{"id":17333,"date":"2026-08-02T07:45:03","date_gmt":"2026-08-02T07:45:03","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=17333"},"modified":"2026-08-02T07:45:03","modified_gmt":"2026-08-02T07:45:03","slug":"anthropic-says-claude-fashions-hacked-3-organizations-throughout-cyber-exams","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=17333","title":{"rendered":"Anthropic Says Claude Fashions Hacked 3 Organizations Throughout Cyber Exams"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<style><![CDATA[\n#ar-widget{margin:0 0 2rem;font-family:-apple-system,BlinkMacSystemFont,\"Segoe UI\",sans-serif;}\n#ar-widget .ar-box{background:#fff;border:1px solid #e5e7eb;border-radius:12px;padding:1.1rem 1.4rem;}\n#ar-widget .ar-top{display:flex;align-items:center;gap:10px;margin-bottom:.85rem;}\n#ar-widget .ar-icon-wrap{width:38px;height:38px;border-radius:50%;background:#EEEDFE;display:flex;align-items:center;justify-content:center;flex-shrink:0;}\n#ar-widget .ar-meta{flex:1;min-width:0;}\n#ar-widget .ar-label{font-size:10px;color:#9ca3af;text-transform:uppercase;letter-spacing:.06em;margin:0 0 2px;}\n#ar-widget .ar-title-text{font-size:13px;font-weight:600;margin:0;color:#111827;white-space:nowrap;overflow:hidden;text-overflow:ellipsis;}\n#ar-widget .ar-progress-section{margin-bottom:.7rem;}\n#ar-widget #ar-seek{width:100%;height:4px;accent-color:#534AB7;cursor:pointer;display:block;margin:0;-webkit-appearance:none;appearance:none;background:#e5e7eb;border-radius:2px;outline:none;border:none;}\n#ar-widget #ar-seek::-webkit-slider-thumb{-webkit-appearance:none;width:14px;height:14px;border-radius:50%;background:#534AB7;cursor:pointer;}\n#ar-widget .ar-times{display:flex;justify-content:space-between;font-size:10px;color:#9ca3af;margin-top:3px;}\n#ar-widget .ar-controls{display:flex;align-items:center;gap:7px;flex-wrap:wrap;}\n#ar-widget .ar-controls button{border:1px solid #d1d5db;border-radius:8px;padding:5px 11px;background:#fff;cursor:pointer;font-size:12px;color:#374151;}\n#ar-widget .ar-controls button:hover{background:#f9fafb;}\n#ar-widget .ar-play-btn{border-color:#534AB7!important;color:#534AB7!important;font-weight:600;min-width:86px;text-align:center;}\n#ar-widget .ar-play-btn:hover{background:#EEEDFE!important;}\n#ar-widget .ar-speed-wrap{margin-left:auto;display:flex;align-items:center;gap:5px;}\n#ar-widget .ar-speed-wrap label{font-size:11px;color:#6b7280;}\n#ar-widget #ar-rate{border:1px solid #d1d5db;border-radius:6px;padding:3px 5px;font-size:11px;background:#fff;color:#374151;cursor:pointer;}\n#ar-widget #ar-status{font-size:11px;color:#9ca3af;margin:.65rem 0 0;padding-top:.65rem;border-top:1px solid #f3f4f6;}\n#ar-widget .ar-voice-row{display:flex;align-items:center;gap:6px;margin-top:8px;}\n#ar-widget .ar-voice-row label{font-size:11px;color:#6b7280;flex-shrink:0;}\n#ar-widget #ar-voice{flex:1;min-width:0;border:1px solid #d1d5db;border-radius:6px;padding:4px 6px;font-size:11px;background:#fff;color:#374151;cursor:pointer;}\n]]><\/style>\n<p class=\"wp-block-paragraph\">A cybersecurity check designed to measure<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/hacker-claude-code-gpt-4-1-mexican-records\/\"> Claude\u2019s hacking talents<\/a> ended with Anthropic fashions gaining unauthorized entry to a few actual organizations after an analysis surroundings was mistakenly left linked to the web. Claude had been advised it was inside a simulation with no exterior entry, so it handled the techniques it discovered on-line as a part of the train. Anthropic disclosed the incidents on July 30.<\/p>\n<p class=\"wp-block-paragraph\">The corporate started reviewing its cybersecurity analysis transcripts after OpenAI disclosed that its personal fashions had bypassed community restrictions and entered Hugging Face\u2019s manufacturing techniques throughout a cyber analysis. As <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/openai-models-breached-hugging-face\/\">Hackread.com beforehand reported<\/a>, the OpenAI fashions exploited an unknown vulnerability whereas trying to find check solutions. Anthropic reviewed 141,006 Claude analysis runs and located six runs linked to a few incidents.<\/p>\n<p class=\"wp-block-paragraph\">Throughout every train, Claude was requested to search out secret info often called a flag inside a fictional community. Anthropic\u2019s immediate stated the surroundings was simulated and had no web connection, however a misunderstanding with analysis associate Irregular left stay entry accessible. The fashions subsequently regarded actual techniques as check targets.<\/p>\n<h3 id=\"claude-opus-4-7\" class=\"wp-block-heading\"><strong>Claude Opus 4.7<\/strong><\/h3>\n<p class=\"wp-block-paragraph\">One fictional firm occurred to share its identify with an actual web site, main Claude Opus 4.7 to assault the actual group throughout 4 runs. The mannequin obtained software and infrastructure credentials, together with entry to a database containing a number of hundred rows of manufacturing information. It continued after discovering proof that the goal was actual, reasoning that it&#8217;d nonetheless belong to the train.