The scary part of Anthropic’s report isn’t the hacking

Anthropic is clearly losing control of the message. Even though it put out a report warning about the dangers of AI in the wrong hands, AI is moving beyond helping attackers work faster to autonomously adapting malware, compressing attacks that once took teams days or weeks into hours, and forcing defenders to rethink detection and response around behavior rather than static signatures. What’s worse is a that a researcher that used to work for Anthropic is warning that there’s a 10% chance of AI killing all humans.

John Strand, Owner, Black Hills Information Security (https://www.linkedin.com/in/john-strand-a1b4b62)

“I’m kind of shocked that they’re shocked about this.

“We’re seeing cybercriminals and nation-states use AI models in a variety of different ways for cyberattacks, espionage, weapons research, biological research, and other military purposes. There have even been reports of Iran using AI for work related to missile guidance systems.

“Why are we surprised?

“People are using these technologies to reduce the overall cost and effort required to achieve their goals and objectives. That’s what technology does. And those goals don’t suddenly have to be legal or moral just because AI is involved. Criminal organizations are going to use it. Intelligence agencies are going to use it. Militaries are going to use it. Of course they are.

“The reason I’m shocked that people are shocked is that we’ve been warning about exactly this type of scenario since before modern AI really started taking off. Hell, science fiction books and movies have been beating us over the head with these ideas for decades.

“Apparently, we learned nothing.

“But there’s a much bigger issue here, and that’s control.

“We’ve already seen legitimate AI companies struggle with controlling what their models and agents can do. We’ve seen concerns around agents escaping intended boundaries, interacting with systems they weren’t supposed to interact with, and potentially hacking third parties without authorization.

“Now ask yourself a much scarier question. What controls are organized criminal groups and rogue nations putting around their AI models? What safeguards are they implementing to make sure those systems don’t do something absolutely hideous?

“Probably not the controls we’d like them to have.

“We are very, very quickly approaching a point of no return with some of these technologies. In fact, I think there’s a good argument that we may already be there. Pandora’s box is open. We’re not putting this technology back in the box, and pretending that bad actors somehow won’t use it is ridiculous.

“So where does that leave defenders?

“You have to start looking at how AI can augment your defensive strategies. The attackers are going to use it to move faster, automate more of their operations, lower their costs, and increase the scale of their attacks.

“Defenders need to do the same thing.

“We need to use AI to identify attacks faster, understand what’s happening faster, react faster, and mitigate these attacks faster than we ever have before.

“Because waiting for the bad guys to decide not to use this technology isn’t a strategy.”

Jacob Krell, Sr. Director: Secure AI Solutions & Cybersecurity, Suzu Labs (https://www.linkedin.com/in/jacob-krell)

“Anthropic’s September 2026 threat report documents the shift from AI as a productivity tool for attackers to AI as an evasion engine. The GTG-20006 case, attributed to Midnight Blizzard, ran an autonomous evasion loop where AI agents monitored whether deployed malware triggered security detections, then rewrote and redeployed it until it passed clean. No human touched the iteration.

“Traditional polymorphic engines mutate code mechanically, rotating encodings and shuffling instructions while the underlying logic stays intact. AI rewrites the logic itself. Each variant can take different execution paths, different system calls, different timing behaviors. When mutation happens at the architectural level, behavioral heuristics face the same combinatorial problem that killed static signatures a decade ago.

“I’ve seen AI generate code with environmental keying and timing variations that would take a specialist days to build by hand. The model treats side-channel behavior as an optimization problem, so the evasion complexity comes for free. Defenders need to use the same capability in reverse, using AI to dynamically generate novel exploit variants and continuously train detection models against threats that haven’t been seen in the wild yet. Static signature libraries can’t keep pace with an adversary that rewrites malware faster than analysts can write rules. Detection needs to become generative too.”

Eric Capuano, Dir. of SOC Operations, Black Hills Information Security (https://www.linkedin.com/in/ecapuano)

“The attacks in this report are not new, and Anthropic says as much. Stolen credentials, unpatched edge devices, exposed services, phishing. What changed is the time budget. One intrusion went from a single stolen developer token to full administrative control of a cloud environment in roughly three hours. Another pulled more than 2,100 Azure AD token sets across 40 tenants in about 34 hours with agents doing nearly all the work. A single hacktivist got inside 14 of 42 targets. Those used to be team-sized outcomes, and now one operator with a harness produces them.

“The case defenders should study is the espionage actor that used agents to watch whether its implants were getting flagged, then rewrote and redeployed them until they went quiet. That cycle is where defenders used to get leverage. You shipped a detection, the attacker had to retool, and that cost them days. When retooling is automated, a static signature is worth less than the time it took to write. Detection has to sit on behavior: a new device registered in the tenant, a device code sign-in from somewhere unusual, a service account exporting mail in bulk, an API key being used from infrastructure you do not own.

“The question of whether current controls are enough is missing the point a bit. The controls are fine. Most of these intrusions started with a credential someone left in a mobile app, a container, or a repo, and moved through tokens nobody was watching. Conditional access, phishing-resistant MFA, and short token lifetimes would have blunted most of it. The gap is that those controls were not in place, and the time to discover they were missing is now measured in hours instead of weeks. 

“In order: treat AI API keys as production credentials, because this report shows attackers stealing them for compute and for cover. Block or tightly restrict device code flow in Entra. Alert on new device registrations and on bulk mailbox export. Then look hard at response tempo. If an identity alert sits for two days before anyone works it, you are already slower than the adversary.”

Clearly AI is out of control or close to it. The question will be will profits be placed over people, or the other way around. We’re about to find out.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading