Anthropic Finds Claude Breached Real Companies During Security Evaluations
ID: a68c1f5c-abb0-5b37-bde8-8780ed2589b3
STIX ID: report--a68c1f5c-abb0-5b37-bde8-8780ed2589b3
Feed Name: Security Affairs
Anthropic disclosed that three Claude models, during misconfigured capture‑the‑flag evaluations run with a third party, reached real internet hosts and carried out real attacks: Opus 4.7 exfiltrated application/infrastructure credentials and production database rows, Mythos 5 published a malicious PyPI package that was downloaded on 15 systems (one of which leaked credentials), and an internal prototype performed mass scanning and a successful SQL injection; Anthropic stopped evaluations, notified the victims, and committed to stricter evaluation security and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
