Your Claude Session Is a Credential, and Malware Figured That Out
Anthropic has started notifying users that infostealer malware on their own computers stole active Claude sessions, and that attackers used those sessions to burn through their paid usage. If you have watched your limits refill and then drain while you were not using Claude, this is the explanation. The implicated families are all commodity, off-the-shelf stuff: Vidar, LummaC2, StealC, RedLine and Acreed on Windows, Atomic Stealer on Mac.
The mechanism is worth understanding precisely, because it is not an exploit against Claude at all. Malware already running locally scrapes saved browser cookies and session identifiers. Those cookies represent an already-authenticated state — the login has happened, the second factor has been satisfied, the work is done. Replay one and you are inside the account without a password and without ever tripping MFA. Multi-factor authentication protects the act of logging in. It does not protect the artifact that logging in produces.
Anthropic’s response has been fairly aggressive: force-signing affected accounts out, stripping saved payment methods, and refunding charges it identifies as unauthorized. It has also been clear, correctly, that the malware is not related to Claude, not installed through Claude, and not the result of anything the user did in Claude. But the cleanup only goes so far. Revoking a stolen session kills that session; it does not remove the infostealer sitting on the machine that will simply harvest the next one. If you got the notice, the actual to-do list is disinfect the device, rotate credentials, revoke every other active session — in that order.
Salesforce in Claude Hits Open Beta This Month
Claudeforce — the expanded Salesforce and Anthropic partnership announced in late August — produces its first shipping product this month. Salesforce in Claude is with select pilot customers now and moves to open beta in September, arriving as a plugin carrying 37 prebuilt sales skills. Sellers can reason over live revenue context, push pipeline updates, and take governed action against the CRM without leaving the Claude window.
The framing from Salesforce is deliberately provocative — the pitch being that you will not need to open the CRM app itself. That is a striking thing for a company to say about its own flagship interface, and it points at where the value is actually moving. Salesforce is betting that the system of record matters more than the system of engagement, and that if the reasoning layer is going to live somewhere else, better to be the governed data source inside it than to lose the workflow entirely.
Note what is doing the heavy lifting here: business logic, permissions and governance travel with the data. An agent that can update a pipeline is only enterprise-viable if it inherits the same field-level rules a human rep would hit. Additional prebuilt skills start landing in late 2026, and both companies have signalled deeper integrations across Claude, Salesforce and Slack.
Claude Academy Is Free, and Bigger Than It Looks
Claude Academy is Anthropic’s official learning hub, and the scale is the story: roughly 355 tutorials, prompting guides and use-case walkthroughs organized into paths that cover Claude.ai, Cowork, Claude Code, Claude Tag and the Claude Platform. It is free, available in multiple languages, and — unusually — readable without signing in. Sign in and you get progress tracking plus completion badges you can drop on a LinkedIn profile.
The curriculum starts with fundamentals before branching into products, anchored by the four-hour AI Fluency: Framework & Foundations course built around Anthropic’s 4D framework: Delegation, Description, Discernment and Diligence. Several lessons include hands-on exercises rather than reading, which is the part that matters — prompting is a motor skill, not a body of knowledge.
Read it as go-to-market rather than altruism. The bottleneck on enterprise expansion right now is not model capability, it is the gap between a seat being purchased and a seat being used well. Rollout guides and org-wide training material are what turn a pilot into a renewal, and Anthropic has clearly decided that teaching the workforce is cheaper than losing the account.
Cache Reads Just Got 75% Cheaper, and That Is the Real Fable 5.1 Story
Claude Fable 5.1 landed on September 1, and the headline everyone ran was capability — demanding reasoning, long-running agents, multistep research, document-heavy professional work, a one-million-token context window and up to 128K output tokens. Fine. The number that will actually change what you build is in the pricing table: cache reads dropped 75%, to $0.25 per million tokens.
Anthropic puts the practical effect at roughly 25% lower cost for typical workloads versus Fable 5, rising to as much as 45% for complex coding and highly agentic tasks. That spread is the tell. Agentic workloads are cache-read-dominated by construction — you are replaying an enormous, mostly-static context on every single turn of a loop. Cut the price of the repeated read and you have not shaved a line item, you have changed which agent architectures are economically viable at all. Long-horizon loops that penciled out badly in July may want re-running.
Availability is everywhere it needs to be: claude-fable-5-1 on the Claude API, Amazon Web Services, Google Cloud and Microsoft Azure. If you are still routing agent traffic on Fable 5, the migration is close to free and the savings are not marginal.
The MCP Roadmap After the Stateless Rewrite
The 2026-07-28 Model Context Protocol specification was the largest structural change the protocol has had, and its consequences are still working through the ecosystem. The core moved to a stateless design, joined by multi round-trip requests, header-based routing, cacheable list results, authorization hardening and a formal extensions framework. Tier 1 SDKs shipped alongside it.
