The Malware Got Rewritten Faster Than It Got Caught (09/11/2026)

September 11, 2026
The Malware Got Rewritten Faster Than It Got Caught (09/11/2026)
Key Intel / TL;DR
  • Anthropic documented criminal and state-sponsored misuse of Claude between December 2025 and August 2026 covering attacks, weapons design, propaganda, and surveillance.
  • A Russian espionage group tracked as GTG-20006 used Claude to rebuild malware each time defenders detected it.
  • Wiz observed attackers chaining two JFrog Artifactory flaws between August 15 and September 8 to take administrator control and plant backdoors.
  • GitLab patched CVE-2026-85706, a CVSS 10.0 path traversal flaw that drew in-the-wild probing within hours of disclosure.
  • Three separate threat clusters exploited two Cisco Secure Firewall Management Center flaws, one of them to deploy Qilin ransomware.

Everybody already assumed attackers were using AI, so the detail worth carrying out of today’s threat reporting is the specific loop a Russian group built with it. Each detection by a defender became the input to a rewrite, and the rewritten sample went back out before the signature finished propagating.

Top 5 Critical Security Alerts

1. A Russian Group Used Claude to Stay Ahead of Detection

Anthropic disrupted a campaign it attributes to a Russian state-sponsored espionage actor tracked as GTG-20006, which built an AI-assisted workflow specifically to get ahead of the detection curve by rebuilding its malware after defenders caught each version. Signature-based and even behavior-based detection assumes the cost of producing a new variant is high enough to slow an adversary down, and this workflow removes that assumption. Your detection library is a list of things that used to work. The Hacker News has the campaign detail.

Operator Note: Weight your detection investment toward behavior and identity anomalies over file and hash indicators, because the indicators expire faster now than your feed can distribute them.

2. Anthropic Publishes the Wider Misuse Picture

The same reporting covers criminal and state misuse of Claude between December 2025 and August 2026, spanning automated exploitation and data theft across multiple victims, weapons design, propaganda operations, and mass surveillance work. Anthropic separately said it disrupted industrial-scale distillation attacks by seven China-based labs including Alibaba, Moonshot, DeepSeek, Z.ai, and MiniMax. Reading the misuse catalog from a model provider is the closest thing available to a census of what this tooling is actually being used for. The Hacker News has the misuse report and The Hacker News has the distillation findings.

3. Artifactory Flaws Chained to Plant Backdoors

Wiz reported attackers chaining two flaws in JFrog Artifactory, the repository that build pipelines pull from, to take administrator control of self-hosted servers and install backdoors, with the activity observed between August 15 and September 8. A compromised artifact repository reaches every application that builds against it, so the blast radius covers the whole software estate and stops nowhere near the server itself. All three known bugs now have patches, which makes the upgrade the entire remediation. The Hacker News has the Wiz report and The Register has the patch status.

Operator Note: If your Artifactory was reachable during that August 15 window, treat the upgrade as step one and go looking for administrator accounts and repository configurations you did not create.

4. GitLab Ships a CVSS 10.0 Path Traversal Fix

GitLab patched CVE-2026-85706, a maximum-severity path traversal flaw in the repository commits API, and researchers saw in-the-wild probing within hours of the public disclosure. File read against a source repository is credential theft by another name, since the interesting files are the deployment configurations and the CI variables rather than the application code. The speed of the probing is the part to plan around. The Hacker News has the CVE and BleepingComputer has the advisory.

5. Cisco FMC Flaws Now Carry Qilin Ransomware

Cisco disclosed that three distinct threat clusters, spanning ransomware crews and state-sponsored operators, have been exploiting two recently patched Secure Firewall Management Center flaws including CVE-2026-20079, a CVSS 10.0 authentication bypass, with one cluster deploying Qilin ransomware. We flagged the active exploitation yesterday, and what changed overnight is the identification of who is using it and for what. Three unrelated groups on the same pair of bugs means the exploit is circulating rather than held. The Hacker News has the clusters and Sophos reports Cyclops Blink returning against the same devices.

Operator Note: A firewall management console is where every rule change originates, so an intrusion there deserves a configuration diff against your last known good export and not just a patch.

Additional Security Alerts

Threat Intelligence

  • Extortion crews are phishing with passkey and SSO themes: Microsoft says actors linked to ShinyHunters and Helix are using passkey-themed social engineering to reach Microsoft 365 data, which turns a security upgrade into a credible pretext. BleepingComputer
  • A phishing campaign is timed to US Eastern business hours: KnowBe4 observed operators abusing Microsoft 365 Direct Send and sending during the window when a message looks most routine. Infosecurity Magazine
  • ClickFix is spreading across both PCs and Macs: The technique keeps working because it is simple and because it arrives while somebody is trying to finish a task. Ars Technica
  • UNC3569 abused a Chinese input method to plant GRAYRABBIT: Gen Digital traced a China-linked group exploiting Sogou Input Method on Windows through a crafted link. The Hacker News

Patches and Incidents

  • PaperCut replaced its emergency patches with a maintenance release: Two actively exploited flaws are now fixed properly in NG and MF versions 26.0.5, 25.0.13, and 24.1.10, which supersedes whatever you applied in a hurry. The Hacker News
  • Trezor puts numbers on the Brevo fallout: 347,000 customer email addresses were targeted and 2,500 people clicked the malicious link, which is a rare published conversion rate for a vendor-sourced phishing run. BleepingComputer
  • A Conti member was sentenced to four years: A Ukrainian national drew the sentence for his role in attacks between 2021 and 2022, after what prosecutors described as a second career alongside his legal practice. BleepingComputer

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)