Summary
Hackers hid dangerous SectopRAT malware on a page within Anthropic's Claude.ai domain, spoofing a Claude Desktop download. Victims were redirected via Bing ads, leading to at least 29 organizations being infected between July 21–22, 2026, before Claude removed the malicious artifact.