No Result
View All Result
  • Login
Monday, January 12, 2026
FeeOnlyNews.com
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
No Result
View All Result
FeeOnlyNews.com
No Result
View All Result
Home Market Analysis

Anthropic Catches Attackers Using Agents In The Act

by FeeOnlyNews.com
2 months ago
in Market Analysis
Reading Time: 4 mins read
A A
0
Anthropic Catches Attackers Using Agents In The Act
Share on FacebookShare on TwitterShare on LInkedIn


The internet is rife with prognostications and security vendor hype about AI-powered attacks. On November 13, AI vendor Anthropic published details about the disruption of what it characterized as an AI-led cyber espionage operation.

This revelation comes on the heels of a Google Threat Intelligence Group report that also highlighted the use of AI in attacks. Although the report covers activity in the wild, it focuses on malware that uses just-in-time invocation of LLMs for defense evasion and dynamic generation of malicious functions.

The Anthropic report describes an altogether different — and much more sophisticated — use of AI that borders on being agentic.

The release of this information is important because AI vendors are the only parties with sufficient visibility into how adversaries are attempting to leverage AI platforms and models. Ideally, a report such as this would have been mapped to a framework like MITRE ATT&CK, but it still provides insights about what defenders may be facing and how adversary capabilities are evolving.

Anthropic discusses many campaign details in its report, but the high-level summary is that a threat actor, which Anthropic assesses with high confidence to be Chinese state-sponsored, targeted around 30 organizations across multiple industry sectors using an AI-driven attack framework employing agents and requiring very little human effort or intervention.

The attack used agents but wasn’t quite autonomous nor fully agentic

Although the campaign made extensive use of agents, it didn’t quite rise to the level of being truly agentic. While the operation represents a significant step forward in attackers’ use of AI — with agents allegedly performing 80–90% of the work — humans were still providing direction at critical junctions, and there are still limits to what exactly what can be automated. One constraint may be the testing and validation of the output of AI.

As the report says: “An important limitation emerged during investigation: Claude frequently overstated findings and occasionally fabricated data during autonomous operations, claiming to have obtained credentials that didn’t work or identifying critical discoveries that proved to be publicly available information. This AI hallucination in offensive security contexts presented challenges for the actor’s operational effectiveness, requiring careful validation of all claimed results. This remains an obstacle to fully autonomous cyberattacks.” Ironically, this means that attackers may have to confront the same AI trust issues as defenders.

Bot management is more important than ever

Throughout the report, Anthropic points out that the rate of requests far exceeded what was humanly possible. In the application security space, organizations have contended with a similar challenge for years: bad bots attempting distributed denial of service, account fraud, web recon, and scraping while disguising themselves by usurping residential proxies and continuously adapting their behavior to evade defenses.

Malicious agents and/or hijacked agents will use similar techniques. Bot and agent trust management software analyzes hundreds, sometimes thousands, of signals to determine bot and agent provenance, behavior, and intent to help defend against agents that target organizations through customer-facing applications, one of the top external attack vectors.

Insecure intent was an important factor

This campaign was possible for a few distinct reasons. First, as Anthropic states, its newer frontier models understand more context. In addition to making deliberate misrepresentations about their identity and purpose, attackers broke up the attack into discrete tasks. This enabled them to create a gap between the context necessary for carrying out the attack and the context necessary to “understand” the requested actions as malicious in relation to each other.

In Forrester’s Agentic AI Enterprise Guardrails For Information Security (AEGIS) framework, we describe this issue as “securing intent,” and it is one of the defining capabilities of AI security. Securing intent is not just an issue for LLM vendors; it’s also a major priority for any organization building an AI agent and is one of the defining capabilities of AI security.

The use of AI is novel — the underlying tactics and techniques are not

AI is only as effective as its training data; the attacks it produces are not novel. The real value is that, using agents, attacks can be constant, high-volume, and eventually automated to not require a human.

