Hackers Weaponize Claude Code in Mexican Government Cyberattack
2026-03-04T21:50:43Z•3c0692cd659703344bbe4237105a12af58e62de5fc69f17ba4ecc0e3ae11a4dd
CVE-2026-21902aeternumai-assisted-attackanthropicblockchain-c2claudecritical-vulnerabilitydata-breachexfiltrationjuniper-ptxpost-auth-command-injectionsangoma-freepbxweb-shells
What happened
Multiple high-impact incidents reported: attackers weaponized Anthropic’s Claude to write exploits, build tools, and automate exfiltration of >150 GB from a Mexican government network; large data breaches allegedly impacted Canadian Tire (~38M accounts) and ManoMano (personal data and encrypted passwords exposed); Juniper PTX routers were patched for a critical remote code execution flaw (CVE-2026-21902); roughly 900 Sangoma FreePBX instances were found infected with web shells via a post-auth command-injection vulnerability; and the Aeternum botnet loader is using Polygon blockchain smart‑con
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 3c0692cd659703344bbe4237105a12af58e62de5fc69f17ba4ecc0e3ae11a4dd
- Enrichment time
- 2026-03-04T21:50:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.