AI is being placed inside the attack loop

Anthropic's September 2026 threat intelligence report describes malicious use it identified and disrupted between December 2025 and August 2026. The company says a majority of the cyber operations in its selected case studies involved direct AI execution or orchestration rather than simple question-and-answer assistance.

Humans still chose targets and reviewed sensitive results. Between those decisions, however, agentic workflows reportedly performed reconnaissance, prepared infrastructure, supported exploitation, harvested credentials, moved through environments, processed stolen data, and maintained access.

Important scope limitation

Anthropic explicitly says these were notable or novel cases, not a representative sample of normal Claude use. The report demonstrates capability and observed misuse; it does not establish how common AI-orchestrated attacks are across the wider threat landscape.

Automation compresses the work between attacker decisions

Operational stageProvider-reported useDefender implication
ReconnaissanceFingerprinting exposed services and building target listsReduce unnecessary exposure and monitor systematic enumeration across identity, cloud, and edge systems.
Initial accessPhishing infrastructure, credential use, and exploitation workflowsCorrelate identity events with endpoint and network activity instead of reviewing alerts in isolation.
Execution and persistenceTool generation, deployment, and repeated adaptationFavor behavior-based controls that survive changes to filenames, hashes, and code structure.
Collection and exfiltrationBulk extraction, organization, and analysis of stolen dataDetect unusual export volume, token use, cross-tenant access, and new exfiltration destinations.

One suspected Russian state-linked operation allegedly used AI-assisted workflows to monitor whether malware was detected, then modify and rebuild the tooling. Anthropic assessed the actor's tradecraft and targeting as consistent with public reporting on Midnight Blizzard; that wording is an assessment, not independent proof of attribution.

Static indicators may lose value faster

Hashes, domains, and filenames remain useful for scoping known activity, but an automated attacker can regenerate some artifacts faster than a manual operation. The durable signals are increasingly the relationships between actions: an unusual sign-in followed by device registration, token creation, mailbox export, privilege escalation, or high-volume collection.

Microsoft's separate reporting on the CaptiveCrunch campaign supports part of this operational picture. It documented AI-augmented activity alongside compromised hospitality networks, captive-portal traffic manipulation, fake update prompts, device-code phishing, credential theft, and malware delivery.

Threat Field Notes assessment

The near-term defensive change is not to buy an “AI security” product. It is to shorten investigation loops, connect identity and endpoint telemetry, protect machine credentials, and ensure detections describe attacker behavior rather than one disposable artifact.

Build controls around the operational chain

  1. 1

    Protect secrets used by automation. Inventory AI, cloud, source-control, and CI/CD tokens. Remove secrets from code and images, restrict scope, rotate exposed credentials, and alert on use from new infrastructure.

  2. 2

    Constrain device-code authentication. Block the device-code flow where it is unnecessary. Where business use requires it, apply Conditional Access, phishing-resistant MFA, device restrictions, and monitoring for anomalous registrations.

  3. 3

    Correlate behavior across systems. Join sign-in, OAuth, endpoint, email, source-control, and cloud audit events so a multi-stage sequence becomes one investigation rather than several low-confidence alerts.

  4. 4

    Hunt for automated collection. Baseline mailbox exports, repository cloning, API enumeration, database reads, token minting, and cross-tenant activity. Investigate sharp changes in volume, cadence, and access breadth.

  5. 5

    Test detections against variation. Validate that important detections still work when a tool changes its hash, name, command formatting, parent process, or hosting location while preserving the same objective.

  6. 6

    Prepare rapid credential containment. Document how to revoke sessions, disable applications, rotate developer tokens, isolate endpoints, and preserve identity evidence without waiting for full attribution.

Look for the seams automation still exposes

  • New device registrations or OAuth grants shortly after an unusual sign-in or device-code event.
  • High-volume mailbox, repository, object-storage, or SaaS exports from identities that do not normally perform bulk collection.
  • A developer or AI API key used from unfamiliar networks, cloud regions, user agents, or workloads.
  • Repeated tool rebuilds or payload changes followed by the same persistence, credential-access, or exfiltration behavior.
  • Fake update, verification, or captive-portal activity that launches command interpreters or downloads executable content.
  • Security-control tampering followed by token theft, session replay, or outbound transfers.

How this analysis was prepared

This topic was surfaced by The Cyber Security Hub newsletter on LinkedIn. Threat Field Notes independently reviewed the cited Anthropic report and related Microsoft research, then wrote this defender-focused analysis in original language.

The underlying cases are based substantially on provider telemetry and provider attribution. Defenders should treat the report as a source of hypotheses, behaviors, and indicators to validate—not as proof that every sophisticated intrusion now uses autonomous AI.