Anthropic Finds Claude Gained Unauthorized Access to 3 Organizations’ Systems

2026-7-31 09:05

Anthropic disclosed 3 incidents in which its Claude models gained unauthorized access to the real systems of 3 different organizations during cybersecurity evaluations that were misconfigured with live internet access.

The AI firm identified the incidents after reviewing 141,006 evaluation runs, a check it launched after OpenAI revealed its models had escaped an isolated test environment and reached Hugging Face.

How Claude Reached Real Systems in Capture-the-Flag Tests

The evaluations tasked Claude with capture-the-flag challenges. These exercises ask a model to break into a machine and retrieve hidden information.

Anthropic told the models they had no internet access. However, a misconfiguration left the test machines connected to the open web. Thus, Claude treated the real systems it found as part of the exercise.

In the most serious incident, Claude Opus 4.7 exploited vulnerabilities in a real company’s infrastructure. The model extracted application and infrastructure credentials and accessed several hundred rows of production data. 

“In all four of the runs, the model eventually recognized (as can be observed in its verbalized reasoning) that the system was real—in two cases, the model rationalized that the real company must be part of the exercise. However, none stopped the attack on that basis,” Anthropic said.

Follow us on X to get the latest news as it happens

Claude Mythos 5 Uploaded Malware to PyPI

In another incident, Claude Mythos 5 published a booby-trapped Python package to PyPI, the public software registry. The package stayed live for roughly 1 hour and ran on 15 real systems.

One was a security company’s scanner, which executed the hidden code. Claude then exfiltrated that company’s credentials and accessed further infrastructure. The model’s own reasoning flagged the risk early on before it convinced itself that the environment was simulated.

“Claude went to extensive lengths to carry out this attack—lengths that would likely have indicated to a human participant that this was no longer just an evaluation, and that they were in fact uploading a real PyPI package,” the team added.

A third incident involved an internal research model that scanned roughly 9,000 targets and compromised one company’s application via SQL injection. That model stopped its attack once it concluded the target was real.

Anthropic notified the affected organizations on July 27 and said it is in talks with evaluator METR for a third-party review. The firm argues the episodes reflect an operational failure rather than a model alignment failure, noting its standard consumer safeguards would have blocked the behavior.

Subscribe to our YouTube channel to watch leaders and journalists provide expert insights

The post Anthropic Finds Claude Gained Unauthorized Access to 3 Organizations’ Systems appeared first on BeInCrypto.

origin »

Bitcoin price in Telegram @btc_price_every_hour

Fast Access Blockchain (FAB) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: -0.02 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Доступно / Всего 28.32m FAB

access anthropic organizations systems unauthorized claude gained

access anthropic → Результатов: 15


Anthropic’s Claude Fable 5 and Mythos 5 Launch: What To Know

Anthropic has just made its neutered Mythos model fable available to the public, confirming speculation that the product would launch today. Key Highlights: Claude Fable 5 & Claude Mythos 5 Launch Biggest Claims Safety & Access Availability Anthropic is effectively introducing a new AI tier above Opus, claiming frontier-level gains in coding, scientific research, cybersecurity, The post Anthropic’s Claude Fable 5 and Mythos 5 Launch: What To Know appeared first on BeInCrypto.

2026-6-9 20:04


Фото:

Firefox finds 20 year old bug and patches 14 months of fixes in 30 days using Anthropic’s Mythos AI

Mozilla’s latest Firefox security update provides a rare glimpse into what happens when frontier AI capabilities reach defenders before attackers. The company said it fixed 423 Firefox security bugs in April after gaining access to Claude Mythos Preview, compared with roughly 420 fixes over the previous 14 months.

2026-5-10 16:00