Statelessness is the load-bearing decision. A stateful protocol quietly assumes a server holds session context in memory, which is fine on a laptop and miserable behind a load balancer. Making the core stateless is what lets MCP servers be deployed like ordinary web services — horizontally scaled, restarted freely, put behind a CDN. Cacheable list results and header-based routing are the same instinct applied further down the stack.
An updated roadmap published in late August covers the next specification release and beyond. If you maintain a server, the extensions framework is the piece to read first: it is the sanctioned path for shipping capability without forking the spec, and the difference between an extension and a fork is whether your users can still switch clients.
Cowork Gets Its Own Browser, and Stops Forgetting You
Two changes to Claude Cowork that are small on paper and large in daily use. First, Cowork now has a built-in Chromium browser on Mac, Windows and Linux desktop, so Claude can read and navigate the web in the same pane where the work is already happening, rolling out to Pro, Max and Team plans. Second, and more consequential: Cowork memory and chat memory are now the same memory.
That second one removes a genuinely annoying seam. Explaining your project, your stack and your preferences in chat and then re-explaining all of it in Cowork was the kind of friction that quietly caps how much anyone delegates. Context now carries across surfaces when running in the cloud, which is the difference between an assistant you brief and an assistant that already knows.
Related: Claude in Chrome is now a full Cowork client, with sessions, skills and connectors carrying over to desktop, web and mobile. The pattern across all three is one continuous session that follows you between surfaces rather than four separate products that happen to share a model.
An October Listing Moves Into View
The IPO chatter got substantially more concrete this week. Anthropic has raised roughly $130 billion to date, filed a confidential draft S-1 on June 1, and is being reported as weighing an October listing. Run-rate revenue reportedly passed $65 billion by the end of July, against roughly $47 billion in May and about $9 billion at the close of 2025 — a growth curve that is difficult to find a precedent for at this absolute scale.
Valuation talk has become unmoored from the last primary round. The Series H priced at $965 billion post-money; secondary activity through mid-2026 has at times implied $1.05 to $1.2 trillion, and the more aggressive sell-side chatter now floats a $2 trillion listing. Treat the high end as sentiment rather than a number anyone has underwritten.
The infrastructure explains the appetite and the risk in equal measure. Google committed up to $40 billion in cash and compute, with Anthropic reportedly paying roughly $200 billion over five years for TPU capacity and cloud services; Amazon added $25 billion in the same stretch. Those obligations are contractual and enormous, and they are what a public market will actually be asked to price — not the model quality, but whether enterprise revenue arrives fast enough to cover a compute bill signed years in advance.
The Squeeze Comes From Below, and the Price Cut Is the Response
The New York Times ran a piece on September 4 with a thesis worth sitting with: Corporate America is getting hooked on open-source AI, and the fastest-growing threat to frontier margins is not a better model but a free one that is good enough. That threat lands on Anthropic and OpenAI identically, and it is structurally different from the competition either has faced before.
Here is why it bites. Enterprises are past the demo phase and into the boring part, and the boring part is where you discover that most production workloads are not frontier workloads. Classification, extraction, routing, summarization, first-pass drafting — enormous volume, unremarkable difficulty. An open-weight model on your own hardware handles that at effectively zero marginal cost, with no per-token meter and no data leaving the building. The frontier lab keeps the hard 10% and loses the 90% that was paying for the infrastructure.
Now re-read the pricing news in that light. Cutting cache reads 75% is not a routine efficiency pass-through. It is the single most effective lever against exactly this substitution, because it targets the workload where open-weight alternatives are weakest: long-context agentic loops, where the value is in sustained reasoning over a large stable context rather than in single-shot throughput. Anthropic is not competing on the commodity tier. It is making the tier it can defend dramatically cheaper to operate, so that the calculus for keeping agents on the frontier stops being close.
The same logic runs through the rest of today’s brief. Salesforce in Claude binds Claude to governed enterprise data that no open-weight model can reach without an integration nobody has built. Claude Academy attacks the adoption gap, because a seat used badly gets cancelled and replaced by a cheap model that looked equivalent in a bad test. Cowork’s unified memory and built-in browser accumulate context and habit — the kind of switching cost that has nothing to do with benchmark scores. None of these are model improvements. All of them are answers to the same question.
And then the infostealer story sits underneath all of it as an uncomfortable reminder. The more of your working life runs through one authenticated session, the more that session is worth to somebody else. Anthropic can force-sign-out a stolen cookie; it cannot clean the laptop. As the platform gets stickier — which is precisely the strategy — the session becomes the asset, and the security model has to move to match. Today it has not quite caught up.