Markets
Anthropic's September Threat Report: A Stolen Developer Token Became Full Cloud Admin in About Three Hours
Anthropic's September 10 threat intelligence report describes ShinyHunters affiliates escalating from one stolen developer token to full cloud admin access in about three hours. In a separate incident, operators pulled more than 2,100 Azure AD tokens from 40+ corporate tenants in about 34 hours. It also names a Chinese group whose operators included two undergraduates, running agent-swarm exploit work against about 50 organizations and producing more than a dozen possible zero-days in a month. For SaaS vendors this means the gap between a leaked token and a multi-tenant compromise is now measured in hours, which argues for short-lived credentials and per-tenant blast-radius limits.
↳ Follow the thread