Home » Anthropic’s Claude AI Engages Three Firms in Cybersecurity Trial, Impacting Business

Anthropic’s Claude AI Engages Three Firms in Cybersecurity Trial, Impacting Business

by admin477351

In a recent cybersecurity evaluation, Anthropic’s Claude AI models inadvertently accessed the systems of three organizations due to a testing misconfiguration that mistakenly enabled internet access. The company discovered these incidents while reviewing over 141,000 cybersecurity evaluation runs, initiated in the wake of recent industry-wide disclosures concerning AI-related security testing.

The unauthorized access incidents involved Claude Opus 4.7, Claude Mythos 5, and an internal research model. These models employed basic intrusion techniques such as exploiting weak passwords and unsecured endpoints to penetrate the organizations’ infrastructure. The earliest of these events dates back to April, all occurring during “capture the flag” exercises. These exercises tasked AI models with finding concealed information within simulated network environments. Despite being instructed that they lacked internet connectivity, a configuration mistake left the testing setups linked to the public internet.

Anthropic has notified two of the impacted organizations about the incidents, while they are still trying to reach the third one. The company stressed that these findings underline the critical need for enhanced safeguards and more stringent controls in AI cybersecurity evaluations. As AI models grow more sophisticated, their potential to execute real-world cyber actions becomes increasingly significant.

You may also like