I read the September 2026 Detecting and Countering Misuse of AI report, with a focus on the Cyber Operations section (35 pages). The report overall is a mixture of 7 distinct and disparate reports, covering the following areas:
Cyber Operations
Surveillance Operations
Influence Operations
Conventional Weapons
Biological Weapons
Scams and Fraud
Illicit Distillation
In this report I will be covering mainly the Cyber Ops section, although I encourage you read the entire report.
In a rush and looking for a quick dopamine hit? Scroll down for the videos from Anthropic of threat actors using AI.
Otherwise, here are some notable highlights from the report:
Uplift Is The Key Takeaway
Uplift is described by anthropic here as:
… uplift, a term we use to describe the AI capability boost, or how much more harm was caused with AI versus without AI. We view uplift through the lens of speed, scale, and depth, and attempt to determine how an actor’s adoption of AI meaningfully impacts each of these traits.
This is probably the biggest takeaway and impact of AI today. Every smart, imaginative, and creative person is now 10-100x faster and powerful. Not only that, but they can iterate more quickly and efficiently, with less overhead. This applies to all sides of IT and Technology, especially in hiring, but when you are criminally motivated, the payout shows in $$$.
Sophisticated attacks no longer require sophisticated attackers
This may have went without saying, but here it is in plain english.
The cybersecurity skills of AI models means that AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators. In the case studies we report below, a hacktivist using stolen API keys, disparate financially motivated individuals, and a state espionage operator each sustained multi-victim campaigns that, even just a year ago, would have required many skilled operators and specialist knowledge.
Cat and Mouse is becoming a whole new game
Because attackers are uplifted so much with powerful tools at their disposal, agents can iterate on the ground so much faster, without human intervention. As a result, security defenses can be bypassed much more quickly. Zero days are no longer limited to the black market and nation states. Anyone with a clue can direct an agent to find new vulnerabilities. (See cost in the next section)
The result of the above is that AI has inverted the cost back onto defenders. Previously, defenders might have been able to slow an attacker’s operational tempo via the deployment of a new detection. Now, at least in theory, capable adversaries can “close the loop,” bypassing traditional security detections faster than defenders can develop and deploy them.
We saw this is in the OpenAI - HuggingFace attack.
Another example with GTG-10007 (GTG-XXXX is the internal numbering schema of threat actors for Anthropic).
The group maintained an autonomous vulnerability research program. Its centerpiece was sustained research against a major security product (of a class of software deployed specifically to detect intrusions) which produced multiple previously-unknown vulnerabilities that were validated by the actor in their own lab environment. The same research effort produced working exploits for several families of network and security appliances.
Here is an example of multiple workstreams in action:
Distinct workstreams were run in parallel. One workflow conducted cyber operations involving exploitation and intrusions, another performed foreign-government reconnaissance, another reverse-engineered security products in search of new vulnerabilities, another developed and tested custom malware, and another built and maintained collection infrastructure.
Cost is Not An Issue
You might be wondering, how can attackers afford to run an agent continuously? Easy, they’re not paying for it! Attackers for the most part using stolen AI credentials and keys to run their attacks! Everything from fake AI login websites and apps to actually stolen credentials from repos, machines, and my favorite “novice service providers with poor security”.
A criminal AI supply chain has established a range of pathways to farm victim API keys and session tokens. One such approach involved masquerading as real AI service providers to deliver malware. The actor stood up websites that purported to be an intermediary service between multiple AI models and offered discounted access to frontier AI models.
This is just one example, there are so many variations of this. Claude Skills, Plugins, Marketplace, Github, and more is rife with this.
👉🏼👉🏼👉🏼 Learn more about Transfer Stations aka API Proxies.
Compromised Credentials Are The Majority Of Entry Points
We’ve been saying it for years. Identity is the new perimeter.
Most intrusions began from compromised credentials. The actor also engaged in extensive scanning, vishing, phishing and domain spoofing operations to trick employees into giving access to systems.
One French-speaking operator going by the aliases of (MeowSHA | frkoo | blazespider) ran a distributed credential-harvesting pipeline across a fleet of 10 AWS EC2 workers. This pipeline mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, decompiled them, and scanned for hardcoded secrets with TruffleHog. Verified findings were routed in real time to a Telegram group organized into over 100 source types. A parallel GitHub organization email harvester fed a second stream of stolen GitHub Personal Access Tokens. These two credential pipelines supplied the initial-access credentials for the bulk of the confirmed breaches associated with frkoo.
Until we find a way to better protect API keys
Threat Actors In Action
Anthropic put together two amazing videos of some well known threat actors, Midnight Blizzard (aka Cozy bear aka APT29) and ShinyHunters, using AI to loop and exploit a variety of targets.
Midnight Blizzard In Action
ShinyHunter In Action
Personal Takeaway
It’s always been a cat and mouse game in the security world, but now more than ever, we as defenders need to level up our game. We can no longer be complacent on off the shelf tools and traditional TTPs (tactics, techniques, and procedures).
Our attackers are using AI in parallel, and so we need to embrace AI in the defense as well. Assume breach has a whole new meaning now.
Reading these reports hopefully will help deliver a wakeup call to defenders everywhere.



