Picture a piece of malware that notices your antivirus just flagged it, and rewrites itself before a human ever gets the alert. That’s not a hypothetical. It’s one of two cases Anthropic described in its September 2026 threat intelligence report, and both of them break an assumption most cybersecurity advice still quietly depends on: that there’s a person on the other end of the keyboard, someone who gets tired, makes mistakes, and mostly works business hours.
Malware that rewrites itself
In one case, a suspected state-sponsored actor targeting Ukrainian and European government and defense organizations used AI to automatically modify and redeploy its own malware the moment security products detected it. Normal cybersecurity runs on a detect-then-respond cycle: a tool flags something suspicious, a human investigates, a fix goes out. This operation collapsed that cycle by automating the attacker’s side of it. The malware adapted in near real time, faster than a human defender could react.
More than 20 organizations were targeted, with a heavy focus on drone technology supply chains. The same operation also compromised hotel WiFi networks and the WhatsApp accounts of senior officials, a reminder that these attacks rarely stay confined to “the network” in any tidy sense.
Agent swarms doing the research
A separate case, linked to university operators in China’s Hunan province, is arguably stranger: autonomous vulnerability research carried out by parallel “agent swarms.” Not one tool working alone, but coordinated groups of AI agents running reconnaissance, exploitation, malware development, and intelligence gathering against major security products at the same time, with barely any human supervision. The result was several previously unknown vulnerabilities found and weaponized faster than a human research team could manage on its own.
Why this isn’t just a government problem
It’s easy to file both of these under “someone else’s problem.” That would be a mistake. Nothing about self-modifying malware or agent swarms is restricted to government targets. Those techniques go wherever someone points them, and the infrastructure built to attack a ministry of defense works exactly the same way against a mid-sized company’s finance system.
The practical takeaway: static defenses, a firewall rule set once and forgotten, a policy reviewed annually, a “we’ll get to it eventually” attitude toward patching, are built for a human-paced threat. They weren’t built for something that iterates in minutes.
What holds up against this
Defending against agentic threats means moving from occasional checkups to continuous review. Vulnerability scanning on a real schedule instead of once a year. Patch cycles measured in days, not quarters. And an honest map of where your most valuable data actually sits and who, or what, can reach it.
That continuous, current picture is what our cybersecurity consulting is built to deliver, reviewed the way an adversary would review it, not the way a checklist would.
Talk to us before your defenses get tested by something that doesn’t sleep.
Source: Disrupting an AI-orchestrated cyber espionage campaign, Anthropic · Anthropic Threat Intelligence Report, September 2026
