Zero Day Room
Live
Vulnerabilities

Anthropic locks Claude accounts after infostealer malware

Anthropic is locking users out of Claude accounts due to login sessions compromised by infostealer malware. Separately, nearly 22,000 Microsoft Exchange servers remain unpatched against a critical flaw, CVE-2026-62911.

Vulnerabilities: Anthropic is locking users out of Claude accounts due to login sessions compromised by infostealer malware

Anthropic has started locking users out of their Claude accounts. The company says their login sessions were compromised through infostealer malware.

A malicious GitHub repository is also impersonating Anthropic. It claims to offer free access to “Claude Opus 5” but instead delivers RevStealer, a Windows information-stealing malware. According to Morphisec, this malware targets passwords, cryptocurrency wallet data, and login credentials.

Critical vulnerabilities and patch forecasts

Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911. This is a critical authentication bypass vulnerability, according to daily scans from the Shadowserver Foundation.

Attackers are exploiting two previously undisclosed zero-day flaws in SonicWall SMA 1000 appliances. The vendor confirmed the exploitation of CVE-2026-83548 and CVE-2026-83549 on Tuesday.

A threat actor is actively targeting internet-exposed Sangoma Switchvox instances. The attack exploits a recently patched SQL injection flaw, CVE-2026-9586. Organizations running them are urged to check for signs of compromise immediately.

The September 2026 Patch Tuesday forecast suggests the high volume of patches continues. August 2026 Patch Tuesday was the second biggest in history, resolving 398 CVEs.

SeverityNumber of CVEs
Critical42
Important355
Moderate1

Ongoing campaigns and actor tactics

Attackers are targeting internet-facing PaperCut Application Servers. PaperCut Software shared that the threat actor is covertly installing legitimate remote access software on compromised servers.

A coordinated voice-phishing campaign, named Spring Ring, abused Microsoft Teams. According to Unit 42, Palo Alto Networks’ threat intelligence team, fake IT support accounts were used to trick employees into installing malware or granting remote access.

The FBI warns that attackers are targeting prominent individuals through OAuth phishing. The goal is to gain persistent access to accounts, including private emails and files.

Russian state hackers are trying to interfere with AI-assisted malware analysis in Ukraine. ESET found they are deliberately setting off AI safety mechanisms, such as by planting nuclear weapon prompts in malware.

Attackers are also posing as AI crawlers to hunt for exposed credentials. GreyNoise reports they disguise automated scanning as traffic from crawlers operated by OpenAI, Anthropic, Google, and Perplexity.

Tools and strategic shifts

A recent CISA review argues for eliminating entire vulnerability classes. The agency believes treating vulnerabilities as an endless queue of individual fixes is why attackers keep winning.

In an interview with Help Net Security, Dr. Joye Purser of Cohesity explained how to rank vulnerabilities when KEV, EPSS, and CVSS metrics disagree.

Sift is a new free, open-source command line tool for secrets scanning. It searches for passwords and API keys across local disks, Active Directory, SharePoint, OneDrive, Teams, Slack, Jira, and Confluence.

Open-source tool halo-record creates audit trails for AI agents. Brian Kuan's Python package logs tool calls, model calls, data access, and approvals made by an AI agent.

Related coverage

More from Vulnerabilities