Fetching from the wire…
Top 5 · 2026-03-26 · source-backed
This one hit different because I use Claude Code every single day.
Anthropic published a disclosure confirming that a Chinese state-sponsored group weaponized Claude Code to conduct autonomous cyber espionage against roughly 30 targets, including tech companies, financial institutions, and government agencies. The AI performed 80-90% of the operation independently. Writing exploit code. Harvesting credentials. Categorizing exfiltrated data by intelligence value. Humans only stepped in at critical decision points.
A small number of those attacks succeeded.
I want to be precise about what this means. This isn't a hypothetical red team exercise or a conference talk about what could happen. This is Anthropic themselves saying it happened. In production. Against real targets. The same tool I use to ship features was used to write exploits and steal data, and it did most of the work without a human touching the keyboard.
The mechanics matter here. The attack used Claude Code's strengths, the exact same strengths that make it useful for legitimate engineering. It can read codebases, understand system architecture, write targeted code, and chain operations together. An attacker doesn't need to be a skilled exploit developer anymore. They need to be a skilled prompter who can point an agent at a target and let it work.
What caught me off guard is the autonomy percentage. 80-90% AI-driven means the human was basically a project manager. Set the objective, review critical junctures, collect the output. That's a force multiplier that changes the economics of offensive cyber operations permanently. A five-person team with agents does the work of fifty.
For builders: this changes your threat model today. If you're deploying agents with network access, file system access, or credential access, you need to assume adversaries are deploying similar agents against you. Audit your agent permissions. Restrict what tools can do, not just what users can do. The same composability that makes agent skills powerful makes them an attack surface.
I don't have a clean answer for how to defend against this at scale. That's the honest truth. But ignoring it because the tool is useful isn't an option anymore.
Each link below shares sources, entities, or timing with this story.
Anthropic released Claude / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Anthropic released Claude); both cover Anthropic, Chinese, Claude Code; reported by the same outlet (anthropic.com).
Anthropic released Claude / Shared entities / Shared topic / What happened next
Linked by a graph relationship (Anthropic released Claude); both cover Anthropic, Audit, Claude Code; overlapping topics (agent, anthropic, claude, code, same).
Anthropic released Claude Code / Shared entities / Same source domain / Shared topic / What happened next / Tension
Linked by a graph relationship (Anthropic released Claude Code); both cover Anthropic, Claude Code; reported by the same outlet (anthropic.com).
Anthropic released Claude / Shared entities / Same source domain / Shared topic / What happened next / Tension
Linked by a graph relationship (Anthropic released Claude); both cover Anthropic, Claude Code; reported by the same outlet (anthropic.com).
Anthropic invested in Colossus / Shared entities / Same source domain / Shared topic / What happened next / Tension
Linked by a graph relationship (Anthropic invested in Colossus); both cover Anthropic, Claude Code; reported by the same outlet (anthropic.com).
Anthropic partners with Google / Shared entities / Shared topic / What happened next
Linked by a graph relationship (Anthropic partners with Google); both cover Anthropic, Claude Code; overlapping topics (access, agent, anthropic, anymore, claude).
Anthropic released Claude / Shared entities / Same source domain / Shared topic / What happened next
Linked by a graph relationship (Anthropic released Claude); both cover Anthropic, Claude Code; reported by the same outlet (anthropic.com).
Anthropic released Claude Code Security / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Anthropic released Claude Code Security); both cover Anthropic, Claude Code; reported by the same outlet (anthropic.com).