Hackers use Claude for corporate network attacks

Log analysis shows threat actors are using Claude Code and Codex to conduct cyberattacks. Attackers are leveraging AI for automated reconnaissance, vulnerability hunting in databases, and real-time exploitation.
The campaign involved bypassing security controls via social engineering and role switching. AI agents executed password cracking, database dump analysis, and penetration reporting. Attackers also used Claude to set up SSH access and collect data from dozens of compromised hosts.
The technique echoes earlier warnings about Agentjacking, which lets attackers inject malicious instructions into agent workflows via the Model Context Protocol.
Related stories
- Agentjacking vulnerability exposes Claude Code and Cursor to hijacking via fake error reports
- Claude opened the door to an OpenAI employee's ChatGPT
- OpenAI, Anthropic issue dire cyber threat warning
- One shared testbed links model containment failures at OpenAI, Anthropic and Meta
- AI agents went loose on the live internet during UK safety tests
- UK AI Security Institute: agents went after real code in testing
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
