View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Anthropic Warns Attackers Using Infostealers to Hijack Claude Login

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Anthropic Warns Attackers Using Infostealers to Hijack Claude Login Sessions
    Anthropic is warning Claude users that infostealer malware is being used to hijack their login sessions.

    • Applies to Claude users, whose accounts Anthropic warns are being targeted via compromised login sessions
    • Attackers use infostealer malware to hijack sessions and steal account usage to run their own activities
    • The tactic reflects a broader shift by bad actors from stealing credentials to hijacking session tokens and authentication cookies
      ๐Ÿ“Ž Coverage: securityboulevard.com ยท ๐Ÿ‘ via securityboulevard.com (discovered)
  • Risky Bulletin: BGP hijack delivers malicious Virtualizor updates โ€” Risky Business News

  • Divi through 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via... โ€” CVE ThreatInt

  • Baserow 2.3.3 - SQL injection in formula index() JSONB array extractionBasero... โ€” CVE ThreatInt

  • MapQuest Get Directions App com.mapquest.android.ace ExpoShareIntentModule.kt... โ€” CVE ThreatInt

  • WP File Download through 6.3.4 - Authenticated (Subscriber+) Arbitrary File Deleti... โ€” CVE ThreatInt

  • FIPS mode assertion failure via malicious CERT payloadIn FIPS mode, Libreswan... โ€” CVE ThreatInt

  • Piwigo Image Derivative i.php path traversalA security vulnerability has been... โ€” CVE ThreatInt

  • OpenCart Autocomplete Workflow edit.php cross site scriptingA vulnerability w... โ€” CVE ThreatInt

  • Keycloak-services: keycloak-services: cross-session email verification proof ... โ€” CVE ThreatInt

  • OpenCart Autocomplete Workflow address.php cross site scriptingA vulnerabilit... โ€” CVE ThreatInt

  • FeatherPanel before 1.3.7.10 Privilege Escalation via Subuser Permission Upda... โ€” CVE ThreatInt

  • APITable through 1.13.0-beta.1 Missing Authentication on the Internal Organiz... โ€” CVE ThreatInt

  • ION-DTN before 4.2.0 Out-of-Bounds Read via decodeSdnvION-DTN versions before... โ€” CVE ThreatInt

  • AirAsia MOVE App com.airasia.mobile com.airasia.core.utils.RealPathUtil.getRe... โ€” CVE ThreatInt

  • AgentProv: Auditing Agentic LLM API Providers via Tool-use Policy Probes โ€” arXiv cs.CR

  • A Formal Analysis of Agent Payment Protocols โ€” arXiv cs.CR

  • Explainable Artificial Intelligence for Industrial Cybersecurity: A Review of Methods, Operational Integration, and Research Challenges โ€” arXiv cs.CR

  • DUPIN: Attack Learning Is Still Needed! Demonstrating Few-Shot after Unsupervised Pretraining Is A Nimble Forensics Learner โ€” arXiv cs.CR

  • Delegation Without Trust: An Empirical Gap Analysis of Identity, Authorization, and Runtime Governance in Multi-Agent LLM Systems โ€” arXiv cs.CR

  • Workload Identification with Physical Side Channels for AI Governance โ€” arXiv cs.CR

  • OreProof: Verifiable Provenance with Limited Disclosure for Critical-Minerals Supply Chains Using Zero-Knowledge Proofs โ€” arXiv cs.CR

  • NeuroPriv: Adversarial Representation Learning for Privacy in Wearable EEG Systems โ€” arXiv cs.CR

  • Federated Trust for Embodied Robot Capability Marketplaces โ€” arXiv cs.CR

  • Don't Trust the Code, Check Its Effects: Runtime Refinement for Regenerated Systems Code Under an Adversarial Generator โ€” arXiv cs.CR

  • Capability-Gated Language Models: Security Composes, Utility Does Not โ€” arXiv cs.CR

  • Does Reasoning Mitigate Backdoor Attacks? A Neuro-Symbolic Perspective โ€” arXiv cs.CR

  • GlitchLab: A Hardware-in-the-Loop Optimizer for Physical Fault Injection โ€” arXiv cs.CR

  • The Safeguard Worked. Is the LLM System Safer? โ€” arXiv cs.CR

  • Transferable End-to-End Optimization for Indirect Long-Term Memory Poisoning in LLM Agents โ€” arXiv cs.CR

  • SoK: When Safe Agents Fail Together: The Security of Multi Agent LLM Systems โ€” arXiv cs.CR

  • NeuroGraph: An AI Graph-Driven Neuro-Symbolic Framework for Explainable Threat Reasoning in Advanced Manufacturing โ€” arXiv cs.CR

  • A Version Space Approach for Digital Circuit Analysis โ€” arXiv cs.CR

  • Automating Static Code Analysis Through CI/CD Pipeline Integration โ€” arXiv cs.CR

  • PhantomCall: Evading ML Malware Detectors via Function Call Graph Perturbation โ€” arXiv cs.CR

  • Anthropic Launches Claude Fable and Mythos 5.1 for Advanced Coding and Research โ€” cryptika.com (discovered)

  • OWASP Launches OASIS AI Initiative to Fix Open Source Vulnerabilities at Scale โ€” cryptika.com (discovered)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check