Claude Opus wrote a Chrome exploit for $2,283

2026-04-17T07:23:56Z65dfb07ac3822a8d3faec59f839e687ff5568b1c56735a1231d3cea061e0128c
AI agentsAnthropicCISAClaudeExcel exploitFortinetGit identity spoofGitHubMCPMicrosoft Patch TuesdayMythosNorth KoreaProject GlasswingSalesforce misconfigurationactive exploitationdata breachmacOS social engineeringprompt injectionransomwaresupply chainzero-day

What happened

A broad set of active security issues and incidents across software, AI systems, and infrastructure: Anthropic's Mythos/Project Glasswing (and its Model Context Protocol) raise risks of automated vuln discovery and a reported MCP design flaw that could enable takeover of ~200k servers; multiple prompt-injection and identity-spoof techniques let AI agents (Claude, Gemini, Copilot integrations) and code-review flows be abused to exfiltrate secrets or approve malicious changes; critical Fortinet sandbox flaws and a 17‑year‑old Microsoft Excel vulnerability are being actively exploited; supply‑cdl

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
65dfb07ac3822a8d3faec59f839e687ff5568b1c56735a1231d3cea061e0128c
Enrichment time
2026-04-17T07:23:56Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.