From assistant to operator

Anthropic described a campaign detected in September 2025 in which attackers used Claude Code and connected tools to automate substantial portions of cyber operations. Human operators remained involved, but the model was used to execute reconnaissance, exploitation, credential collection, and data handling at a degree of autonomy the company considered unprecedented.

The important shift is orchestration. A model that can act, inspect results, and continue turns ordinary weaknesses into a search problem that can be run concurrently across many targets.

Defending the decision loop

Rate limits alone constrain volume but do not make the returned evidence less useful. Vallum combines quotas with proof-bound admission, session-specific response layouts, optional scrambling and carriers, normalized origin responses, and coherent local containment that avoids contacting the origin.

None of those mechanisms makes an authenticated browser opaque to an agent that controls it. The defensible objective is narrower: deny unauthorized raw automation a stable, truthful response-guided loop while preserving the authorized application path.

Scope note

Vallum is a response-resistance and origin-admission layer for bounded HTTP(S) exchanges. It is not a WAF, endpoint agent, sandbox, identity provider, or secure enclave.

← Back to all threat intelligence