4 September 2026

9 min read

Claude AI targeted by session hijacking malware | Cyber Intelligence Briefing – 4 September 2026

September 2026
Claude AI targeted by session hijacking malware | Cyber Intelligence Briefing – 4 September 2026 placeholder thumbnail

Top news stories this week

  1. Mis-anthropic malware. Claude AI targeted by session hijacking malware
  2. Berlin Wall-ed Off. German authorities continue to face ransomware demands as stolen government data heads to the auction block
  3. Prescription for Trouble. Healthcare giant McKesson confirms data breach after extortion attempt
  4. Cyber Crime on a Budget. Researchers discover low-cost, AI-powered ransomware operation 
  5. Open and Shut. Authorities disrupt botnet and arrest software hackers 
  6. Trust issues. Lenovo verification flaw exposes Dropbox accounts
  7. Star struck. Researchers claim administrative access to Starlink terminal

1. Claude AI targeted by session hijacking malware.

Claude, Anthropic's AI platform, has become an increasingly attractive target for cybercriminals. According to Anthropic, infostealer malware families have been stealing saved passwords, browser cookies, and locally stored credentials from infected devices. By capturing authenticated session cookies, attackers can hijack active Claude sessions without needing the user's password or MFA approval.

So what?

The growing focus on AI platforms by threat actors highlights the continued importance of foundational security controls. Regular malware scanning, strong endpoint protection and MFA remain essential to reducing the risk of session hijacking, credential theft.

[Researcher: Tlhalefo Dikolomela]  


2. German authorities continue to face ransomware demands as stolen government data heads to the auction block.

Berlin’s state government has confirmed an extortion attempt following a compromise of the city’s administrative network. Authorities disclosed that data was exfiltrated in mid-August from state systems, although the full scope of the breach remains under investigation. Berlin has stated it will not negotiate with or pay the threat actors, despite claims on the Rhysida ransomware leak site that approximately 5.79 TB of data and information relating to more than 12,000 individuals was stolen.

So what?

Cyber resilience must address both operational recovery and data protection. A working backup does little to mitigate extortion once sensitive information has been exfiltrated.  

[Researcher: Jenny Eysert]  


3. Healthcare giant McKesson confirms data breach after extortion attempt.

The extortion group has threatened to release the data if a ransom is not paid. While McKesson acknowledges data theft, the full scope of the breach remains under investigation and the attackers claims of stealing 284 million records have not been independently verified.

So what?

This incident reinforces the growing trend of healthcare organizations being targeted through identity-based attacks and data extortion rather than ransomware. Organizations should focus on secure cloud platforms and renew focus on defend against social engineering, as ShinyHunters has repeatedly leveraged these tactics to compromise identity services and gain unauthorized access to sensitive data.

[Researcher: Steve Ross]


4. Researchers discover low-cost, AI-powered ransomware operation.

Researchers recently discovered an exposed server belonging to a ransomware affiliate that revealed an AI-driven operation capable of automating attacks against GitLab instances for $0.40 to $4.00 per target. The infrastructure contained 3.1 TB of stolen data from over 30 organizations, along with AI-generated reconnaissance, exploitation tools, and ransom note templates, highlighting how AI is lowering costs and effort required to carry out large-scale cyber extortion.

SO WHAT? 

AI continues to dramatically reduce the cost, time, and skills required to launch cyberattacks. As offensive workflows become increasingly automated, organizations must prepare for threat actors to scale attacks against more targets with greater speed and consistency.

[Researcher: Steve Ross]


5. Authorities disrupt botnet and arrest software hackers.

In a multinational operation spanning the US, Bulgaria, Hungary and Romania, authorities disrupted the long-running Sality botnet by seizing infrastructure and sinkholing traffic from infected devices. Separately, Australian police arrested two men accused of involvement in the cybercriminal group TeamPCP, which allegedly used compromised open-source software packages to target and gain access to thousands of businesses worldwide.

So What?

Cybercrime operates as a cross-border enterprise, requiring coordinated international action to disrupt. These incidents show that threat actors can achieve significant scale by abusing trusted software and infrastructure, often for extended periods before law enforcement intervenes. Organizations should assume that commonly used tools could become targets or vectors of compromise and ensure appropriate controls are in place to manage software supply chain risk.

[Researcher: Gabriella Nolan]


6. Dropbox accounts compromised via Lenovo authentication flaw

Approximately 5,000 Dropbox accounts were reportedly accessed after threat actors exploited a flaw in Lenovo's email verification process. The issue enabled attackers to create fraudulent Lenovo IDs using victims' email addresses and gain access to linked Dropbox accounts. Dropbox subsequently invalidated affected sessions and introduced additional authentication requirements.

SO WHAT? 

Organizations should regularly review SSO integrations, enforce multi-factor authentication (MFA), and reassess trust relationships with external identity providers to reduce the risk of account compromise.

[Researcher: Houren Lee]


 

7. Researchers claim administrative access to Starlink Terminal

Darknavy, an independent cybersecurity research team operating in Singapore and China, claims to have gained full administrative control of a newer-generation Starlink terminal through a hardware-based attack. The research may provide deeper insight into Starlink's security architecture, although there is currently no evidence that the technique could be used to remotely compromise other Starlink users or satellites.

SO WHAT? 

 As satellite communications become increasingly critical for commercial, government, and military operations, organizations relying on such technologies should remain aware of emerging vulnerabilities and closely monitor vendor security advisories. 

[Researcher: Houren Lee]

SUBSCRIBE TO RECEIVE OUR WEEKLY CYBER THREAT INTELLIGENCE BRIEFING VIA EMAIL

The S-RM Cyber Intelligence Briefing is a weekly round-up of the latest cyber security news, trends, and indicators, curated by our intelligence specialists.

To discuss this briefing or other industry developments, please reach out to one of our experts.

Editors

Share this post

Subscribe to our insights

Get industry news and expert insights straight to your inbox.