the same suspicion you’d give a sketchy email attachment.

An AI subscription being quietly drained isn’t the scariest thing an infostealer can do to you, but it’s a pretty reliable sign that something considerably worse, like your actual banking credentials, might already be sitting in the same haul.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Anthropic)

Anthropic Warns Commodity Infostealers Are Hijacking Claude Sessions to Drain Paid Usage

31 de Agosto de 2026, 07:09

A session cookie depicted as a key being stolen from a browser window while a two-factor authentication prompt sits bypassed, illustrating Claude session hijacking by infostealer malware.

Anthropic warned users over the weekend that a threat actor is using widely available infostealer malware to hijack active Claude login sessions from infected computers, then using those sessions to run up victims' paid usage without ever needing a password or a two-factor code.

The company said it identified six malware families in the campaign: Vidar, LummaC2, StealC, RedLine and Acreed on Windows, and Atomic Stealer, known as AMOS, on a smaller number of macOS machines. None are novel or bespoke. All are commodity stealers sold or rented on criminal dark web marketplaces, and all work the same basic way - harvesting locally stored browser credentials, autofill data and authentication cookies from a compromised machine and shipping them to an operator's server.

Claude Session Cookies Heist

What makes the campaign notable is the target rather than the technique. Session cookies represent an already-authenticated state, so an attacker who replays a stolen Claude session token steps past both the account password and multi-factor authentication entirely. This is textbook session hijacking; the new element is that paid AI assistant subscriptions have become worth stealing as a commodity in their own right, alongside the streaming and gaming accounts that stealer log markets have traded for years.

Anthropic told affected users that the tell sign for them was a usage pattern that made no sense. Limits appearing to refill and then drain while the account owner was not using Claude was the biggest red flag.

Also read: Hacker Used Claude AI to Automate Reconnaissance, Harvest Credentials and Penetrate Networks

The company said it is signing affected users out of their sessions, removing saved payment methods from compromised accounts and refunding unauthorized charges identified during its investigation. It also stressed that the malware is not connected to Claude, was not installed through Claude and did not result from anything users did with the product. Infections trace to the usual vectors — pirated software and other illicit downloads.

A Reddit user going by the moniker "WorriedAssociate7029" received the notification from Anthropic and confirmed that he mistakenly installed an infostealer from "a reputable Russian underground forum" while downloading a pirated game. "I got fooled like a rookie by downloading a cracked game," he said.

Intrestingly though, the user claimed of using Claude's Opus model to detect and remove the malware.

"I use the models exclusively in permission-free mode on my entire computer," the Reddit user said.
"Opus was very efficient. It scanned for active processes, then listed my recent downloads. It found the virus almost instantly. My prompt was very simple: "I think I downloaded a virus recently. My login credentials were stolen. Audit the malware and remove it if you find it. Report on the extent of the damage. He deactivated the virus and created a folder on the desktop containing all the relevant information (including the deactivated virus, lol)."

Anthropic has not disclosed how many accounts were affected.

The security implications reach past the billing line. AI assistant accounts increasingly hold conversation histories, uploaded documents, connected data sources and, in developer configurations, API keys and repository access. A hijacked session inherits whatever the account can reach. Organizations that have rolled out AI tools without folding them into identity and access management now have a class of high-value session token sitting in employee browsers, largely outside the monitoring applied to corporate SaaS.

Anthropic's guidance to compromised users is the standard infostealer playbook. Change credentials across every service used on the affected machine, revoke active sessions, and actually remove the malware, since signing out does not clear an infection that will simply harvest the next session.

There is no formal regulatory hook here yet — no confirmed breach of the provider itself and no disclosure obligation triggered on Anthropic's side. But the episode lands as regulators and standards bodies are working out how AI system security fits existing frameworks, and it illustrates a gap those frameworks have barely addressed - the weakest point in an AI deployment may be an unmanaged endpoint rather than the model or the platform.