<\/p>\n<h3 id=\"claude-mythos-5\" class=\"wp-block-heading\"><strong><strong>Claude Mythos 5<\/strong><\/strong><\/h3>\n<p class=\"wp-block-paragraph\">A separate train led Claude Mythos 5 to publish a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/vmconnect-malicious-pypi-package-mimic-python-tools\/\" data-type=\"post\" data-id=\"91732\">malicious package deal on PyPI<\/a> after discovering setup directions that referred to a nonexistent package deal. The malicious package deal remained accessible for about an hour and ran on 15 actual techniques. One belonged to a cybersecurity firm whose scanner put in the package deal, permitting Claude to acquire credentials and entry extra of its infrastructure earlier than PyPI eliminated the file.<\/p>\n<h3 id=\"internal-research-model\" class=\"wp-block-heading\"><strong>Inside Analysis Mannequin<\/strong><\/h3>\n<p class=\"wp-block-paragraph\">Elsewhere, an inside analysis mannequin scanned about 9,000 on-line targets after failing to achieve its fictional one. It compromised an organization\u2019s software utilizing credentials uncovered on a debug web page and SQL injection. As soon as the mannequin acknowledged that the system had no connection to the train, it stopped.<\/p>\n<p class=\"wp-block-paragraph\">Not one of the fashions wanted superior or <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/google-workspace-vulnerabilities-network-breaches\/\" data-type=\"post\" data-id=\"107275\">beforehand unknown vulnerabilities<\/a> within the three Anthropic incidents. They used weak passwords, uncovered endpoints, and different acquainted strategies. Anthropic described the incidents as primarily an operational and analysis failure, not proof that Claude had fashioned an impartial aim. <\/p>\n<p class=\"wp-block-paragraph\">The check fashions ran with out the classifiers and monitoring utilized to publicly accessible Claude companies. The devoted analysis infrastructure had no entry to Anthropic\u2019s inside techniques or buyer information.<\/p>\n<p class=\"wp-block-paragraph\">Anthropic\u2019s <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.anthropic.com\/news\/investigating-incidents-cybersecurity-evals\" target=\"_blank\" rel=\"noopener\">safety advisory<\/a> confirms that it halted its cyber evaluations on July 23, recognized all three incidents the next day, and tried to contact the affected organizations on July 27. Two had not detected the exercise earlier than Anthropic reached them and are actually working with the corporate on remediation. Anthropic was nonetheless attempting to achieve the third group when it printed its account and didn&#8217;t disclose any names.<\/p>\n<p class=\"wp-block-paragraph\">Studying the disclosures from each labs, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.linkedin.com\/in\/dianakelleysecuritycurve\" target=\"_blank\" rel=\"noopener\">Diana Kelley<\/a>, chief info safety officer at Noma Safety, a New York Metropolis-based AI safety and governance platform, stated entry restrictions can&#8217;t depend upon an AI agent appropriately understanding its environment. <\/p>\n<p class=\"wp-block-paragraph\">\u201cDon\u2019t depend on intent, depend on controls,\u201d Kelley advised Hackread.com. She beneficial isolation, least privilege, identity-based authorization, runtime controls, coverage enforcement and kill switches for brokers performing prolonged autonomous duties.<\/p>\n<p class=\"wp-block-paragraph\">Anthropic plans to validate web entry paths earlier than assessments, enhance monitoring of analysis logs and transcripts, and apply stricter checks to exterior distributors. It additionally requested different AI laboratories to evaluation previous evaluations for related incidents.<\/p>\n<p>\n\t\t\t<\/div>\n<p><template id="GzQ28iSlHXOYszKGzfdG"></template><\/script><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A cybersecurity check designed to measure Claude\u2019s hacking talents ended with Anthropic fashions gaining unauthorized entry to a few actual organizations after an analysis surroundings was mistakenly left linked to the web. Claude had been advised it was inside a simulation with no exterior entry, so it handled the techniques it discovered on-line as a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":17335,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[2333,458,959,173,266,1846,841],"class_list":["post-17333","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-anthropic","tag-claude","tag-cyber","tag-hacked","tag-models","tag-organizations","tag-tests"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17333","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=17333"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17333\/revisions"}],"predecessor-version":[{"id":17334,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17333\/revisions\/17334"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/17335"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=17333"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=17333"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=17333"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-08-03 21:43:27 UTC -->