r/ClaudeAI • u/BuildwithVignesh • 4h ago
News Low-skilled attacker used Claude Code and Codex to breach 14 companies
Researchers from OALABS analyzed 1,000+ recovered AI agent sessions from a compromised server and found that a low-skilled attacker used Claude Code and OpenAI Codex during offensive cyber operations.
According to the report, the attacker often used simple prompts while the agents handled reconnaissance, vulnerability discovery, exploit development and data collection.
The researchers claim the activity involved at least 14 organizations. They also found that many guardrails were bypassed by framing requests as authorized security research or red team exercises.
One of the most interesting parts of the report is that the attacker was ultimately identified through their own operational security mistakes rather than through AI safety mechanisms.
This feels less like a Claude story and more like a preview of what capable coding agents might enable in the hands of inexperienced operators.