The capabilities needed to defend against these attacks are many of the same ones we already rely on: focusing on Zero Trust, implementing proactive security, building a strong governance capability, and effectively detecting and responding to attacks. To protect against future AI-enabled attacks, security pros should:

Implement the principles of proactive security. Visibility, prioritization, and remediation make up the core of proactive security, and they’re applicable regardless of whether or not an attacker is using AI. By improving prioritization and shortening remediation windows, organizations will be better protected against current threats and better equipped to match the velocity of the AI-powered attacks of the future. Encrypt data at rest and in transit, and use strong key management. This makes high-value targets such as databases and backups far less useful to attackers, even if they are exfiltrated.
Leverage emerging AI capabilities in security tools. Emerging AI capabilities in security — especially in security operations — are proving effective in reducing the time to investigate alerts, especially for use cases such as phishing. Vendors and users are leveraging these technologies. If you are not currently using AI agents for triage and investigation already, start exploring these now. Use Forrester’s Six Steps To The AI-Enabled Security Organization to get started.
Tighten boundaries and kill implicit trust everywhere. Kill long-lived credentials, enforce phishing-resistant multifactor authenticaiton and short-lived tokens everywhere, and constrain lateral movement paths. The attack Anthropic describes leaned heavily on “harvest credentials -> test -> pivot,” so limiting the utility of stolen credentials hamstrings the automation loop that made the operation scalable. This includes applying Zero Trust principles to software development pipelines and environments, as they often have elevated access to sensitive data and are vulnerable to privilege escalation.

While the attack itself used existing exploits and wasn’t fully autonomous, it’s important to note that this serves as a harbinger of things to come for future attacks using AI and agents. Malicious actors will continue to improve on these capabilities, as they have with past technical advances.

Let’s connect

Clients who want to explore Forrester’s diverse range of AI research further can set up a guidance session or inquiry or contact their account team.



Source link

Tags: ActagentsAnthropicAttackerscatches
ShareTweetShare
Previous Post

Gov’t plans bank tax for mortgage relief even if rate falls

Next Post

Google parent Alphabet shares surge 6%, hit record after Berkshire Hathaway makes rare tech bet with $4.9 billion stake

Related Posts

1 Stock to Buy, 1 Stock to Sell This Week: Morgan Stanley, Capital One Financial

1 Stock to Buy, 1 Stock to Sell This Week: Morgan Stanley, Capital One Financial

by FeeOnlyNews.com
January 11, 2026
0

The stock market finished the first full trading week of 2026 with the Dow Jones Industrial Average and the S&P...

The Hidden Culture Risks Of Rapid Growth And How Leaders Can Counter Them

The Hidden Culture Risks Of Rapid Growth And How Leaders Can Counter Them

by FeeOnlyNews.com
January 9, 2026
0

Rapid growth — of a team, department, or company — is often coupled with an underestimation of the cultural implications....

Why Platforms Must Evolve for AI Agents

Why Platforms Must Evolve for AI Agents

by FeeOnlyNews.com
January 9, 2026
0

We are seeing a great pivot underway as technology companies paddle out to catch the next big AI wave. Domain-specific...

Three Strategic Imperatives For Tech Leaders

Three Strategic Imperatives For Tech Leaders

by FeeOnlyNews.com
January 9, 2026
0

Hg Capital’s agreement to acquire OneStream for $6.4 billion marks a pivotal moment in the enterprise performance management landscape. This...

OpenAI And b.well Promise Greater Patient Empowerment (With Some Caveats)

OpenAI And b.well Promise Greater Patient Empowerment (With Some Caveats)

by FeeOnlyNews.com
January 9, 2026
0

OpenAI’s recent partnership with b.well marks a pivotal moment in healthcare technology. With ChatGPT Health, OpenAI is integrating consumer medical records...

Autonomous Testing Platforms, Q4 2025, Is Out!

Autonomous Testing Platforms, Q4 2025, Is Out!

by FeeOnlyNews.com
January 9, 2026
0

Autonomous Testing Platforms: The Next Frontier In Software Quality The software development world is moving at breakneck speed, fueled by...

