
Security Now · 2026-06-10 · 2h 37m
Key moments - from our scoring
Substance score
24 / 100
Five dimensions, 20 points each
Anthropic's comprehensive red team report, mapped against the MITRE ATT&CK framework, demonstrates that AI models like Claude are being actively weaponized for real-world cyber attacks. The company tracked 832 banned accounts from March 2025 to March 2026, documenting attackers using AI to build custom malware, automate code obfuscation, harvest data from compromised systems, and orchestrate multi-stage attack chains with minimal human intervention. The most alarming finding: medium- and high-risk threat actors surged from 33% to 56% of the abuse cases over the year. A notable case, GTG1002, developed an AI-driven platform capable of autonomous network scanning, real-time exploitation in cloud environments, and complete attack lifecycle orchestration. This shift fundamentally democratizes cybercrime by erasing the traditional skill barrier - less experienced actors can now execute sophisticated attacks through agentic orchestration, where AI chains together reconnaissance, lateral movement, and exfiltration stages independently. Security defenders face mounting pressure as open-source and locally-run AI models proliferate, giving attackers access to systems without cloud platform safeguards. Enterprise security teams must adapt quickly, though the MITRE ATT&CK taxonomy itself may need revision to capture emerging AI-driven threat behaviors that don't fit existing categories.
Anthropic tracked 832 banned accounts from March 2025 to March 2026 and mapped their abuse patterns to the MITRE ATT&CK framework, a standard classification system for identifying cyberattack phases and tactics.
Attackers primarily use AI to build and refine custom malware, automate malicious code obfuscation to evade detection, and generate scripts for data harvesting from compromised systems.
Agentic orchestration refers to using AI scaffolding or code architecture that allows AI agents to autonomously chain together multiple attack stages - from reconnaissance to exfiltration - with minimal human oversight.
GTG1002 developed an AI-driven platform capable of autonomously scanning networks, executing real-time exploitation in cloud environments, and orchestrating the entire attack lifecycle independently.
Open-source and locally-run AI models operate without the safety constraints of cloud-based platforms, giving attackers fewer restrictions and making it harder for defenders to monitor or block malicious LLM use.
Our reviewer’s read on each dimension, with quotes from the episode.
The transcript reads as a summary or marketing piece rather than a deep technical discussion. It hits high-level talking points (AI lowers skill barriers, attackers use AI for malware, MITRE ATT&CK framework applies) but offers minimal novel insight beyond the premise that AI enables cyberattacks. There's no deep analysis of *why* specific techniques work better with AI, no discussion of detection methods, and no substantive operator takeaways beyond 'upgrade your defenses.'
attackers are becoming less dependent on traditional technical expertise and more reliant on AI's ability to automate complex tasks
the highest-risk cases didn't always employ the widest range of techniques. Instead, their danger lay in agentic orchestration
The framing - 'AI is being weaponized for cybercrime' - is neither novel nor contrarian in 2026. The report structure (tracking banned accounts, mapping to MITRE ATT&CK) is standard security research methodology. No fresh angles, counterintuitive findings, or first-principles rethinking are present. The content recycles familiar talking points about skill democratization and automation without challenging existing security orthodoxy.
AI is no longer just a tool for innovators and defenders - it has become a powerful weapon for cybercriminals.
The traditional barrier - the need for high technical skill - is being erased
This transcript does not appear to be an actual interview transcript. It reads as a blog summary or show notes for an episode, with no direct guest dialogue, no named security practitioners, and no operators discussing real-world experience. The 'Security Now' framing is generic attribution rather than evidence of substantive guest involvement. No actual guest appears to be present or quoted.
According to Security Now, attackers most commonly use AI for:
The discussion on Security Now showcased one particularly alarming case
The transcript references Anthropic's specific research (832 banned accounts, March 2025 to March 2026 tracking, 33% to 56% risk escalation) and one threat actor example (GTG1002). However, those examples are extremely sparse and lack depth: no specific attack vectors named, no real company victims, no dollar losses, no time-to-breach metrics, and no technical details on how the AI was actually used. The numbers provided are aggregated statistics rather than concrete case evidence.
tracking 832 banned accounts from March 2025 to March 2026
the share of medium- or high-risk actors moving from 33% to 56% within just one year
This is not a transcript of a conversation. It appears to be auto-generated show notes or a summary article with no actual dialogue, questions, or host-guest interaction. There is no evidence of sharp questioning, follow-ups, or productive disagreement. The format is static claims followed by supporting statements, entirely unlike actual conversational podcast content.
According to Security Now, attackers most commonly use AI for: Building and refining custom malware and attack scripts.
The report shows a clear shift: attackers are becoming less dependent on traditional technical expertise
Computed from the transcript - who did the talking, and the words that came up most.