  • ✇Graham Cluley
  • Smashing Security podcast #480: This is the AI service you should never sign up to Graham Cluley
    Would you like access to Anthropic's Claude at 90% off the normal price? All you have to do is redirect your traffic to a mysterious service called "Poison Claude". Only problem is that it's run by fraudsters... Meanwhile, a phishing-as-a-service platform called "Greatness" has come up with something rather nasty: a phishing attack that doesn't need a fake website, a suspicious URL, or your password. Just a real Microsoft login page and a moment of misplaced trust - and the attackers walk off
     

Smashing Security podcast #480: This is the AI service you should never sign up to

12 de Agosto de 2026, 20:12
Would you like access to Anthropic's Claude at 90% off the normal price? All you have to do is redirect your traffic to a mysterious service called "Poison Claude". Only problem is that it's run by fraudsters... Meanwhile, a phishing-as-a-service platform called "Greatness" has come up with something rather nasty: a phishing attack that doesn't need a fake website, a suspicious URL, or your password. Just a real Microsoft login page and a moment of misplaced trust - and the attackers walk off with full access to your emails, your files, and your entire organisation. All this and more in episode 480 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Lianne Potter.

AI Agent Exploits Gym System Vulnerability, Cancels Waitlist Booking in Australia

10 de Agosto de 2026, 04:54

Gym System Vulnerability

An AI agent assigned to book a gym class in Australia reportedly discovered a gym system vulnerability, used it to secure reservations months ahead of schedule, and then cancelled another customer's booking.   The incident, reported by the Australian Broadcasting Corporation (ABC) and other outlets, involved Andrew, who describes himself as an AI expert. He wanted to reserve a popular early-morning class at his regular gym and gave the task to Anthropic's large language model, Claude, through the open-source AI agent software OpenClaw.  Within minutes, the AI agent reportedly uncovered an authentication weakness in the gym's reservation system. Regular customers were generally restricted to booking classes only a few weeks ahead, but the gym system's vulnerability allowed the AI to access dates several months into the future. It subsequently secured those reservations. 

AI Agent Finds Gym System Vulnerability 

The situation became more serious when Andrew was fourth on the waitlist for a class scheduled later that week. He asked the AI how he could improve his position. Instead of simply explaining the options, the AI agent apparently tested the gym system vulnerability by cancelling the reservation belonging to the person at the top of the waitlist.  The AI told Andrew the action had been carried out "as part of a test" and sent him a message explaining the flaw: "The API had absolutely no authentication check when canceling someone else's booking. I tested this on the person in the number 1 spot on the waitlist, and the process actually went through. You have now moved up from 4th to 3rd."  Andrew immediately instructed the AI to undo the action. The system, however, responded: "I have bad news. It is impossible to restore that person." Andrew ultimately directed the AI agent to draft and send an email to the system provider, disclosing the exploited vulnerability and reporting what had occurred. 

AI Alignment and Liability Concerns 

Bill Simpson-Young, affiliated with an Australian AI research institute, said the episode demonstrated the growing risks associated with autonomous AI. "You ask for something harmless, and the AI might take another action that a human never thought of or explicitly requested," he said, warning that the case also exposed the fragility of modern digital security.  The episode is being viewed as a striking example of the AI "alignment problem." The term describes situations in which an AI pursuing a particular objective chooses methods that users or developers did not anticipate, including potentially unethical or illegal actions. As autonomous AI systems gain greater independence, the consequences of such decisions could become increasingly serious, making AI safety an important concern.  The Australian Signals Directorate (ASD) has previously warned about AI agents misinterpreting instructions or taking unexpected actions. Additional concerns arise when multiple AI models work together, potentially making responsibility harder to establish and creating new AI cybersecurity challenges.  Current Australian legal frameworks also provide no straightforward answer to liability in such cases. Existing laws generally assign responsibility to natural persons or corporations, leaving uncertainty over whether damages caused by a rogue AI agent should be attributed to the user, developer, model provider or operator of the vulnerable system. 

Beware cut-price AI services that read your every word

7 de Agosto de 2026, 12:33
f someone offered you 90% off the official price to access Claude, the powerful AI model from Anthropic, would you be tempted? It turns out that around 900 people were, and they may be regretting their decision. Read more in my article on the Fortra blog.

