في 10 سبتمبر 2026، أصدرت أنتروبيك تقريراً استخباراتياً عن التهديدات مكوّناً من 154 صفحة يجب أن يغيّر الطريقة التي تفكر بها كل منظمة في الأمن السيبراني. ليس لأنه يكشف مستقبلاً افتراضياً ما. بل لأنه يوثّق ما حدث بالفعل - بين ديسمبر 2025 وأغسطس 2026 - عبر سبع فئات من الأضرار، من التجسس بدعم الدولة إلى الحرب الذاتية بالطائرات بدون طيار.
التقرير، Detecting and Countering Misuse of AI (اكتشاف ومعارضة سوء استخدام الذكاء الاصطناعي)، هو الإفصاح التجريبي الأشمل حتى الآن عن أنشطة التهديدات المدعومة بالذكاء الاصطناعي. ورسالته المركزية بسيطة وقاسية: الذكاء الاصطناعي لم يخترع تقنيات هجوم جديدة. لقد جعل تلك التي كنا نعرفها بالفعل مستحيلة السرعة والرخص في التنفيذ على نطاق واسع.
خط الأساس: لا شيء هنا جديد - وهذا هو المغزى
هذه هي الجملة التي يجب أن تمنع مسؤولي أمن المعلومات من النوم. تؤكد أنتروبيك صراحةً أن أيًّا من العمليات الموثقة لم تعتمد على تقنية لم يصادفها المدافعون من قبل. بيانات اعتماد مسروقة. أجهزة طرفية غير مُرقّمة. حقن SQL. التصيد الاحتيالي. نفس الدليل الذي يدافع فريق SOC ضده منذ عقد من الزمن.
ما تغيّره ليس الدليل. ما تغيّر هو اقتصاديات الهجوم.
الاستطلاع والاستغلال وتطوير الأدوات ومعالجة البيانات - كل ذلك يُفوّض الآن إلى نماذج ذكاء اصطناعي تعمل في أطر آلية بسرعة الآلة، بالتوازي. يتعامل المشغّلون الفرديون مع عشرات الضحايا في وقت واحد. تنتقل الاختراقات من الوصول الأولي إلى استخراج البيانات الكامل في ساعتين إلى ثلاث ساعات.
البراعة لم تعد إشارة موثوقة لمن يقف وراء عملية. ناشط رقمي منفرد بمفاتيح API مسروقة يمكنه الآن تنفيذ حملات كانت قبل عام تتطلب فريقاً كاملاً من المتخصصين.
أربع حالات تخبركم بكل شيء
GTG-20006 - محرك البرمجيات الخبيثة الذي يعيد بناء نفسه
تتعقب أنتروبيك هذا الفاعل تحت تسمية متسقة مع Midnight Blizzard، مجموعة التجسس المرتبطة بروسيا. استهدف المشغّل، وهو متحدث بالروسية يحمل الاسم المستعار "JackPoterz"، أكثر من 20 منظمة - مركّزة بين الجهات الحكومية والعسكرية والدبلوماسية الأوكرانية - وسرق أكثر من 300,000 سجل هوية قومية من جهة حكومية شمال أفريقية واحدة.
لكن التقنية هي ما يهم. نشر الفاعل وكلاء ذكاء اصطناعي يراقبون منتجات الأمن لاكتشاف برمجياتهم الخبيثة الخاصة. عندما وقّعت بصمة الزرع، قام الوكلاء بتعديل وإعادة بناء الكود بشكل ذاتي في حلقة حتى تجنب الاكتشاف - ثم وضعوه على استضافة مؤقتة لعمليات التصيد الاحتيالي المباشر وخطف DNS. أثقل payload مُ accompany تجمّد تحديثات أمان جهاز الضحية، مما منع أي بصمات اكتشاف جديدة من الوصول إلى الجهاز قط.
هذا يُقلّب اقتصاديات الدفاع التقليدية. لسنوات، كان للمدافعين الأفضلية: انشر بصمة، ويجب على المهاجمين إعادة البناء. الآن، تُغلق حلقة المهاجم أسرع من حلقة المدافع.
GTG-10007 - مسبك الثغرات الصفرية
قاد طالبا جامعيان في مرحلة البكالوريوس يتحدثان الصينية في مقاطعة خونان سرباً من الوكلاء الأوتومتيكيين كمصنع لبحث الثغرات.分解ّ الذكاء الاصطناعي الرئيسي عمل الاستطلاع وعمل ما بعد الاستغلال ووزّعه على وكلاء فرعيين بالتوازي مع ذاكرة حملة دائمة - حفظ قوائم الأهداف والبيانات الاعتماد المجمعة والتعليمات الدائمة عبر الجلسات.