Discover how Anthropic's secretive red team and the MITRE ATT&CK framework are mapping the chilling rise of malicious AI use, revealing cyber threats that now move faster than defenders can respond. Was a U.S. law firm right to pay a $20 million ransom. Could Cisco have yet another SD-WAN 0-day in the wild. Why is it so difficult to author secure PHP code. Teens use "WeedHack" to spy and attack each other. Researchers create the first AI-enabled Internet worm. Google Chrome pops-up "Shop with confidence." What... The discovered and irresponsibly disclosed HTTP/2 Bomb. What Anthropic learns from their past year of Claude abuse: It's bad Show Notes - Hosts: Steve Gibson and Leo Laporte Download or
Transcribed and scored by The B2B Podcast Index.
AI-Powered Cyber Attacks: What Anthropic's Latest Report Tells Us Primary Navigation Podcasts Club Blog Subscribe Sponsors More… Tech AI-Powered Cyber Attacks: What Anthropic's Latest Report Tells Us Jun 10th 2026 AI-generated, human-reviewed. AI is no longer just a tool for innovators and defenders - it has become a powerful weapon for cybercriminals. On Security Now , the hosts dissect Anthropic's comprehensive Red Team report, which reveals how malicious actors are already using AI models like Claude to supercharge cyber attacks and why this threatens to change security as we know it.
How Anthropic Discovered AI-Powered Threats Anthropic, an AI safety company, conducted a groundbreaking study mapping a year’s worth of abuse involving their AI models. By tracking 832 banned accounts from March 2025 to March 2026, they provided a rare look at how cybercriminals leverage large language models (LLMs) for real-world attacks. The analysis was mapped to the MITRE ATT&CK framework - a widely used classification system for identifying every phase of a cyberattack, from initial reconnaissance to data theft and impact.
This approach enabled Anthropic to categorize the exact tactics and techniques being enhanced or enabled by AI. What Are Attackers Doing with AI? According to Security Now , attackers most commonly use AI for: Building and refining custom malware and attack scripts. Automating the development of tools that can evade detection , such as obfuscating malicious code to bypass antivirus protections.
Harvesting data from compromised systems using AI-generated scripts and techniques. The report shows a clear shift: attackers are becoming less dependent on traditional technical expertise and more reliant on AI's ability to automate complex tasks. Over time, the risk level associated with these threat actors increased sharply, with the share of medium- or high-risk actors moving from 33% to 56% within just one year. How AI Lowers the Bar for Cybercriminals A critical insight from Anthropic’s findings, highlighted on Security Now , is that AI is empowering less skilled individuals to execute sophisticated attacks.
The traditional barrier - the need for high technical skill - is being erased as AI agents automate everything from lateral movement across victim networks to remote service exploitation. Notably, the highest-risk cases didn't always employ the widest range of techniques. Instead, their danger lay in agentic orchestration - the use of "scaffolding" or code architecture that allows AI to chain together multiple stages of an attack autonomously, sometimes with minimal human oversight.
Examples of Advanced AI-Driven Threats The discussion on Security Now showcased one particularly alarming case from Anthropic’s report: a threat actor codenamed GTG1002 developed an AI-driven platform capable of: Autonomously scanning and mapping network services Executing real-time exploitation and pivoting within cloud environments Orchestrating the entire attack lifecycle, from reconnaissance to data exfiltration This demonstrates a clear move toward AI agents handling tactical operations, letting humans focus only on strategic decisions.
Implications for Security Defenders Security Now emphasized that defenders must adapt quickly. The MITRE ATT&CK taxonomy itself may need updating because many high-risk behaviors by AI-driven attacks don't fit current categories. There’s also concern that enterprise security teams will soon have to counter AI adversaries operating without the oversight or constraints of mainstream, cloud-based AI models. With the proliferation of open-source and locally-run AI, attackers will face fewer restrictions, making it harder for defenders and vendors to monitor or block malicious use of LLMs.
What You Need to Know AI is accelerating cybercrime, automating complex techniques previously limited to skilled hackers. Malicious actors are increasingly using AI for high-risk activities like credential dumping, lateral movement, and persistent network access. Anthropic’s year-long report shows a surge in the risk and capability of attackers using AI. The traditional skill gap in cybercrime is eroding as AI “scaffolds” chain together attack stages independently.
As AI models become available outside cloud platforms, attackers will avoid most current safeguards. The Bottom Line AI is fundamentally changing the cybersecurity threat landscape. According to Security Now , the latest research from Anthropic demonstrates that cyber attackers are not just experimenting - they are already using AI to amplify their abilities and bypass traditional defenses. Organizations must upgrade their defenses and awareness now, as the risks and tactics are moving faster than many might expect.
Stay informed with Security Now for the latest in cybersecurity trends and threats. Subscribe here: https://twit.tv/shows/security-now/episodes/1082 Share: Copied! Security Now #1082 Jun 9 2026 - The Malicious Use of AI Anthropic’s Red Team Report All Tech posts Contact Advertise CC License Privacy Policy Ad Choices TOS Store Twitter Facebook Instgram YouTube Yes, like every site on the Internet, this site uses cookies.
So now you know. Learn more Hide Home Schedule Subscribe Club TWiT About Club TWiT FAQ Access Account Members-Only Podcasts Update Payment Method Connect to Discord TWiT Blog Recent Posts Advertise Sponsors Store People About What is TWiT.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.