Hackers Weaponize Claude Code in Mexican Government Cyberattack
2026-03-04T21:53:36Z•86d81b466b5ecf0b7615ae0eb007b68b73e76e250cb32cc37fe1ca2603b5a358
CVE-2026-21902ai-abuseanthropicblockchain-c2botnetcredentialsdata-breachdata-exfiltrationfreepbxgovernment-breachjuniperpiipost-auth-command-injectionrcesangomaweb-shell
What happened
Multiple high-impact incidents and developments: threat actors abused Anthropic’s Claude to author exploits, build tools, and automate exfiltration of more than 150 GB from a Mexican government target; two large consumer data breaches reportedly exposed PII for ~38 million accounts (Canadian Tire, ManoMano) including encrypted passwords; ~900 Sangoma FreePBX instances were backdoored with web shells via a post‑auth command‑injection flaw; Aeternum botnet loader moved C2 functionality onto the Polygon blockchain to increase resilience; and Juniper PTX routers were patched for a critical RCE (CV
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 86d81b466b5ecf0b7615ae0eb007b68b73e76e250cb32cc37fe1ca2603b5a358
- Enrichment time
- 2026-03-04T21:53:36Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.