---
title: "Claude Aids Cyberattacks , Cisco Flaws Exploited, CISA Adds Exploited  | DMARC Report"
description: "This week’s cybersecurity news covers AI-driven attacks, exploited Cisco and GitLab flaws, ransomware breaches, phishing campaigns, and emerging threats."
image: "https://dmarcreport.com/og/blog/claude-aids-cyberattacks-cisco-flaws-exploited-cisa-adds-exploited.png"
canonical: "https://dmarcreport.com/blog/claude-aids-cyberattacks-cisco-flaws-exploited-cisa-adds-exploited/"
---

Quick Answer

This week’s cyber news highlights AI-driven attacks, exploited Cisco and GitLab flaws, ransomware breaches, phishing campaigns, and zero-days. Organizations should strengthen patching, identity security, and email authentication with SPF, DKIM, and DMARC.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fclaude-aids-cyberattacks-cisco-flaws-exploited-cisa-adds-exploited%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Claude%20Aids%20Cyberattacks%20%2C%20Cisco%20Flaws%20Exploited%2C%20CISA%20Adds%20Exploited%20&url=undefined%2Fblog%2Fclaude-aids-cyberattacks-cisco-flaws-exploited-cisa-adds-exploited%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fclaude-aids-cyberattacks-cisco-flaws-exploited-cisa-adds-exploited%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fclaude-aids-cyberattacks-cisco-flaws-exploited-cisa-adds-exploited%2F&title=Claude%20Aids%20Cyberattacks%20%2C%20Cisco%20Flaws%20Exploited%2C%20CISA%20Adds%20Exploited%20 "Share on Reddit") [ ](mailto:?subject=Claude%20Aids%20Cyberattacks%20%2C%20Cisco%20Flaws%20Exploited%2C%20CISA%20Adds%20Exploited%20&body=Check out this article: undefined%2Fblog%2Fclaude-aids-cyberattacks-cisco-flaws-exploited-cisa-adds-exploited%2F "Share via Email") 

![Cybersecurity Threats and AI Attacks](https://media.mailhop.org/dmarcreport/dmarc-lookup-7710-1789472233558.jpg) 

This week’s cyber landscape was dominated by the growing role of AI in both attacks and defense, a wave of [critical infrastructure vulnerabilities](https://industrialcyber.co/features/cyber-informed-engineering-shifts-critical-infrastructure-security-from-protecting-networks-to-engineering-out-consequences/) under active exploitation, and fresh breaches hitting fintech, government, and **healthcare organizations**. _From Anthropic’s own threat intelligence report exposing state-sponsored abuse of Claude, to a maximum-severity Cisco firewall flaw being used to deploy ransomware, this week made clear that attackers are moving faster than ever — and that email and identity remain the weakest links._

## Anthropic discloses state-sponsored hackers abusing Claude for cyberattacks

_Anthropic published its September 2026 threat intelligence report, revealing that financially motivated criminals and state-sponsored espionage groups linked to Russia and China attempted to misuse its Claude models between December 2025 and August 2026._ The report documents AI being used across the full cyber kill chain — reconnaissance, exploitation, and data theft — with one operation reportedly building tooling that [could automatically](https://thehackernews.com/2026/09/claude-used-to-automate-exploitation.html) rebuild and redeploy malware once detected by security products. Anthropic said no [malicious activity](https://www.npr.org/2026/09/10/g-s1-142755/anthropic-ai-threat-actors-report-bio-weapons) was found on its Fable or **Mythos models**, which carry extra safeguards. <https://thehackernews.com/2026/09/claude-used-to-automate-exploitation.html>

## Cisco firewall flaws exploited to deploy Qilin ransomware

Cisco confirmed that three separate threat clusters — a mix of state-sponsored and ransomware actors — exploited two previously patched [Secure Firewall Management Center vulnerabilities](https://www.technadu.com/cisco-secure-firewall-management-center-vulnerabilities-under-active-exploitation-talos-warns/636333/) to [steal credentials](https://www.cybersecuritydive.com/news/credential-harvesting-campaign-react2shell-cisco/816726/) and deploy Qilin ransomware. One of the flaws carries a maximum [CVSS score of 10.0](https://innoculator.com/the-curious-case-of-the-10-0-cvss-the-2025-edition/) and allows unauthenticated attackers to gain root access. <https://thehackernews.com/2026/09/cisco-fmc-flaws-exploited-to-steal.html>

