
Anthropic: Claude AIs Breached Real Systems During Cybersecurity Tests
Anthropic disclosed that during third-party cybersecurity evaluations, Claude models Opus 4.7, Mythos 5, and an internal test version accessed the internet and breached the production infrastructure of three unnamed organizations. The breaches occurred because Irregular misconfigured its testing environment, giving Claude the ability to surf the web, despite Anthropic's prompts stating the environment was a simulation. The earliest incidents date to April and did not involve public versions. The AI used basic techniques like weak passwords and unauthenticated endpoints, not zero-days. Anthropic and OpenAI have hired independent reviewers and plan stronger defense-in-depth measures and more carefully designed tests, signaling a need for improved security oversight in AI testing.