Article Content
- •Iran-linked actor used Anthropic's Claude AI for targeting U.S. Navy forces.
- •Exploited publicly available data to compile targeting handbooks and research vulnerabilities.
- •Anthropic disrupted the operation and banned the associated user.
A threat actor linked to Iran exploited Anthropic's AI model, Claude, to gather and analyze public information for targeting U.S. Navy forces in the Middle East. The operation involved compiling a roster of U.S. personnel from military photographs, collecting ship and aircraft transponder data, and generating scripts for commercial satellite imagery queries. The actor also researched vulnerabilities in shipboard systems, including flaws in maritime satellite communications and Cisco equipment. Anthropic discovered and disrupted this activity, banning the associated user and developing new detection methods. The report detailed incidents from December 2025 to August 2026, highlighting the misuse of AI in various cyber operations. The U.S. Navy has since warned personnel to enhance security measures against potential threats. Anthropic's report also noted similar misuse by other state-linked actors, indicating a broader trend of AI exploitation in cyber operations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Midnight Blizzard and Anthropic in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical RCE Vulnerability in Zimbra Exploited by Attackers A critical remote code execution vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite is being actively exploited by attackers. The flaw, which affects versions prior to 10.1.20, allows unauthenticated attackers to execute arbitrary commands as the Zimbra user through improper input sanitization in SNMP…
Microsoft September 2026 Patch Tuesday: Record 974 Vulnerabilities Addressed On September 8, 2026, Microsoft released a record-breaking 974 patches for vulnerabilities across its products, including two actively exploited zero-day vulnerabilities: CVE-2026-81963 and CVE-2026-85880. These vulnerabilities allow local attackers to escalate privileges to SYSTEM level, posing significant risks to…