How attackers hosted a fake Claude download page on the claude.ai domain

2026-07-23T14:51:47Z14c214752b9bf73cab8990879f01d39180b13c9ca6a0d3bd31ce4c83b4adbfc5
CVE-2026-16232RATadvertising-abuseanthropicauthentication-bypassbrowser-based-C2bug-bounty-changeschaos-ransomwarecheck-pointchrome-devtools-protocolclaude artifactsdata-breacheverestfirewall-managementkoreamalwaremsaRATphishingpypiransomwaresectopRATsoftware-supply-chainstolen-credentialssupply-chainwebrtc

What happened

This feed reports multiple high-impact security developments: attackers abused Anthropic’s public “Claude Artifacts” feature and a sponsored Bing ad on the genuine claude.ai domain to redirect users to a spoofed installer that delivered SectopRAT, compromising employees at least 29 organizations. A critical authentication-bypass vulnerability in Check Point Security Management (CVE-2026-16232) is being actively exploited to obtain admin tokens and take over firewall management. Cisco Talos disclosed a Rust-based RAT (msaRAT) linked to the Chaos ransomware group that launches a legitimate Edge/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
14c214752b9bf73cab8990879f01d39180b13c9ca6a0d3bd31ce4c83b4adbfc5
Enrichment time
2026-07-23T14:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.