Anthropic’s Claude platform suffered a widespread service disruption that affected users globally across the web app, mobile clients, and Claude Code, with reports of elevated errors, long response delays, hung sessions, and failed requests involving models such as Opus 4.6 and Sonnet 4.6. User complaints rose sharply after the incident began around 0600 UTC, and Anthropic’s status page moved from reporting a partial outage to saying a fix had been implemented before later marking systems operational, though some customers continued to report intermittent problems after remediation.
Separately, a security researcher disclosed a critical supply-chain vulnerability in Anthropic’s official Claude Code GitHub Actions workflow that could have allowed an unauthenticated attacker to compromise repositories using it, including Anthropic’s own. The flaw stemmed from write-permission checks that trusted any GitHub actor whose name ended with [bot], enabling a malicious GitHub App bot to bypass restrictions and, when chained with prompt injection, potentially exfiltrate secrets, steal GitHub Actions OIDC credentials, obtain a privileged Claude GitHub App token, and push malicious code downstream; Anthropic said it patched the issues in v1.0.94 with stronger actor validation and additional workflow hardening.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Anthropic experienced another major Claude service disruption beginning at 15:08 UTC, affecting claude.ai, the Claude API, Claude Code, Claude Cowork, and multiple model versions. Anthropic later said the incident was caused by infrastructure issues rather than a security breach and reported full restoration by 18:27 UTC.
Anthropic patched the Claude Code GitHub Actions issues in version 1.0.94 by strengthening actor validation and adding multiple workflow hardening measures. The company also awarded RyotaK $3,800 plus a $1,000 bug bounty bonus.
Security researcher RyotaK of GMO Flatt Security discovered a critical supply chain vulnerability in Anthropic's Claude Code GitHub Actions, along with a separate workflow misconfiguration. The issues could allow repository compromise, secret exfiltration, theft of OIDC credentials, and malicious code pushes to downstream repositories.
Anthropic said it was investigating the Claude outage, first classifying it as a partial outage on its status page. By 1042 UTC, the company reported that a fix had been implemented and later marked systems operational, though some intermittent issues persisted for some users.
Anthropic's Claude experienced a significant service disruption affecting users globally across web, mobile, and Claude Code. The outage began around 0600 UTC / 2:10am ET, with users reporting errors, delays, hung sessions, and failures.
Anthropic filed a draft registration statement with the US Securities and Exchange Commission for a proposed IPO. The filing occurred one day before Claude's major service outage.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.