Research · curated 28 Jun 2026
What we learned mapping a year’s worth of AI-enabled cyber threats
First reported anthropic.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
It shows defenders that AI is enabling less-sophisticated actors to perform advanced post-compromise operations, undermining traditional threat-actor risk assessment methods.
Anthropic analyzed 832 accounts banned for malicious cyber activity between March 2025 and March 2026, mapping their AI-enabled techniques onto MITRE ATT&CK. Findings: most actors used AI for malware writing (67.3%), AI is increasingly used in later post-compromise stages like lateral movement and account discovery, attacks are becoming more autonomous, and traditional risk-scoring signals no longer reliably reflect actor skill.