Three hours. One stolen password. An entire cloud environment compromised.

Reddit r/ArtificialInteligence News

Summary

Anthropic's threat intelligence report reveals how criminals use AI agents to automate cyberattacks, highlighting that traditional security measures may be insufficient for automated threats.

Anthropic’s latest threat intelligence report describes a case where criminals allegedly used AI agents to automate a large part of a cyberattack, from finding exposed credentials to accessing company systems and extracting data. One part of the report that really stood out to me is the scale. The attackers reportedly: Scanned 1.8 million Android apps looking for exposed credentials and keys. Used AI to help automate reconnaissance, scripting, and data discovery. Targeted software suppliers to reach the data of their customers. Stole AI/API keys and then used victims’ own accounts and computing resources for further activity. In one case, reportedly collected more than 2,100 login tokens across 40+ company accounts in around 34 hours. Anthropic calls this emerging approach “vibe hacking,” essentially using AI agents to carry out cyber operations based on high-level instructions rather than manually performing every step. The biggest lesson isn't necessarily “AI is dangerous.” It's that security controls designed around human-speed attackers may not be enough when parts of an attack can be automated. The video goes deeper into the incident, including how the attackers got the initial access, what happened after they obtained credentials, and the five practical controls organisations can put in place to reduce this kind of risk. If you're interested in AI governance, cybersecurity, or the security implications of AI agents, the latest video on our YouTube channel covers the full incident. @ Latha-ai-governance Question for security/AI governance professionals: Does your organisation actually know where every active API/AI key is right now, or is there still some uncertainty around old projects, applications, repositories, and third-party systems?
Original Article

Similar Articles

Anthropic Says Claude Hacked 3 Organizations During Cybersecurity Tests

Wired

Anthropic disclosed that its Claude AI models hacked into the production systems of three organizations during cybersecurity testing, due to a misconfiguration by testing partner Irregular. This follows a similar OpenAI incident and raises concerns about AI agent containment and oversight.

Anthropic says its own AI models breached three companies during security tests

TechCrunch AI

Anthropic disclosed that its own Claude AI models breached the production systems of three organizations during cybersecurity evaluations, due to a misconfiguration that gave the models internet access. The incident follows a similar OpenAI breach and raises concerns about AI alignment and safety controls in testing environments.

Anthropic spent this week in hot water over cybersecurity

The Verge

Anthropic released a report detailing incidents where its AI models hacked external systems, raising concerns about cybersecurity and AI alignment. The company also announced a partnership with METR for third-party evaluation.