
What happened
Anthropic's threat report covering December 2025 through August 2026 documents Claude misuse across seven categories — including a Yemen cell (GTG-87001) using Claude Code for three missile programs, a Russian-speaking actor (GTG-20006) whose agents rewrote malware to evade antivirus, and Alibaba's Qwen lab extracting over 151 million exchanges for training data.
Why it matters
Anthropic says autonomy lowers the cost of attacks, making previously unprofitable targets worth pursuing — and that writing new detection signatures no longer slows an attacker if AI cycles through changes faster than signatures can be rolled out, with more than 20 organizations targeted and a complete proprietary drone-vision SDK stolen.
What to watch
Anthropic has already launched Fable 5 with stricter safeguards for dual-use biology requests and 'preserved thinking' in Fable 5.1 to block distillation via new API accounts — the test is whether classifiers can both enable useful work and prevent harm, which Anthropic itself concludes may be impossible because user intent in dual-use areas cannot be reliably detected.
WHO IT HITSEnterprise security teams defending against AI-accelerated attacks face a structural problem: anomaly-based detection degrades when malware rewrites itself faster than signatures can be deployed. AI lab trust and safety teams are similarly affected, since the report documents labs relaying their own customers' requests to Claude and buying transcripts through intermediaries.
Ask the AI about this article →
Summaries like this, in your inbox every morning.
Anthropic's report breaks misuse into seven categories and says it documents novel cases rather than the typical kind. The affected models were primarily Haiku, Sonnet, and Opus, while Fable and Mythos appeared in only a single distillation case — suggesting that older, widely deployed models remain the primary vector even as newer ones carry stricter safeguards.
The report's cyber chapter argues that sophisticated attacks no longer require sophisticated attackers. The techniques themselves are familiar — stolen credentials, unpatched devices, SQL injection, phishing — but reconnaissance, exploitation, and tool-building now run in parallel at machine speed. A Russian-speaking actor tracked as GTG-20006 ran AI agents that checked whether malware was being flagged, rewrote and recompiled the code when it was, and slipped past detection again; more than 20 organizations were targeted, and the actor stole a complete proprietary SDK for a drone vision system.
The distillation findings raise a different set of questions. Anthropic says the illegitimate version is industrial-scale and covert, enabled by fake accounts and 'transfer stations.' But the strangest cases involve labs relaying their own customers' requests — Moonshot AI (GTG-16002) relayed nearly 300,000 customer requests over ten days while users believed they were using a Kimi model, and DeepSeek (GTG-16001) routed selected users to Claude Opus, over 12.1 million exchanges in 14 days. Among those, Anthropic found a user likely tied to the People's Liberation Army analyzing CCTV footage from hundreds of cameras in Chengdu, and an operator with live credentials for a database linked to the Russian Ministry of Defense. Whether stricter API controls can prevent this kind of relay — where the misuse happens through intermediaries rather than direct accounts — is the open question the report leaves unresolved.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
A Digitimes piece argues corporate cybersecurity's perimeter model — firewalls at network entry points, email…

Dynatrace acquired Arize AI, adding AI observability, evaluation and agent monitoring to its application obser…
A Daily Dose of Data Science test kept LoRA adapters separate from a shared 7B base model, cutting 100 fine-tu…

A report by Spencer Kitts, Thomas Larsen and Sydney Von Arx says an OpenAI agent swarm very likely ran an atta…

Simon Willison wrote that many people, himself included, have gone through an existential crisis when a coding…

Stephen Aarons, a New Mexico defense lawyer of over 40 years, was held in direct contempt and fined $5,000 for…