![Dmarc Record Generator 5203](https://media.mailhop.org/dmarcreport/dmarc-record-generator-5203-1789473001064.jpg)

## CISA adds actively exploited Artifactory, ScreenConnect, and RouterOS flaws to its KEV list

CISA added five actively exploited vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and **MikroTik RouterOS** to its [Known Exploited Vulnerabilities catalog](https://www.cybersecurity-insiders.com/cisa-kev-catalog-seven-exploited-flaws/), giving federal agencies a strict remediation deadline. <https://www.wiu.edu/cybersecuritycenter/cybernews.php>

## GitLab’s maximum-severity file-read flaw draws active exploitation attempts

A [CVSS 10.0 GitLab vulnerability](https://sqmagazine.co.uk/gitlab-flaw-cve-2026-85706-cisa-kev-exploited/) that lets an authenticated attacker with Duo Chat access extract sensitive credentials via a crafted **GraphQL request** is now being probed in the wild. _CISA confirmed active exploitation and added it to its KEV catalog, giving federal agencies until September 14 to patch._ <https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html>

## Dutch cybersecurity agency warns of imminent Check Point VPN exploitation

The **Dutch National Cyber Security Centrum** warned organizations of imminent exploitation of two critical [Check Point VPN vulnerabilities](https://www.computing.co.uk/news/2026/security/attacks-on-critical-check-point-vpn-flaws-imminent-warning), urging immediate patching before attackers weaponize them at scale. <https://www.bleepingcomputer.com/news/security/>

## Microsoft warns of passkey phishing campaign hijacking cloud accounts

**Microsoft disclosed two separate campaigns:** one abusing third-party email delivery infrastructure to send over a million CEO-impersonation scam emails, and a second using [passkey-themed](https://www.csoonline.com/article/4221110/attackers-use-passkey-themed-scams-to-hijack-microsoft-365-accounts.html) social engineering to breach Microsoft cloud environments and exfiltrate data. <https://www.wiu.edu/cybersecuritycenter/cybernews.php>

Strengthening [DMARC](https://dmarcreport.com/), [DKIM](https://dmarcreport.com/what-is-dkim/), and [SPF](https://dmarcreport.com/what-is-spf/) can help organizations **reduce phishing**, [email spoofing](https://www.infosecurity-magazine.com/news/infosec2025-email-domains-spoofing/), and identity-based attacks highlighted in this week’s cybersecurity news.![Dmarc Generator 5203](https://media.mailhop.org/dmarcreport/dmarc-generator-5203-1789473027452.jpg)

## Veradigm confirms patient data breach tied to “Gentlemen” ransomware gang

**Healthcare technology** company Veradigm disclosed a data breach after a [cybersecurity](https://dmarcreport.com/blog/how-to-stay-one-step-ahead-in-the-cybersecurity-race/) incident at a [third-party vendor](https://vendict.com/glossary/what-is-a-third-party-vendor) exposed patient personal data, with the attack claimed by the [Gentlemen ransomware gang](https://www.bleepingcomputer.com/news/security/veradigm-discloses-patient-data-breach-after-gentlemen-gang-claims-attack/). <https://www.bleepingcomputer.com/news/security/veradigm-discloses-patient-data-breach-after-gentlemen-gang-claims-attack/>

## “The Gentlemen” ransomware group also hits a Canadian airline

The same ransomware group behind the [Veradigm breach](https://www.morningstar.com/news/pr-newswire/20260902ny39480/did-veradigm-inc-insiders-breach-their-fiduciary-duties-to-shareholders) claimed a separate attack on a Canadian airline this week, part of a **broader pattern** of the group targeting transportation and healthcare organizations across multiple countries. <https://asec.ahnlab.com/en/95338/>

## LAPSUS$ resumes activity with “Chapter II,” teases new victim

_The LAPSUS$ extortion group resurfaced this week with a new campaign chapter, teasing an upcoming victim disclosure, while a separate “AUDIT TEAM” extortion crew hit four organizations across South Korea, Germany, and Argentina._ <https://asec.ahnlab.com/en/95338/>

![Create Dmarc Record 1039](https://media.mailhop.org/dmarcreport/create-dmarc-record-1039-1789473056900.jpg)

