Anthropic's September threat report documents autonomous agent swarms, 13 unsupervised collection agents, and a developer token escalated to full admin in three hours
Anthropic's September 2026 threat intelligence report covers December 2025 through August 2026. It describes GTG-10007, a Chinese operation running agent swarms with persistent campaign memory and thirteen standing collection agents on a scheduled job, which produced more than a dozen candidate zero-days in one month. It also covers ShinyHunters affiliates using 'vibe hacking' to go from one stolen developer token to full admin in about three hours and compromise 200+ downstream organizations. A third actor pointed a containerized pentest platform at roughly 30 AI companies in four days, trying to reach pre-release Claude models. Several cases name Claude Code as the tool used to build exploitation frameworks, and the NYT separately reported the same day that Anthropic blocked possible bioweapons efforts.
Source
↳ Follow the thread