Critical

Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecast

Help Net Security
Actively Exploited

Overview

Anthropic has locked users out of their Claude accounts after attackers compromised login sessions using infostealer malware. This incident raises concerns about the security of user credentials and the potential for unauthorized access to sensitive information. While the company is taking steps to protect users by enforcing account locks, it highlights the risks associated with infostealer malware that targets login information. Users may need to reset their passwords and monitor their accounts for any suspicious activity. This situation serves as a reminder for individuals to be vigilant about their online security practices.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Claude accounts
  • Action Required: Users are advised to reset their passwords and monitor their accounts for suspicious activity.
  • Timeline: Ongoing since September 2023

Original Article Summary

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Anthropic locks out Claude users after infostealers hijack login sessions Anthropic has started locking users out of their Claude accounts due to their login sessions having been compromised through infostealer malware. September 2026 Patch Tuesday forecast: All we need is more time The Patch Apocalypse is continuing unabated. We are seeing record numbers of patches being released and reported CVEs … More → The post Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecast appeared first on Help Net Security.

Impact

Claude accounts

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Ongoing since September 2023

Remediation

Users are advised to reset their passwords and monitor their accounts for suspicious activity.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Patch, Malware.

Related Coverage

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 113

Security Affairs

Recent reports indicate that hackers are using infostealer malware to hijack login sessions for Claude, a popular AI tool. This type of malware captures sensitive information from users, allowing attackers to gain unauthorized access to accounts. The evolving Fire Ant malware has been noted for its ability to operate at a deeper level within systems, moving from hypervisors to trusted infrastructures. Additionally, a new toolkit called Gryxa has emerged, designed to monitor how users uninstall it. Another malware variant, ValleyRAT, is disguising itself as adware to trick users into installing it. These developments suggest a growing sophistication among cybercriminals and a heightened risk for users across various platforms, emphasizing the need for robust security measures.

Sep 6, 2026

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

The Hacker News

A new vulnerability in Magento Open Source and Adobe Commerce, identified by the Dutch security firm Sansec and named StyleSmuggler, is currently being exploited by attackers. This flaw allows malicious code to be executed on online store servers without requiring a login, which poses a significant risk to e-commerce platforms. Sansec reported that attacks began on September 4, 2023, just a day before the advisory was published. Online stores using these platforms are at risk of being backdoored, which can lead to unauthorized access and data breaches. Companies running affected systems need to take this threat seriously and implement necessary security measures to protect their customers and data.

Sep 5, 2026

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

The Hacker News

JetBrains recently informed users of its Cadence software to revoke and rotate all credentials after a security breach linked to an unpatched vulnerability in TeamCity. Attackers exploited this flaw to gain access to JetBrains' environment, which potentially exposed AWS credentials. The company emphasized the urgency for users to take action and secure their accounts, as any credentials used for Cadence executions may be compromised. This incident highlights the risks associated with unpatched software and the importance of maintaining security updates. Users should act quickly to protect their cloud resources and prevent unauthorized access.

Sep 5, 2026

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

The Hacker News

Broadcom has issued security updates to address two vulnerabilities in VMware Workstation and VMware Fusion, one of which is particularly severe. This critical vulnerability, identified as CVE-2026-59346, has a CVSS score of 9.3 and involves an integer-overflow issue. If exploited by a local attacker with elevated privileges, this flaw could allow them to execute arbitrary code on the host system. This poses a significant risk to users of these virtualization products, as it could lead to unauthorized access and control over the host machine. Users are urged to apply the updates promptly to mitigate this risk.

Sep 5, 2026

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

BleepingComputer

Cybercriminals are exploiting over 5,400 hacked small-business websites to distribute ClickFix payloads, which are stored in smart contracts on the BNB Smart Chain (BSC). This operation targets unsuspecting website owners and their visitors, potentially leading to unauthorized access and data theft. The use of blockchain technology for storing malicious payloads makes it challenging for traditional security measures to detect and mitigate these attacks. This incident highlights the growing trend of attackers using compromised legitimate sites as a delivery mechanism, raising concerns for both businesses and consumers. Organizations should take immediate steps to secure their websites and monitor for any signs of compromise.

Sep 5, 2026

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

The Hacker News

Trezor, a manufacturer of hardware wallets, announced that a data breach at its shipping provider, ShipMonk, has compromised the personal information of approximately 67,000 U.S. customers. The leaked data includes names, email addresses, phone numbers, shipping addresses, and order numbers from transactions made between November 2019 and August 2021. Despite this breach, Trezor stated that the security of its hardware wallets remains intact, meaning users' funds are not at risk. This incident raises concerns about how third-party vendors can impact customer data security and highlights the importance of robust data protection practices in supply chains. Customers affected by this breach should remain vigilant for potential phishing attempts or other malicious activities using their exposed information.

Sep 5, 2026