A Google Threat Intelligence Group analyst named Larsen ran a covert operation to observe the hacker collective TeamPCP, gaining access to a server where the group stored stolen credentials from numerous victim companies. Google used this visibility to rapidly notify cloud providers like AWS and Microsoft to revoke compromised access tokens before the hackers could exploit them for extortion, rather than trying to contact each victim individually.
arstechnica.com
· 2026-09-20
Google's Threat Intelligence Group disclosed a credential-harvesting operation where attackers compromised cloud infrastructure and deployed a multi-agent AI framework that scanned for vulnerabilities, fixed its own errors, and rotated IP addresses largely without human input. The entire campaign, which compromised thousands of third-party credentials, took less than six hours to execute. Separately, Microsoft found AI-assisted phishing messages reaching click-through rates of 54%, compared to roughly 12% for conventional campaigns.
bleepingcomputer.com
· 2026-09-17
Anthropic disclosed in a threat intelligence report that it detected and shut down efforts to use its Claude AI models for potentially dangerous purposes, including activity that could aid biological weapons development. The report also details other misuse cases involving state-linked actors from Russia and Iran, scam operations, surveillance tools, and alleged attempts by Chinese firms to copy Claude's technology.
bbc.co.uk
· 2026-09-11
Anthropic's Threat Intelligence team disclosed that it identified and shut down multiple cyber operations run by state-sponsored groups, financially motivated criminals, and politically motivated actors who abused its Claude Haiku, Sonnet, and Opus models. The company said no misuse was found involving Claude Fable or Mythos, which carry stronger safeguards, and that in every case it disrupted the activity, patched its defenses, and coordinated with law enforcement and industry partners.
anthropic.com
· 2026-09-10
Google's Threat Intelligence Group reports that attackers are moving from simple AI-assisted coding to fully autonomous, multi-agent systems that plan and execute entire attacks with little human input. In one case, a financially motivated actor compromised cloud infrastructure and used an AI coding chatbot with markdown-based agent instructions to build and run a mass credential-harvesting operation in under six hours. Separately, researchers found an exposed command-and-control server running a framework called 'Recon' that autonomously managed reconnaissance and tens of thousands of harvested credentials.
bleepingcomputer.com
· 2026-09-08
Anthropic's threat intelligence chief Jacob Klein says foreign actors, particularly in China, are using illegal methods to extract outputs from its Claude models and train cheaper rival systems, a practice known as distillation. He named Moonshot AI's Kimi K3 model as an example of technology he believes was built this way, describing an organized effort to evade Anthropic's account and access controls at scale.
cnbc.com
· 2026-09-03
Palo Alto Networks' Unit 42 team says its new Frontier AI Defense service, which pairs threat intelligence with AI models, compressed roughly one to two years of penetration testing into three weeks and found dozens of vulnerabilities in customer systems. The researchers warn that the same AI-driven speed and automation available to defenders could soon give low-skill attackers, known as script kiddies, capabilities once reserved for well-funded, state-sponsored hacking groups.
zdnet.com
· 2026-08-27
ESET's Director of Threat Research, Jean-Ian Boutin, explained how his team's intelligence work integrates into ESET's Managed Detection and Response (MDR) offering. He outlined how combining automated detection technology with human analyst expertise gives small and midsize businesses access to proactive threat hunting capabilities they couldn't otherwise afford to build in-house.
bleepingcomputer.com
· 2026-08-27