TL;DR
Anthropic Claude users are under active infostealer attack; ransomware gangs now weaponize AI coding assistants for network intrusion; Kaspersky and ServiceNow released critical patches; North Korean threat actors are diversifying beyond IT jobs into healthcare and sales recruitment fraud.
Executive Summary
- Anthropic is forcing Claude account logouts and removing payment methods following infostealer malware infections targeting an unknown number of users.
- Aurora ransomware operators have begun using SpaceX's Cursor AI coding assistant to break into target networks, with at least 10 organizations reportedly affected.
- Kaspersky released a patch for a critical vulnerability in its Endpoint Security product after Nightmare Eclipse disclosed an exploit; Microsoft released updates addressing nearly 400 security holes, including one already being actively exploited.
- North Korean threat actors are expanding recruitment fraud campaigns beyond the IT sector, with recent investigations identifying suspected workers in healthcare, sales, and marketing roles.
- ServiceNow patched three critical code injection vulnerabilities that could allow arbitrary code execution and data tampering.
Top Threats Today
1. Infostealer Campaigns Target Anthropic Claude Users
Severity: HIGH Affected: Technology
Anthropic is responding to infostealer malware infections targeting Claude users by forcing account logouts and removing payment data to prevent unauthorized Claude usage [1][2]. The scope of the attack—including the total number of affected users—remains unconfirmed, though multiple infostealers have been observed collecting session information and stealing Claude account access credentials [1].
Sources:[1] Dark Reading[2] SecurityWeek
Recommended Action
- If you use Anthropic Claude, change your password immediately and enable multi-factor authentication if available.
- Review recent Claude account activity and API usage logs for unauthorized access.
- Run malware and infostealer scans on any machine used to access Claude accounts.
- Monitor payment methods and financial accounts linked to Claude for fraudulent activity.
2. Aurora Ransomware Operators Deploy Cursor AI for Network Intrusion
Severity: HIGH Affected: Technology
Threat actors associated with Aurora (also known as Aur0ra) ransomware have been observed using SpaceX's Cursor artificial intelligence-powered coding assistant to break into target networks [1]. Researchers from CloudSEK and Gambit Security identified at least 10 targets of this attack, based on exposed infrastructure found during their independent analyses [1]. This marks a novel escalation in which AI tools designed for legitimate development purposes are being weaponized to automate reconnaissance and exploitation during ransomware campaigns.
Sources:[1] The Hacker News
Recommended Action
- Implement network segmentation and zero-trust access controls to limit lateral movement if intrusion is suspected.
- Monitor for suspicious Cursor or other AI coding assistant tool activity on development and production networks.
- Review EDR and network logs for anomalous PowerShell, shell command execution, or API calls initiated by AI-assisted tools.
- Ensure ransomware incident response playbooks are current and regularly tested.
3. Kaspersky and Microsoft Release Critical Patches
Severity: HIGH Affected: Technology
Kaspersky patched a critical vulnerability in its Endpoint Security product after the Nightmare Eclipse threat actor publicly disclosed an exploit ⚠[2]. In parallel, Microsoft released updates addressing at least 398 security vulnerabilities across Windows and supported software, including one weakness already being actively exploited in the wild and two others that were publicly disclosed prior to the patch release [1].
Sources:[1] Krebs on Security[2] SecurityWeek
Recommended Action
- Prioritize deployment of the active zero-day Windows patch across all systems on the network.
- Update Kaspersky Endpoint Security products to the latest patched version immediately on all protected systems.
- Apply the remaining Microsoft patches according to your vulnerability management process, prioritizing the two publicly detailed weaknesses.
- Monitor endpoint detection tools for exploitation attempts targeting the previously public vulnerabilities.
4. North Korean Threat Actors Expand Job Fraud Beyond IT
Severity: HIGH Affected: Healthcare
Threat actors with ties to the Democratic People's Republic of Korea (DPRK) have expanded their job fraud operations beyond the information technology sector, with recent investigations identifying suspected North Korean workers employed in healthcare, sales, and marketing roles [1]. This represents a geographic and sectoral diversification of credential harvesting and supply-chain infiltration tactics previously focused on IT recruitment.
Sources:[1] The Hacker News
Recommended Action
- Screen all new hires across healthcare, sales, and marketing departments—not just IT—through extended background verification processes.
- Implement mandatory video interview verification and domain-based email validation for all remote hiring.
- Monitor newly onboarded user accounts for unusual access patterns, data exfiltration, or lateral movement activity.
- Alert SOC and HR to any job applicants with inconsistent technical backgrounds or suspicious communication patterns.
5. ServiceNow Patches Critical Code Injection Flaws
Severity: HIGH Affected: Technology
ServiceNow released patches for three critical code injection vulnerabilities that could allow attackers to execute arbitrary code and access or tamper with data [1]. The vulnerabilities affect ServiceNow platforms widely deployed across enterprise IT operations, finance, and HR workflows.
Sources:[1] SecurityWeek
Recommended Action
- Apply ServiceNow patches to all ServiceNow instances across your organization without delay.
- Audit recent ServiceNow logs and admin activity for signs of code injection exploitation or unauthorized data access.
- Validate that no custom workflows or integrations were compromised during any potential exploitation window.
Today’s Action Checklist
- ☐ URGENT: Force Claude account logouts and verify no Claude API keys are active in production; scan all systems used for Claude access for malware.
- ☐ URGENT: Deploy Microsoft's active zero-day patch to all Windows systems; prioritize the two publicly disclosed vulnerabilities.
- ☐ URGENT: Update Kaspersky Endpoint Security and ServiceNow instances to latest patched versions.
- ☐ HIGH: Review EDR and network logs for Aurora ransomware activity and suspicious Cursor AI tool usage.
- ☐ HIGH: Implement enhanced background verification for healthcare, sales, and marketing hires; screen for North Korean job fraud indicators.
- ☐ MEDIUM: Audit API usage logs and payment methods tied to compromised Claude accounts for unauthorized activity.