How attackers hosted a fake Claude download page on the claude.ai domain
2026-07-23T14:51:47Z•14c214752b9bf73cab8990879f01d39180b13c9ca6a0d3bd31ce4c83b4adbfc5
CVE-2026-16232RATadvertising-abuseanthropicauthentication-bypassbrowser-based-C2bug-bounty-changeschaos-ransomwarecheck-pointchrome-devtools-protocolclaude artifactsdata-breacheverestfirewall-managementkoreamalwaremsaRATphishingpypiransomwaresectopRATsoftware-supply-chainstolen-credentialssupply-chainwebrtc
What happened
This feed reports multiple high-impact security developments: attackers abused Anthropic’s public “Claude Artifacts” feature and a sponsored Bing ad on the genuine claude.ai domain to redirect users to a spoofed installer that delivered SectopRAT, compromising employees at least 29 organizations. A critical authentication-bypass vulnerability in Check Point Security Management (CVE-2026-16232) is being actively exploited to obtain admin tokens and take over firewall management. Cisco Talos disclosed a Rust-based RAT (msaRAT) linked to the Chaos ransomware group that launches a legitimate Edge/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 14c214752b9bf73cab8990879f01d39180b13c9ca6a0d3bd31ce4c83b4adbfc5
- Enrichment time
- 2026-07-23T14:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.