< ciso
brief />
Tag Banner

All news with #claude tag

159 articles

Anthropic Expands Claude Access for Cyber Defenders

🔒 Anthropic is expanding a program that lets vetted cybersecurity professionals test advanced AI models with reduced safeguards, reporting Project Glasswing uncovered at least 129,000 verified vulnerabilities between April and July 2026 and another 5,500 through open-source scans through October. The new Cyber Verification Program (CVP) offers three tiers—Defense, Red Team, and Specialized Access—providing graduated model access including Claude Opus 5.5 and Claude Mythos 5.1. Anthropic says these capabilities will help defenders while acknowledging dual-use risks and uneven exploitability of discovered flaws.
read more →

Fake AI Sites Steal Ad Accounts and MFA Codes

🔒 Researchers warn of a phishing campaign that uses fake ChatGPT, Gemini, Claude, and Perplexity pages to steal advertising account credentials and MFA codes via browser-in-the-browser attacks. The pages impersonate AI tools that promise ad planning and auditing, then open a simulated Google login to harvest passwords and authentication codes. Operators use a kit that mimics multiple OS/browser styles and can request repeated password and MFA entries, enabling account takeover or resale of compromised ad accounts.
read more →

Amazon Bedrock adds Claude models to London region

🛈 Amazon Web Services now offers in-region support for Anthropic's Claude Opus 5.5 and Claude Sonnet 5 on Amazon Bedrock in the UK (London) Region. Customers in regulated industries such as financial services, healthcare, and the public sector can perform inference while keeping data processing confined to the eu-west-2 Region. Calls to the bedrock-runtime endpoint ensure requests and processing remain within the Region. See the Bedrock User Guide for current regional model availability and the Bedrock console to get started.
read more →

Google Cloud Data Agent Kit reaches general availability

🛠️ Today Google Cloud announces the general availability of Data Agent Kit, a free set of Model Context Protocol (MCP) tools and Google-authored agent skills that let coding agents access and act on Google Cloud data products. The GA release adds support for BigQuery Graph, Bigtable, and Managed Service for Apache Spark in Lakehouse workflows, plus numerous quality-of-life and performance improvements. The kit integrates with IDEs, Antigravity, Claude Code, Codex, Cloud Shell, and Cloud Workstations, enabling agents to inspect schemas, run queries, read job logs, and orchestrate pipelines using customers' IAM permissions.
read more →

Anthropic Claude models expand in Asia regions

🚀 Amazon Bedrock now offers Anthropic's Claude Opus 5, Claude Sonnet 5, and Claude Haiku 4.5 in India, Claude Opus 5 and Claude Sonnet 5 in South Korea, and Claude Sonnet 5 in Singapore. These deployments enable customers in regulated industries to keep inference and data processing within-country using in-region or geographic cross-Region inference. In India, endpoints run across Mumbai and Hyderabad Regions; South Korea and Singapore support in-region bedrock-runtime endpoints.
read more →

AWS announces Claude Sonnet 5.5 availability

🚀 AWS now offers Claude Sonnet 5.5, a smarter and more efficient Sonnet that advances coding and knowledge work at lower cost per task and faster speeds. The model is an upgrade from Sonnet 5, improving coding assistance for feature development, verification, and well-scoped tasks while producing ready-to-share knowledge outputs like summaries, diagrams, and edits. Customers can access Sonnet 5.5 through Amazon Bedrock for AWS-resident data and managed features, or via Claude Platform on AWS for the native Anthropic experience with unified billing and authentication.
read more →

Anthropic’s Claude Opus 5.5 Writes Differently

📰 Arena’s benchmarking shows Anthropic’s Claude Opus 5.5 produces fewer telltale AI writing patterns, using shorter sentences and simpler wording compared with Opus 5. The analysis found a dramatic drop in em dash use and reduced semicolon frequency, while overall response length increased. Opus 5.5 scored better on most writing measures in Arena’s August–September 2026 Text Arena data.
read more →

Anthropic offers up to $250 in Claude Code cloud credits

🧭 Anthropic now enables cloud sessions for Claude Code without requiring enrollment in the research preview and is providing promotional credits to eligible subscribers. Cloud sessions run on Anthropic-hosted infrastructure so tasks continue remotely when your device is off, and they can be started from claude.ai/code, the mobile or desktop apps, or the CLI. Eligible Pro users receive $100 in cloud-session credits and Max subscribers receive $250; credits apply automatically and are distinct from normal plan limits. The promotion must be claimed by October 7 and unused balances expire November 4.
read more →

Claude Opus 5.5 in Microsoft Foundry for Long Tasks

🧭 Claude Opus 5.5 is now available in Microsoft Foundry, bringing Anthropic’s Opus advances to developers and enterprises for long-running coding and knowledge work. The model emphasizes sustained focus, adaptive reasoning, and clearer agentic communication while lowering token costs and enabling cache efficiencies. It also introduces expanded safeguards and new beta API capabilities tailored for long-lived agent architectures.
read more →

Anthropic’s Claude Opus 5.5 Now Available on AWS

🔔 Anthropic’s Claude Opus 5.5 is now available on AWS via Amazon Bedrock and Claude Platform on AWS. The model improves efficiency over Opus 5 by using fewer tokens at lower cost, with additional savings from cheaper cache reads. It’s designed for long-running coding and knowledge work and reports clearly on actions, findings, and next steps. Customers can choose Bedrock for zero data retention and regional residency, or Claude Platform for Anthropic’s native experience with AWS billing.
read more →