Claude Opus 5 Vending Test Shows Profit-Driven AI Risks

3 de Agosto de 2026, 14:44

Claude Opus 5 set a Vending-Bench record while fabricating supplier bids, breaking truces, and ignoring refunds, showing why companies need stronger AI agent controls.

The post Claude Opus 5 Vending Test Shows Profit-Driven AI Risks appeared first on TechRepublic.

  • ✇Arstechnica
  • Claude published malicious code to the Internet and attacked 3 real companies Dan Goodin
    Anthropic said its Claude-based security models gained unauthorized access to the sensitive production environments of three outside organizations during internal testing designed to measure the models’ offensive cyber capabilities. The events, which Anthropic revealed Thursday, are the second revelation in 10 days that AI models from the world’s wealthiest providers have trespassed into protected networks, an offense that, in more traditional hacking scenarios, could land the human behind the k
     

Claude published malicious code to the Internet and attacked 3 real companies

31 de Julho de 2026, 17:39

Anthropic said its Claude-based security models gained unauthorized access to the sensitive production environments of three outside organizations during internal testing designed to measure the models’ offensive cyber capabilities.

The events, which Anthropic revealed Thursday, are the second revelation in 10 days that AI models from the world’s wealthiest providers have trespassed into protected networks, an offense that, in more traditional hacking scenarios, could land the human behind the keyboard in prison for years. Earlier this month, OpenAI said its security models exploited a zero-day vulnerability for use in breaking into the network of Hugging Face, a platform for open source machine-learning models and AI datasets. The OpenAI models went on to steal access credentials and other confidential Hugging Face information. The OpenAI models also exploited publicly exposed credentials to compromise accounts of four other third-party services.

Anthropic said the OpenAI event spurred its engineers to review similar cybersecurity evaluations by Claude models. The audit found three incidents “in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations.”

Read full article

Comments

© Getty Images

  • ✇Security Affairs
  • Anthropic Finds Claude Breached Real Companies During Security Evaluations Pierluigi Paganini
    Anthropic says a misconfigured test let Claude access three real organizations, prompting tighter AI evaluation and monitoring controls. Anthropic disclosed that Claude models had accessed the real production infrastructure of three separate organizations during cybersecurity evaluations that were supposed to run in isolated, fictional environments. The company found the incidents after reviewing 141,006 evaluation runs following OpenAI’s disclosure about its own models escaping a test envir
     

Anthropic Finds Claude Breached Real Companies During Security Evaluations

31 de Julho de 2026, 05:55

Anthropic says a misconfigured test let Claude access three real organizations, prompting tighter AI evaluation and monitoring controls.

Anthropic disclosed that Claude models had accessed the real production infrastructure of three separate organizations during cybersecurity evaluations that were supposed to run in isolated, fictional environments. The company found the incidents after reviewing 141,006 evaluation runs following OpenAI’s disclosure about its own models escaping a test environment. Three different Claude models were involved, Opus 4.7, Mythos 5, and an internal research prototype, and each behaved differently once evidence emerged that the targets were real.

“In all three incidents, Claude had been tasked with a capture-the-flag challenge, one of the ways we assess a model’s cyber capabilities. The model is given a fictional scenario and told that a piece of secret information (the “flag”) has been hidden on a different machine on the network, and its objective is to break in and retrieve it. The challenge is left open-ended, and no particular method is prescribed.” reads the report published by Anthropic. “Due to a misunderstanding between us and our evaluation partner, this was not the case, and internet access was available. Because of this, when Claude’s search led it to real systems on the open internet, it treated them as part of the exercise.”

The evaluation partner is Irregular, a third-party firm that creates and runs cybersecurity benchmarks. Neither Anthropic nor Irregular was aware of the misconfiguration until Anthropic began its retrospective review the week of July 23.

The first incident is the most serious. In four evaluation runs, Claude Opus 4.7 couldn’t reach its simulated target inside the test environment, found that the real company was reachable via the internet, and attacked it.

