Chinese Hackers Exploit Claude AI to Automate Cyberattacks
Chinese Hackers Exploit Claude AI to Automate Cyberattacks#### For the first time in history, Chinese hackers carried out a large-scale cyberattack, with 80–90% of the work performed by artificial intelligence.

Anthropic has released detailed information about the GTG-1002 campaign, in which a Chinese state-sponsored group exploited Claude Code with MCP servers to automate most of the attacks (reconnaissance, vulnerability discovery, exploitation, lateral movement, data collection and sorting). About 30 targets experienced several successful breaches. The attackers focused on large technology companies, financial institutions, chemical manufacturing companies, and government agencies.
We believe this is the first documented case of a large-scale cyberattack carried out without substantial human intervention, said Anthropic
Overall, the attacker was able to use AI to conduct 80–90% of the campaign, with human intervention only needed sporadically (about 4–6 critical decisions per hacking campaign). The amount of work performed by the AI would have taken a human team an enormous amount of time.
Simplified diagram of the entire operation:
Anthropic released a comprehensive report, in which it describes all phases of the attack. The diagram above is based on this report.
Fortinet Patches Critical Vulnerability in FortiWeb Interface
CVE-2025–64446 (CVSS score 9.1) is a critical vulnerability in Fortinet FortiWeb (WAF) that allows an unauthenticated attacker to execute commands under the administrator account through specially crafted HTTP/HTTPS requests. An attacker without password knowledge can take over the device. Through HTTP/HTTPS requests, configuration changes, policy disabling, creating local admin accounts, and potential pivoting to other systems are possible. Fortinet has officially confirmed the vulnerability and stated that it is being actively exploited.
The attack mechanics are simple. Just send an HTTP POST request using path traversal to the endpoint “/api/v2.0/cmdb/system/admin%3F/../../../../../cgi-bin/fwbcgi” to create an admin account.
Affected versions are FortiWeb 8.0.0–8.0.1, 7.6.0–7.6.4, 7.4.0–7.4.9, 7.2.0–7.2.11, and 7.0.0–7.0.11. Patches are available in 8.0.2, 7.6.5, 7.4.10, 7.2.12, and 7.0.12.
OWASP Top 10:2025
The OWASP organization has released an RC version of its OWASP Top 10:2025 ranking, which brings significant changes reflecting developments in application security. This update is based on analysis of 2.8 million applications and 589 CWEs, representing a significant increase over the previous version from 2021.
The most dramatic change is Security Misconfiguration’s jump from 5th to 2nd place, reflecting the growing complexity of modern applications and their dependence on configurations. Broken Access Control remains in first position, now incorporating SSRF (Server-Side Request Forgery). In contrast, Cryptographic Failures dropped from 2nd to 4th place and Injection from 3rd to 5th place.
The ranking introduces two completely new categories. A03: Software Supply Chain Failures represents an expansion of the original “Vulnerable and Outdated Components” category and includes compromises across the entire ecosystem of dependencies, build systems, and distribution infrastructure. A10: Mishandling of Exceptional Conditions focuses on incorrect error handling, logic errors, and scenarios where the system fails into an insecure state.
Complete OWASP Top 10:2025:
-
Broken Access Control
-
Security Misconfiguration ⬆️
-
Software Supply Chain Failures 🆕
-
Cryptographic Failures ⬇️
-
Injection ⬇️
-
Insecure Design ⬇️
-
Authentication Failures
-
Software or Data Integrity Failures
-
Logging & Alerting Failures
-
Mishandling of Exceptional Conditions 🆕.
Official release is planned for early 2026.
Microsoft Fixed 63 Security Vulnerabilities
Microsoft fixed 63 vulnerabilities in November’s Patch Tuesday. 29 of these vulnerabilities are related to privilege escalation and 16 allow remote code execution.
Patch Tuesday also included a fix for an actively exploited zero-day vulnerability in Windows Kernel, tracked as CVE-2025–62215 (with CVSS score: 7.0) that leads to local privilege escalation.
The updates also include fixes for two buffer overflow bugs in Microsoft’s graphics component (CVE-2025–60724 with CVSS score 9.8) and Windows Subsystem for Linux graphical interface (CVE-2025–62220, CVSS score: 8.8), which could lead to remote code execution.
Another significant vulnerability is a flaw in the Windows Kerberos system tracked as CVE-2025–60704 (CVSS score 7.5), which exploits a missing cryptographic step to gain administrator privileges.
Proton Launched Black Friday
Proton launched Black Friday. Currently offering Proton VPN with 70% discount and 50% discount on the entire Proton Unlimited package (VPN, Mail, Calendar, Drive, Pass).