Next Post
Google parent Alphabet shares surge 6%, hit record after Berkshire Hathaway makes rare tech bet with .9 billion stake

Google parent Alphabet shares surge 6%, hit record after Berkshire Hathaway makes rare tech bet with $4.9 billion stake

Robinhood will bring cash to your doorstep. Here’s when cash still comes in handy.

Robinhood will bring cash to your doorstep. Here's when cash still comes in handy.

  • Trending
  • Comments
  • Latest
EBRI: 401(k) loans serve as health and housing lifeline

EBRI: 401(k) loans serve as health and housing lifeline

December 16, 2025
Episode 242. “Our couples therapist couldn’t fix this. Please help.”

Episode 242. “Our couples therapist couldn’t fix this. Please help.”

January 6, 2026
BAT to offload ITC Hotels shares worth Rs 2,948 crore via a block deal

BAT to offload ITC Hotels shares worth Rs 2,948 crore via a block deal

December 4, 2025
Want to Retire Comfortably Without Cutting Fun? Here’s the Trick Few People Use

Want to Retire Comfortably Without Cutting Fun? Here’s the Trick Few People Use

November 1, 2025
*HOT* Dyson V9 De-tangling Motorbar Cordless Vacuum only 9.98 shipped (Reg. 9!)

*HOT* Dyson V9 De-tangling Motorbar Cordless Vacuum only $279.98 shipped (Reg. $599!)

January 11, 2026
*HOT* Audible Discount: Get 3 Months for just alt=

*HOT* Audible Discount: Get 3 Months for just $0.99/month!

January 10, 2026
Bitcoin Price Prediction as Trump Caps Card Rates at 10%

Bitcoin Price Prediction as Trump Caps Card Rates at 10%

0
Andrew Freris on political pressure on the Fed, soaring gold and where to invest in a ‘Messy’ world

Andrew Freris on political pressure on the Fed, soaring gold and where to invest in a ‘Messy’ world

0
Women in Alts: Leading with Inspiration, Intuition, and Impact

Women in Alts: Leading with Inspiration, Intuition, and Impact

0
Week 2: A Peek Into This Past Week + What I’m Reading, Listening to, and Watching!

Week 2: A Peek Into This Past Week + What I’m Reading, Listening to, and Watching!

0
9 things naturally calm people do during stressful moments that anxious people never think to try

9 things naturally calm people do during stressful moments that anxious people never think to try

0
Key GOP senator says he won’t confirm anyone for the Fed until DOJ probe on Powell is resolved

Key GOP senator says he won’t confirm anyone for the Fed until DOJ probe on Powell is resolved

0
Andrew Freris on political pressure on the Fed, soaring gold and where to invest in a ‘Messy’ world

Andrew Freris on political pressure on the Fed, soaring gold and where to invest in a ‘Messy’ world

January 12, 2026
China’s tech bet fall short of filling property hole, report says

China’s tech bet fall short of filling property hole, report says

January 12, 2026
Pentagon Considers Raising Budget By 50%

Pentagon Considers Raising Budget By 50%

January 12, 2026
Powell says rate policy under threat after DOJ action against the Fed

Powell says rate policy under threat after DOJ action against the Fed

January 11, 2026
BHEL shares tumble 6% as Chinese import fears resurface. Should investors buy this dip?

BHEL shares tumble 6% as Chinese import fears resurface. Should investors buy this dip?

January 11, 2026
9 things naturally calm people do during stressful moments that anxious people never think to try

9 things naturally calm people do during stressful moments that anxious people never think to try

January 11, 2026
FeeOnlyNews.com

Get the latest news and follow the coverage of Business & Financial News, Stock Market Updates, Analysis, and more from the trusted sources.

CATEGORIES

  • Business
  • Cryptocurrency
  • Economy
  • Financial Planning
  • Investing
  • Market Analysis
  • Markets
  • Money
  • Personal Finance
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Andrew Freris on political pressure on the Fed, soaring gold and where to invest in a ‘Messy’ world
  • China’s tech bet fall short of filling property hole, report says
  • Pentagon Considers Raising Budget By 50%
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclaimers
  • About Us
  • Contact Us

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.