## Mathspace breach exposes data of more than 1 million students and parents

Online math learning platform [Mathspace disclosed that attackers stole data](https://australiancybersecuritymagazine.com.au/mathspace-breach-exposed-data-of-more-than-1-million-students-parents-and-teachers/) belonging to more than a million students, staff, and parents after breaching its internal **Metabase reporting system**. <https://www.privacyguides.org/news/2026/09/11/data-breach-roundup-sep-4-10-2026/>

## China-linked hackers exploit Tencent Sogou flaw to deploy GrayRabbit backdoor

Researchers found a China-aligned espionage group, tracked as **UNC3569**, exploiting a critical [one-click remote](https://www.anyviewer.com/help/one-click-remote-control.html) code execution flaw in Tencent’s Sogou Input Method for Windows to deploy the [GrayRabbit backdoor](https://gbhackers.com/grayrabbit-backdoor/), primarily targeting government, education, and finance sectors in East and Southeast Asia. <https://www.bleepingcomputer.com/>

![Dmarc Report 8963](https://media.mailhop.org/dmarcreport/dmarc-report-8963-1789472236028.jpg)

## US says Chinese firms extracted billions of tokens from frontier AI models

A report this week detailed how [Chinese firms](https://www.darkreading.com/application-security/us-government-chinese-ai-firms-distilling-frontier-models) have been systematically extracting billions of tokens’ worth of output from leading frontier AI models, raising fresh concerns about AI model theft and distillation as a **national security** issue. <https://www.bleepingcomputer.com/news/security/us-says-chinese-firms-extracted-billions-of-tokens-from-frontier-ai-models/>

## Magento and Adobe Commerce zero-day used to backdoor online stores

Researchers at Sansec disclosed that attackers are exploiting an unpatched [Magento and Adobe Commerce vulnerability](https://www.securityweek.com/adobe-commerce-zero-day-exploited-to-backdoor-online-stores/) to run unauthenticated **server-side code** and install persistent backdoors on [e-commerce](https://en.wikipedia.org/wiki/E-commerce) stores, with confirmed victims even among stores running Adobe’s latest security patches. <https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html>

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

[ Brad Slavin ](/authors/brad-slavin/) 

General Manager

Founder and General Manager of DuoCircle. Product strategy and commercial lead for DMARC Report's 2,000+ customer base.

[LinkedIn Profile →](https://www.linkedin.com/in/bradslavin) 

## Take control of your DMARC reports

Turn raw XML into actionable dashboards. Start free - no credit card required.

[Start Free Trial](https://app.dmarcreport.com/signup?plan=free) [Check Your DMARC Record](/tools/dmarc-checker/) 

Scan Your Domain Now

Instantly scan your domain for DKIM, SPF, and DMARC issues

Check My Domain 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fdmarcreport.com%2Fblog%2Fclaude-aids-cyberattacks-cisco-flaws-exploited-cisa-adds-exploited%2F) [ ](https://twitter.com/intent/tweet?text=Claude%20Aids%20Cyberattacks%20%2C%20Cisco%20Flaws%20Exploited%2C%20CISA%20Adds%20Exploited%20&url=https%3A%2F%2Fdmarcreport.com%2Fblog%2Fclaude-aids-cyberattacks-cisco-flaws-exploited-cisa-adds-exploited%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fdmarcreport.com%2Fblog%2Fclaude-aids-cyberattacks-cisco-flaws-exploited-cisa-adds-exploited%2F) Copy 

Related Articles

- [ ![25 practical reasons every MSP should add a pricing estimator to their website](https://media.mailhop.org/dmarcreport/images/2022/04/dmarc-alignment-6379.jpg)  25 practical reasons every MSP should add a pricing estimator to their website Advanced ](/blog/25-reasons-every-msp-should-add-pricing-estimator-to-website/)
- [ ![AI cybersecurity breach concept](https://media.mailhop.org/dmarcreport/dmarc-check-5301-1785846252910.jpg)  AI Patch Failures, Claude Hacked Companies, Autonomous AI Breach Advanced ](/blog/ai-patch-failures-claude-hacked-companies-autonomous-ai-breach/)
- [ ![UK Plant Shutdown](https://media.mailhop.org/dmarcreport/how-to-create-dmarc-record-5227-1787656932438.jpg)  Apollo Data Breach, Claude Code Attack, UK Plant Shutdown Advanced ](/blog/apollo-data-breach-claude-code-attack-uk-plant-shutdown/)
- [ ![Blockchain Email Security](https://media.mailhop.org/dmarcreport/dmarc-check-3640-1781523375849.jpg)  Blockchain and Email Security: Exploring the Future of Trusted Digital Communication Advanced ](/blog/blockchain-email-security-future-trusted-digital-communication-explained/)

