Anomali Cyber Watch reports that MITRE ATT&CK has two separate technique numbers for a threat actor scanning stolen session data to reuse Claude logins without passwords or MFA prompts.
Public source
Publisher name
Public post
Six commodity malware families. One attacker. Zero passwords needed. It's been confirmed that a threat actor was scanning stolen session data specifically to find and re…
Company
Anomali
The Leading AI-Powered Security and IT Operations Platform. Be Different. Be the Anomali.
- Industry
- Computer and Network Security
- Location
- Redwood City, US
- Company size
- 201–500 employees
About Anomali
Anomali delivers the intelligence-native Agentic SOC Platform, unifying a hyperscale security data lake, threat intelligence, and AI-driven automation to power modern security operations. At the foundation is the Anomali Unified Security Data Lake, a cloud-native platform designed to ingest, retain, and analyze massive volumes of security telemetry without the performance limitations or cost constraints of legacy SIEM, SOAR, and XDR platforms. Built on this foundation, Anomali ThreatStream Next-Gen provides continuous threat intelligence and contextual enrichment, transforming raw security data into prioritized insights that help analysts detect and understand threats faster. Anomali Agentic AI operates across the platform to automate triage, guide investigations, and drive governed, auditable response at scale. Trusted by global enterprises and government organizations, Anomali enables security teams to reduce complexity, accelerate detection and response, and operate more effective security operations centers.
See moreLatest activity
Latest activity from Anomali
19 signals
Presence & Recognition
Anomali employee Satyajit Roy is attending the Gartner Security & Risk Management Summit 2026 in London, U.K.
Research & Knowledge
Anomali published the details of a new campaign letting attackers ride along on an already logged-in browser session without a password after the fact
Presence & Recognition
Anomali employee Satyajit Roy is attending the Gartner Security & Risk Management Summit 2026 in London, U.K.
Discover more
Similar signals
Similar public activity from other companies.
Research & Knowledge
Palo Alto Networks
Palo Alto Networks Unit 42 published an investigation revealing how a threat actor used frontier AI models to compress two weeks of complex intrusion tradecraft into less than 10 hours.
Research & Knowledge
Recorded Future
Recorded Future published its H1 2026 research showing that attackers are mostly using AI to accelerate methods that already work, and vulnerability timelines are tightening at the same time.
Research & Knowledge
Palo Alto Networks Unit 42
Palo Alto Networks Unit 42 investigated a breach where a threat actor deployed autonomous AI agents to execute an intrusion in under 10 hours.
Research & Knowledge
Wiz
Wiz analyzed 90 days of attack telemetry across AI frameworks, proxies, and agent deployments to find attackers building AI-native playbooks.
Research & Knowledge
Darktrace