Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests

2026-07-31T07:23:21Z135d377035d39e260cdffe7fd0a5983c5bde486094f03b97b67d59e8d0e6afc5
CVE-2026-20316AI-securityChaos-ransomwareCisco-FMCMicrosoft-ExchangeMicrosoft-TeamsNorth-KoreaOWAReaperPyPI-malwareRussian-state-sponsoredShinyHuntersVMwareactive-exploitationauthentication-bypasscredential-theftdata-breachhealthcarenpmransomwareremote-code-executionsupply-chain-attackvirtual-machine-escapevishingvulnerabilitieszero-day

What happened

A BleepingComputer security-news feed covering critical vulnerabilities, actively exploited zero-days, ransomware and vishing campaigns, data breaches, supply-chain attacks, and AI-assisted security incidents reported on July 29–30, 2026. Notable items include an actively exploited Cisco FMC credential flaw (CVE-2026-20316), an Exchange OWA zero-day attributed to Russian state-sponsored actors, critical VMware flaws enabling authentication bypass and VM escape, North Korean-linked npm supply-chain attacks, and healthcare targeting by ShinyHunters.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
135d377035d39e260cdffe7fd0a5983c5bde486094f03b97b67d59e8d0e6afc5
Enrichment time
2026-07-31T07:23:21Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests · Baitaphish