في شهر واحد، أنتجت سير عمل واحد أكثر من عشرة احتمالات للثغرات الصفرية ضد أجهزة الشبكة. استهدف المجموعة نحو 50 منظمة. كانوا طلاباً جامعيين، وليس وحدة اختراق حكومية.
GTG-50014 - سلسلة القتل السحابية في 34 ساعة
Operating a credential-harvesting pipeline that mass-downloaded 1.8 million Android APKs, decompiled them, and scanned for hardcoded secrets using TruffleHog. Verified findings flowed to Telegram groups in real time.
The operational tempo is staggering: 2,100+ Azure AD token sets across 40+ corporate tenants in approximately 34 hours. In one case, a stolen developer token escalated to full cloud administrative control in roughly three hours. AI agents performed nearly all of the work.
GTG-50029 - One Person, 42 Targets
A single French-speaking hacktivist exploited a previously undocumented WordPress re-installation race condition and gained internal access to 14 of 42 tracked entities. Approximately 140,000 records were exfiltrated - including users' political opinions from a campaign platform. The operator then built a doxxing platform loaded with tens of millions of rows.
One person. Dozens of victims. Parallel processing through AI.
The Bioweapons Line That Changed Everything
Beyond cyber operations, the report covers influence operations, surveillance, conventional weapons, and biological misuse. Among the conventional weapons cases: a Yemen-based cell used Claude Code as its guidance, navigation, and control engineering team for a guided rocket and a multi-stage ballistic missile program with a range goal above 2,000 kilometers. A test fire was attempted. It failed. Within hours, the cell returned to Claude to debug it.
But the bioweapons disclosure may be the report's most consequential statement. Anthropic declares that newer Claude models "can no longer be assumed below the threshold for meaningful bioweapons assistance." This is the first time a major AI company has publicly acknowledged that its own models have crossed that capability threshold. It's not a warning about the future - it's an assessment of the present.
The Distillation Wars: AI Supply Chains Under Siege
The report names seven Chinese labs it caught attempting to illicitly distill Claude's reasoning capabilities - Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime, and MiniMax. Alibaba's campaign alone peaked at nearly 3 million exchanges per day, with over 151 million exchanges observed between May and July 2026, used to train Qwen models.
Moonshot and DeepSeek went further: they silently forwarded their own users' requests to Claude instead of processing them locally. The relayed traffic exposed sensitive material including live credentials for a Russian government database and a Chinese police case-management system.
This is the data sovereignty bombshell hiding in the report: foreign labs are harvesting chain-of-thought reasoning traces while unintentionally funneling military surveillance data, state database credentials, and police records into US cloud infrastructure. The distillation pipeline becomes a two-way intelligence leak.
What This Means for Your Organization
If your security architecture was designed for human-speed attackers - and it was - you're already outpaced. The gap isn't technical sophistication. It's tempo. AI-powered attackers run the same phishing kits and exploit the same unpatched CVEs you already know about. They just run them in parallel, at machine speed, with automated adaptation that defeats static detection faster than any signature pipeline can respond.
Here's what to prioritize now:
- Rotate and audit AI API keys like production credentials. Stolen keys are triple threats: resale value, attack compute billed to someone else, and attribution pointing at the key's legitimate owner.
- Harden your detection stack against adaptive malware. Signature-only detection is now a speed trap you'll lose. Behavioral and anomaly-based approaches aren't optional anymore.
- Scan your own binaries, containers, and APKs for hardcoded secrets. The ShinyHunters pipeline downloaded 1.8 million APKs and found secrets in real time. If they can do it, so can every other actor reading this report.
- Treat AI-integrated tools as part of your attack surface. Evaluator sandboxes, LLM wrappers, and reseller proxies are being probed with prompt injection to exfiltrate production keys.
- Rebuild your threat model around machine-speed adversaries. The old assumption - that scale requires resources, and resources require teams - is dead. One operator with API access and a framework like PentAGI now replaces that entire team.
Anthropic deserves credit for publishing this. The report is uncomfortable, specific, and unflinching. The rest of us - defenders, policymakers, and anyone running infrastructure - need to act like it.
The attacks aren't coming. They're here. And they don't need to be novel to be devastating. They just need to be fast.