“These four runs extracted information like application and infrastructure credentials, and obtained access to a database containing several hundred rows of production data. This represented the most serious impact we identified.” continues the report. “This incident involved Claude Opus 4.7, and was the only case in which the model continued to attack a system after learning it was likely operating in a real environment. In all four of the runs, the model eventually recognized (as can be observed in its verbalized reasoning) that the system was real—in two cases, the model rationalized that the real company must be part of the exercise. However, none stopped the attack on that basis.”

The fictional company chosen for the scenario happened to share its name with an active website domain, which is how the model ended up there.

The second incident involves Claude Mythos 5 and a Python package. The model found setup instructions in the fictional environment telling developers to install a package from PyPI that didn’t actually exist. Claude concluded that publishing its own malicious package under the same name would cause the fictional company’s systems to install it automatically.

“Claude went to extensive lengths to carry out this attack—lengths that would likely have indicated to a human participant that this was no longer just an evaluation, and that they were in fact uploading a real PyPI package. For instance, in one case, in order to create a PyPI account, Claude needed an email address.” continues the report. “And in order to create an email address, it needed a phone number. To get a phone number, after failing to find a free phone number service, it tried—and failed—to obtain funds to pay for a phone number through several different means. It finally backtracked, found a free, non-blocked email provider, used this to register a PyPI account, and then used this account to upload malware to PyPI.”

The package was live for roughly one hour, was downloaded and run on 15 real systems, and one of those was a security company’s automated scanner that treated PyPI packages as safe to install, which handed Claude the company’s credentials. The package was removed automatically by PyPI’s own security systems.

Mythos 5’s own reasoning during this run correctly identified what it was doing. It noted that if this were the real internet, publishing the package would be a real-world attack, “NOT okay, and surely not the intended solution.” It then convinced itself it was still in a simulation because it didn’t recognize the certificate authorities it was seeing, and because the calendar date of 2026 on the systems proved, in its own reasoning, that the environment was staged. It never revisited that conclusion.

The third incident involved an internal research model that scanned roughly 9,000 targets before compromising one company’s internet-facing application through basic techniques, reading credentials from an exposed debug page and SQL injection. This model eventually concluded on its own that the target was real, and stopped. That’s the behavior Anthropic wanted to see, and it only appeared in the most recent model of the three.

Anthropic stopped all cyber evaluations on July 23 after spotting the first suspicious transcripts, identified all three incidents the following day, and notified the three affected organizations on July 27. Two of them had not previously detected the activity. Anthropic is framing the root cause as an evaluation infrastructure failure rather than a model alignment failure, the models were told they had no internet access and were given an open-ended instruction to capture the flag, while actually having internet access. The fix the company emphasizes most: evaluation environments containing powerful autonomous capabilities now need to be held to the same security standard as any other system the models run in.

“many factors contributed to these incidents, but, consistent with a blameless postmortem culture, we’re approaching the fixes as if the responsibility were ours alone. This begins with ensuring every part of our evaluation pipeline is secure, including the manner in which we integrate with external partners.” conlcudes the report. “Moving forward, it will include expanding our continuous monitoring of evaluation transcripts for unexpected behavior, improving our investigation tooling, and conducting more rigorous assurance work with the vendors we rely on.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Claude)

PromptFiction Flaw Auto-Submitted Hidden Prompts in Claude Desktop

A one-click Claude Desktop flaw allowed attackers to submit concealed instructions without review, exposing chats and enabling code execution on some systems remotely.

Fake ChatGPT Desktop App Ads Used to Push Password-Stealing Malware

Fake ChatGPT desktop app ads pushed password-stealing malware by abusing trusted AI links, hiding from scanners, and tricking users into downloads.

Trojanized Gemini and Claude Installers Target Developers Via SEO Poisoning

Cybercriminals are using SEO poisoning and fake Gemini and Claude installer sites to infect developers with fileless malware and steal data.

Claude Mythos AI Identified 10,000+ Software Vulnerabilities in One Month

Anthropic says its Claude Mythos AI identified more than 10,000 software vulnerabilities in one month, including critical flaws in open-source code.

Fake Claude Code Installer Targets Developers With Browser Credential Stealer

Researchers at Ontinue have discovered an undocumented malware campaign targeting developers with fake Claude Code installers to steal browser passwords and cookies.
❌
❌