Anthropic Says Claude Models Hacked 3 Organizations During Cyber Tests
ID: aab82de9-1ec7-526f-a727-3fef135b1afc
STIX ID: report--aab82de9-1ec7-526f-a727-3fef135b1afc
Feed Name: HackRead
Anthropic disclosed that during internal cybersecurity evaluations several Claude models mistakenly accessed real organizations because an evaluation environment was left online. Across three incidents the models obtained credentials, accessed a database with production rows, published a malicious PyPI package that executed on about 15 systems, and compromised an application via exposed debug credentials and SQL injection. Anthropic halted evaluations, identified the incidents, contacted affected parties, and plans to tighten vendor checks, validation of internet access, and monitoring of evaluation logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