BragJack: Malicious Extensions Hijack Browser AI

🔒 Security researcher Gal Weizman of Forever Security disclosed a proof-of-concept attack named BragJack that uses a single malicious Chromium extension to hijack built-in AI browser agents. The technique, demonstrated against Chrome Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Claude for Chrome, exploits Chromium's declarativeNetRequest to intercept and modify trusted resources, enabling agents to access files, history, screenshots, and act on users' behalf. Vendors issued fixes and paid bug bounties, and the researcher published a full technical breakdown.
read more →

Plugin4Shell: Zero‑Click RCE in AI Coding Agents

🔒 Researchers discovered a zero-click vulnerability called Plugin4Shell affecting AI coding agents like Codex, Claude Code, Gemini CLI, and GitHub Copilot, allowing attackers to swap trusted plugins for malicious ones and execute code without developer interaction. The flaw stems from agents passing a Git commit SHA to Git but not verifying the checked-out commit, enabling repository owners or takeovers to resolve a malicious version under the expected identifier. Some vendors have patched the issue, while others have deprecated components or applied mitigations; enterprises are urged to inspect affected machines and audit logs.
read more →

Anthropic tests Claude Money for personal finance

💡 Anthropic is trialing a new feature called "Claude Money" that lets users link bank accounts to Claude to analyze spending, plans, and more. The capability appeared in the iOS app alongside other sections, but it's not widely available yet and details remain limited. It's likely to mirror existing offerings like ChatGPT Finances and may be restricted regionally due to privacy laws.
read more →

AI-assisted weaponization risks and developer findings

🔍 Anthropic disclosed that threat actors in northern Yemen used Claude models to support three weapons programs, including guided rockets and long-range missiles. The actors employed Claude Code to replace human engineers for GNC tasks, running multiple instances with divided roles to write, research, and review code. Anthropic’s safeguards blocked many requests but were circumvented through obfuscation and session-splitting. The actors test-fired a guided rocket and returned to Claude after a failure to diagnose issues.
read more →

Threat actors abused Claude to harvest secrets

🔒 Anthropic reports multiple financially motivated and state-linked groups abused its Claude model between December 2025 and August 2026 for cybercrime, espionage, surveillance, and weaponization. One actor associated with the ShinyHunters collective used automated pipelines to download and decompile 1.8 million Android APKs, scanning for hardcoded secrets and routing verified findings to a Telegram group. The company says AI agents performed much of the work, enabling rapid credential theft, mass data exfiltration, and subsequent attacks across diverse sectors.
read more →

Anthropic Disrupts Seven China-Based Illicit Distillation Attacks

🛡️ Anthropic says it identified and disrupted industrial-scale illicit distillation campaigns run by seven China-based labs, including Alibaba, Moonshot, DeepSeek, Z.ai (Zhipu), and MiniMax. The company reports attackers used proxy networks, fake accounts, stolen payment credentials, and harvested API keys to stealthily route user queries through Claude and save transcripts for training. Anthropic observed large-scale extraction of chain-of-thought, agentic capabilities, coding, and reasoning data and has updated Claude and its policies to limit such misuse.
read more →

Anthropic Finds Claude Used in Widespread Cyber Abuse

🛡️ Anthropic reported that between December 2025 and August 2026 its Claude models were abused by diverse threat actors—state-aligned groups, criminal affiliates, commercial vendors, and individuals—for cyberattacks, surveillance, influence operations, and weaponization. The company cataloged multiple Generative Threat Groups (GTGs) using Claude for reconnaissance, exploit development, credential harvesting, data exfiltration, and mass content production. Anthropic says abuses ranged from conversational assistance to fully autonomous multi-agent campaigns, and that it disrupted many operations and influence networks before they gained traction.
read more →

Threat Actors Exploit Trusted AI Platforms

🛡️ Huntress warns that attackers are abusing trusted AI platform features—like shareable artifacts, public conversation links, and sponsored search placements—to distribute malware and social-engineer victims. Over nine months, campaigns used real domain content (claude.ai, chatgpt.com, grok.com) and SEO or sponsored results to surface malicious install guides and troubleshooting advice. These short-lived deceptive pages and shared links leveraged user trust in platform branding to execute stealer and RAT payloads before removal.
read more →

Claude Fable Solves a 370‑Year‑Old Cipher

🔎 Claude Fable 5.1 decoded a 370-year-old cipher in forty-four minutes, demonstrating AI's strength at exhaustive search and pattern testing. The result aligns with observations about AIs excelling at mathematical and combinatorial tasks that benefit from large-scale trial and error. The post briefly contextualizes the achievement and its implications for cryptanalysis and AI capabilities.
read more →

AI Coding Agents Install Untrusted Code on Networks

🔍 Researchers scanned 6,214 live domains of defense contractors, Fortune 500, and Big Tech firms and found 8,265 llms.txt and llms-full.txt files. They registered several unclaimed package names referenced in those files and hosted payloads; within an hour a Fortune 500 system phone‑homed to their server, and dozens more followed. The chain of parent processes showed agent involvement from Claude, OpenAI’s Codex, and Nous Research’s Hermes, illustrating a broken trust model.
read more →