Anthropic's September threat report: Chinese students produced "more than a dozen possible zero day findings in a single month" with Claude
The report covers seven harm categories from December 2025 to August 2026. GTG-10007, described as university students in Hunan Province, ran autonomous binary-analysis workflows against security products at that rate; GTG-20006, a Russian state group, used Claude to systematically rebuild malware whenever detections fired, targeting Ukrainian and European government military intelligence; GTG-50014, ShinyHunters affiliates, exfiltrated more than a terabyte from one technology provider and reached an airline's tens of millions of passenger records with AI agents doing "nearly all of the work." Nine influence operations across Russia, Iran and Turkey were disrupted, timed to national elections.
Source
↳ Follow the thread