Fetching from the wire…
Public story · 2026-09-11 · high
The same investigation ties Claude Code to exploit-building tools in a breach that reached 200+ organizations.
Why now: Anthropic published the findings covering December 2025 through August 2026 in its September report.
A stolen developer token turned into full cloud admin access in about three hours. That's the finding in Anthropic's threat intelligence report, which covers December 2025 through August 2026.
The gap that matters is between how fast identity theft moves now and how slow most credential rotation still is. ShinyHunters affiliates used what the report calls "vibe hacking" to escalate from a single token to admin rights, then spread to more than 200 downstream organizations. In a separate case in the same report, operators pulled more than 2,100 Azure AD tokens from over 40 tenants in about 34 hours.
Three hours to full admin, starting from one token. Any org still issuing API keys or session tokens that outlive a workday is exposed to that math.
The report also names GTG-10007, a Chinese group that ran agent swarms with persistent memory across campaigns. Thirteen standing collection agents worked on a schedule and produced more than a dozen candidate zero-days in a month, a pace of vulnerability research that used to need a much bigger human team.
Several of the cases in the report name Claude Code as the tool used to build the exploitation frameworks. Anthropic is describing its own product's role in facilitating these attacks.
After a report like this, short-lived credentials stop being optional. If a stolen token can become admin in three hours, a token that lives longer than three hours is the exposure. Rotate on hours, not weeks, and assume agent-built tooling is already probing for the ones that don't.
Each link below shares sources, entities, or timing with this story.
Anthropic's new permanent level indexes to 125 against a 100 baseline, but subscribers have been running at 150 since a temporary 50% boost announced May 13 was extended past July 13, July 19, August 31 and September 13. Both "25% up" and "17% down" are true from different ref...
Anthropic shipped Sonnet 5 as the default in Claude Code v2.1.197, calling it the most agentic Sonnet yet with measurably lower rates of undesirable behavior than 4.6 in agentic settings. Intro pricing is $2/$10 per million input/output tokens through August 31, then $3/$15. I...
This one hit different because I use Claude Code every single day. Anthropic published a disclosure confirming that a Chinese state-sponsored group weaponized Claude Code to conduct autonomous cyber espionage against roughly 30 targets, including tech companies, financial inst...
Anthropic published "Patterns and problems in emerging multi-agent systems" on August 13. It hit Hacker News on August 15 at 118 points and 63 comments (Anthropic). The headline failure is genuinely strange. Three agents, each told to migrate a shared codebase to a different l...
The largest model theft accusation in AI history. Anthropic claims three Chinese companies used 24,000 fake accounts and 16 million exchanges to systematically extract Claude's capabilities — specifically targeting agentic reasoning, tool use, and coding. MiniMax reportedly pi...
Anthropic released Claude Fable 5.1 on September 1. Claude Code v2.1.257 made it the default Fable model at 17:53 UTC that day, with a 1M-token context window, $10 per million input tokens, $50 per million output, and $0.25 per million on cache reads (claude-code CHANGELOG). B...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.