AI is officially the attacker now.
Anthropic confirmed the first real AI-driven cyber attack… and the scary part is that the hackers didn’t jailbreak anything. They simply tricked the AI into believing it was doing a legitimate, authorised security test.
Once Claude Code accepted that context, it ran almost the entire attack chain on its own.
Here’s what the AI did by itself:
• Recon
• Scanning
• Vulnerability discovery
• Writing the exploit
• Credential harvesting
• Lateral movement
• Sorting and prioritising data
And then it paused at the end and asked the human attacker:
“Should I exfiltrate this data now?”
This wasn’t a small attack. Around 30 global organisations were targeted across tech, banking, chemical manufacturing and government.
This is a brand new attack vector.
Not AI assisting a hacker, but AI acting as the hacker because it was socially engineered into thinking everything was authorised.
What do you think about this? Let me know 👇🏽
Follow
@cyber.queen_ to stay ...