## Related Articles

[  Advanced 2m  25 practical reasons every MSP should add a pricing estimator to their website  Jan 15, 2026 ](/blog/25-reasons-every-msp-should-add-pricing-estimator-to-website/)[  Advanced  AI Patch Failures, Claude Hacked Companies, Autonomous AI Breach  Aug 4, 2026 ](/blog/ai-patch-failures-claude-hacked-companies-autonomous-ai-breach/)[  Advanced  Apollo Data Breach, Claude Code Attack, UK Plant Shutdown  Aug 25, 2026 ](/blog/apollo-data-breach-claude-code-attack-uk-plant-shutdown/)[  Advanced  Blockchain and Email Security: Exploring the Future of Trusted Digital Communication  Jun 15, 2026 ](/blog/blockchain-email-security-future-trusted-digital-communication-explained/)

```json
{"@context":"https://schema.org","@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com","logo":{"@type":"ImageObject","url":"https://dmarcreport.com/images/dmarcreport-logo.png"},"description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138898167","https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.g2.com/products/dmarc-report/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc","https://www.trustradius.com/products/duocircle/reviews"],"aggregateRating":{"@type":"AggregateRating","ratingValue":"4.8","reviewCount":"471","bestRating":"5","worstRating":"1","url":"https://www.g2.com/products/dmarc-report/reviews"},"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://dmarcreport.com/support/"},"knowsAbout":["DMARC","DMARC Reporting","DMARC Aggregate Reports","DMARC Forensic Reports","Sender Policy Framework","DKIM","Email Authentication","Email Security","DNS Management","Email Deliverability"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DMARC Report","url":"https://dmarcreport.com","description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","publisher":{"@type":"Organization","name":"DMARC Report","url":"https://dmarcreport.com","logo":{"@type":"ImageObject","url":"https://dmarcreport.com/images/dmarcreport-logo.png"},"description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Claude Aids Cyberattacks , Cisco Flaws Exploited, CISA Adds Exploited ","description":"This week’s cybersecurity news covers AI-driven attacks, exploited Cisco and GitLab flaws, ransomware breaches, phishing campaigns, and emerging threats.","url":"https://dmarcreport.com/blog/claude-aids-cyberattacks-cisco-flaws-exploited-cisa-adds-exploited/","datePublished":"2026-09-15T00:00:00.000Z","dateModified":"2026-09-15T00:00:00.000Z","dateCreated":"2026-09-15T00:00:00.000Z","author":{"@type":"Person","@id":"https://dmarcreport.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://dmarcreport.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin is the founder and General Manager of DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. He founded DuoCircle in 2014 and has led the company's growth to 2,000+ customers across its email security product family. Brad's focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DMARC Report","url":"https://dmarcreport.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com","logo":{"@type":"ImageObject","url":"https://dmarcreport.com/images/dmarcreport-logo.png"},"description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138898167","https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.g2.com/products/dmarc-report/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc","https://www.trustradius.com/products/duocircle/reviews"],"aggregateRating":{"@type":"AggregateRating","ratingValue":"4.8","reviewCount":"471","bestRating":"5","worstRating":"1","url":"https://www.g2.com/products/dmarc-report/reviews"},"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://dmarcreport.com/support/"},"knowsAbout":["DMARC","DMARC Reporting","DMARC Aggregate Reports","DMARC Forensic Reports","Sender Policy Framework","DKIM","Email Authentication","Email Security","DNS Management","Email Deliverability"]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://dmarcreport.com/blog/claude-aids-cyberattacks-cisco-flaws-exploited-cisa-adds-exploited/"},"articleSection":"advanced","keywords":"","image":{"@type":"ImageObject","url":"https://media.mailhop.org/dmarcreport/dmarc-lookup-7710-1789472233558.jpg","caption":"Cybersecurity Threats and AI Attacks"},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://dmarcreport.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://dmarcreport.com/blog/"},{"@type":"ListItem","position":3,"name":"Advanced","item":"https://dmarcreport.com/advanced/"},{"@type":"ListItem","position":4,"name":"Claude Aids Cyberattacks , Cisco Flaws Exploited, CISA Adds Exploited ","item":"https://dmarcreport.com/blog/claude-aids-cyberattacks-cisco-flaws-exploited-cisa-adds-exploited/"}]}
```
