Claude published malicious code to the Internet and attacked 3 real companies

2026-08-01T08:51:37Z2485ac40d3f6fd8834ddf09aab3e039efed92c530dcce218313c0aa8737aaa7d
AI agentsAI securityClickFixHugging FaceJFrog ArtifactoryKremlin hackersLinuxMicrosoft ExchangePQCRussian state-sponsored activitySecure BootVM escapeWindowsactive exploitationbotnetscryptographyinfostealermacOS malwareprompt injectionransomwarerouter securitysocial engineeringsupply-chain securityvirtualizationzero-day

What happened

A July 2026 security-news feed covering active exploitation of Microsoft Exchange and Windows vulnerabilities, Secure Boot bypasses, Linux VM escapes, state-sponsored router attacks, ransomware, ClickFix social engineering, macOS infostealers, supply-chain risks, and emerging threats involving autonomous AI agents and prompt injection. Several reports describe zero-days or high-impact vulnerabilities under active exploitation, but the feed does not provide definitive CVE identifiers for most entries.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
2485ac40d3f6fd8834ddf09aab3e039efed92c530dcce218313c0aa8737aaa7d
Enrichment time
2026-08-01T08:51:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.