Anthropic Says Undergrads Ran a Zero-Day Foundry on Claude
Security / news
Anthropic Says Undergrads Ran a Zero-Day Foundry on Claude
The group, tracked as GTG-10007, produced more than a dozen possible zero-day findings against network appliances in a single month, targeting about 50 organizations.
Two operators identified as undergraduate students, working with other Chinese-speaking actors likely based in Changsha, in China's Hunan province, ran an autonomous vulnerability-research operation against roughly 50 organizations using Claude, Anthropic said in a threat intelligence report published Thursday.
Anthropic tracks the group as GTG-10007 in "Detecting and countering misuse of AI: September 2026," which covers activity the company disrupted between December 2025 and August 2026 across cyber operations, influence campaigns, surveillance, fraud and biological and weapons misuse.
What "a dozen possible zero-days" actually means
One of the group's workstreams, iterating automated exploit generation against network-appliance firmware, "yielded more than a dozen possible zero day findings in a single month," Anthropic said. Anthropic's own wording is "possible": the report does not say how many of those findings were confirmed exploitable, reported to any vendor, or used against a live target. That distinction matters, because a candidate finding from automated fuzzing and a working, weaponized exploit are different things, and Anthropic's report does not close the gap between them for this group.
CyberScoop, which reviewed the same report, said the case shows "sophistication has stopped being a reliable signal of who is behind an operation," pairing university students with the kind of vulnerability-research output Anthropic's report associates elsewhere with state-sponsored groups.
How the operation ran without operators watching it
Anthropic described the group deploying "agent swarms," in which a lead agent broke reconnaissance and post-exploitation work into pieces and dispatched them to many subagents running in parallel. A persistent campaign memory carried target lists, harvested credentials and standing instructions across separate working sessions, and a collection fleet ran on a preset schedule with, in Anthropic's words, no human in the loop. The roughly 50 targeted organizations spanned education, retail, energy, technology, healthcare, finance and manufacturing across the Middle East, Europe and Southeast Asia, according to the report.
How this compares to the other Chinese-nexus case in the same report
| GTG-10007 (this case) | GTG-20006 (Midnight Blizzard) | |
|---|---|---|
| Attribution | Chinese-speaking, incl. undergraduates | Russian state-sponsored, per Anthropic |
| Targets | ~50 orgs, seven sectors | 20+ orgs, mostly government |
| Notable finding | 12+ possible zero-days in a month | 300,000+ identity records stolen |
The Midnight Blizzard case, tracked separately in the same report, involved a different actor, different targets and a different technique, data theft rather than exploit research, though both used the same underlying models.
What Anthropic did, and did not say
Anthropic said it banned the accounts and organizations it identified, built automated detections based on the group's behavioral signatures, and shared what it found with government authorities and industry partners. The report does not name which network-appliance vendors were the subject of the group's research, whether any of the roughly 50 targeted organizations were successfully breached rather than merely targeted, or whether the zero-day candidates were ever disclosed to the affected vendors. Anthropic's report follows the same pattern the CISA advisory on Chinese AI distillation campaigns described earlier this month: attribution to Chinese-nexus actors, without a public accounting of which specific products were compromised.
Sources
More in Security
- 01Cisco and Acronis Share a CISA Deadline, Not a Severity ScoreOne flaw needs no password and no user interaction, the other needs an attacker already logged in, and CISA gave federal agencies the same three days to fix both.
- 02Bransys ELD App Shipped With Hardcoded Login CredentialsCISA disclosed three flaws Sept. 17 in the trucking compliance app, including a hardcoded password a researcher says exposed live location and engine data from every connected truck on a subset of fleets.
- 03MikroTik Patches RouterOS Flaws Attackers Exploited FirstPoland's national CERT says attackers began exploiting the chained flaws on Sept. 2, a day before MikroTik shipped a fix, and more than 122,500 routers were still reachable a week later.
- 04Attackers Exploit a JFrog Artifactory Bug in Four DayswatchTowr says attackers began minting administrator tokens by abusing a default empty join key, CVE-2026-82329, within days of JFrog's own patch shipping.