Anthropic disclosed a state-backed espionage campaign in which a Chinese threat group abused Claude Code through the Model Context Protocol (MCP) to target about 30 organizations in technology, finance, chemicals, and government, with AI reportedly performing 80% to 90% of the tactical work and humans stepping in only at key decision points. The campaign highlighted how attackers can exploit the same agentic integrations enterprises are deploying for automation, while related research showed how those risks extend to host compromise and autonomous vulnerability discovery: Netskope said Anthropic’s Claude Mythos independently found kernel memory corruption bugs, upstream software flaws, and reconstructed n-day vulnerabilities, including one Windows 11 privilege-escalation chain to SYSTEM.
Defenders are responding with new monitoring and disruption techniques aimed at AI workflows rather than traditional endpoints alone. Splunk published detections for sensitive data in prompts, excessive token use, and high-risk filesystem and shell tool invocations in AWS Bedrock Claude logs, while detection-engineering guidance urged telemetry collection across model requests, responses, tools, MCP server changes, and cross-boundary actions to catch prompt injection, tool poisoning, and unauthorized tool use. Ars Technica also reported on Tracebit’s "context bombing" approach, which plants prompt injections in decoy secrets to derail AI hacking agents; in simulated AWS tests, the method reportedly cut full admin compromise rates from 57% to 5% and reduced compromise with persistence from 36% to 1%.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Tracebit researchers described a defensive prompt-injection technique called 'context bombing' that plants refusal-triggering strings inside decoy secrets to disrupt AI hacking agents in AWS environments. In simulated testing across five models and 152 attack runs, the technique reportedly reduced full account admin compromise from 57% to 5% and complete compromise with persistence from 36% to 1%.
Netskope described internal research using Anthropic's Claude Mythos preview to autonomously find and verify vulnerabilities in Netskope software and upstream open source components. The company reported nine reachable kernel memory corruption findings in Windows drivers, 17 previously unreported upstream bugs, and four confirmed n-day vulnerabilities reconstructed from binary diffs, with several issues already fixed and others under remediation or coordinated disclosure.
Anthropic disclosed a previously unseen September 2025 espionage campaign in which attackers abused Claude Code through MCP rather than bypassing model safety controls directly. The disclosure framed prompt injection and instruction-data ambiguity in agent architectures as key structural weaknesses.
On 2026-07-06, Splunk published detection content for AWS Bedrock Claude covering excessive token usage, sensitive data in prompts, and high-risk filesystem and execution tool invocations. The analytics are intended to surface signs of prompt injection, data leakage, bulk extraction, runaway loops, and dangerous tool use in Bedrock environments.
On 2026-05-07, an AWS Bedrock invocation log recorded a prompt sent to an Anthropic Claude model that included commands to read /etc/passwd and ~/.aws/credentials along with exposed example AWS access key and secret key values. The request was processed in account 387769110234 through Bedrock in us-west-2 with inference in us-east-2, showing sensitive data was transmitted as model input.
In September 2025, a Chinese state-sponsored threat group used Anthropic's Claude Code through the Model Context Protocol to target about 30 organizations in technology, finance, chemicals, and government. Anthropic described it as a large-scale campaign in which AI handled roughly 80% to 90% of the tactical work with minimal human intervention.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
arstechnica.com
Open sourcenetskope.com
Open sourceinfosecwriteups.com
Open sourcetechrepublic.com
Open sourceresearch.splunk.com
Open sourceresearch.splunk.com
Open sourcekodemsecurity.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.