SNACK three-line summary
- Anthropic analyzed 832 accounts blocked for malicious activity from March 2025 to March 2026 in the original article's summary.
- The report says 560 accounts, or 67.3%, used AI for preparatory work such as malware creation, while later-stage internal tasks also became more important.
- Anthropic argues that post-intrusion activity and agent-like orchestration can be harder to describe with existing MITRE ATT&CK categories alone.
Editor quick take
- Nea — The value of the report is that it separates which attack stages are changing instead of only saying AI is scary.
- Red — Defenders should pay attention to the work after entry: account discovery, next-step selection, and chained operations.
- Kirari🌟 — The practical concern is that AI can reduce the skill gap in later attack workflow, making old attacker-skill assumptions less reliable.
The quick read
Anthropic's official report maps a year of AI-enabled cyber threat activity against MITRE ATT&CK. The original article highlights that the discussion is about attack stages and risk movement, not only general fear about AI.
What the numbers show
The report analyzed 832 blocked accounts. The original article cites 560 accounts, or 67.3%, using AI for preparatory steps, while medium-or-higher risk activity rose from 33% in the first six months to 56% in the second six months.
Why post-intrusion matters
The article emphasizes movement from initial access toward activity inside the system. Account discovery increased, while AI-assisted phishing decreased in the cited comparison, changing where defenders need to watch.
Editor view
For ordinary readers this is a security trend note. For organizations, it points to monitoring AI-assisted chains, internal reconnaissance, credentials, and tool policy rather than only blocking obvious first-entry attempts.
Quick reference
| Check | Details |
|---|---|
| Publisher | Anthropic |
| Period | March 2025 to March 2026 in the original article |
| Accounts analyzed | 832 blocked malicious-activity accounts |
| Most common use | Preparatory work such as malware writing |
| Main warning | More risk in internal discovery and agent-style follow-up actions |
Sources and check date · Game Sunakku English edition. Checked: June 6, 2026
Leave a comment