Advertisement
Infostealers Target Anthropic Claude Users via Session Theft
Threat actors are employing various infostealers to compromise Anthropic Claude user accounts via session theft, posing significant risks.
Claude AI Chats Exposed on Google: Personal Data and Crypto Keys At Risk
Sensitive personal data, including cryptocurrency wallet keys and medical information, from Anthropic's Claude AI chats are searchable on Google.
Anthropic Finds Models Hacked via Malicious Python Package
Anthropic's AI models and systems were compromised across three organizations due to a malicious Python package, highlighting supply chain risks in AI development.
Anthropic Claude Chrome Extension: Malicious AI Action Trigger
A flaw in Anthropic's Claude for Chrome extension enables malicious extensions to trigger AI actions, potentially abusing access to connected services like Gmail, Google…
Anthropic's Claude Cowork Mobile: Enterprise Security Implications
Anthropic tests Claude Cowork on mobile, enabling long-running AI tasks. This analysis covers potential data, access, and shadow IT risks for security teams.
NastyC2 npm Packages, AI Abuse & macOS Threats Identified
Analysis of NastyC2 npm supply chain attacks, Claude chat abuse for malware, memory-resident macOS threats, and device-code phishing.
Advertisement
Anthropic Claude Enterprise Security Governance via 28 Integrations
Anthropic expands Claude’s security posture with 28 integrations from CrowdStrike, Okta, and Microsoft to enhance enterprise AI visibility and governance.
Emerging Reconnaissance: Attackers Actively Probe AI Models
DShield sensors detect increasing scanning activity targeting popular AI models like Claude and Hugging Face, signaling a potential new attack vector for threat actors.
AI Privacy Considerations: Policy and Technical Insights
Senator Bernie Sanders discusses critical AI privacy aspects with Claude, an artificial intelligence model, touching on policy and ethical implications.
Claude Chrome Extension Zero-Click Prompt Injection Vulnerability
A critical flaw in Anthropic's Claude Chrome extension allowed websites to silently inject malicious prompts using zero-click XSS techniques.
Claudy Day: Prompt Injection and XSS Flaws Target Claude AI Users
Researchers uncover 'Claudy Day', a trio of vulnerabilities in Anthropic's Claude AI that allow data theft through malicious Google search results.
Claude AI Exploited to Automate Mexican Government Network Breach
Unknown actors bypassed Anthropic's Claude safety filters to automate vulnerability discovery and data exfiltration against Mexican government systems.
Federal Directive Mandates Phase-Out of Anthropic AI from U.S. Agencies
All U.S. federal agencies must discontinue Anthropic technology, impacting AI supply chains while OpenAI, Google, and xAI maintain their government contracts.
Entropy Deficiencies in LLM-Generated Passwords
Research indicates that Large Language Models produce predictable passwords with biased character distributions, increasing vulnerability to targeted attacks.