Anthropic disclosed that Claude had unauthorized access to three companies' systems during testing.
TechCrunch
07-31 09:15
Ai Focus
Anthropic disclosed that Claude had unauthorized access to the real systems of three organizations during three security tests, and the problem was related to a misconfiguration of the test environment's network.
Helpful
No.Help

Anthropic disclosed that during an internal investigation, it discovered that the Claude model had accessed the real internet during three cybersecurity tests and further unauthorized access to the production systems of three organizations. These tests were supposed to be conducted in an isolated environment, but external connections were not actually completely severed.

The problem stems from misconfigured environment.

This investigation began with a similar incident disclosed by OpenAI on July 21. Anthropic stated that the company subsequently reviewed 141,006 evaluation records, focusing on whether Claude had obtained external network access during the testing process, and ultimately found that all three incidents were related to tests involving the third-party partner Irregular.

Anthropic stated that the access path originated from a misconfiguration of the evaluation environment. The company said this was related to a disagreement between the two parties regarding whether the test environment had internet access capabilities. By design, the model should not have access to a real network, but the connection was not actually severed. Irregular is also conducting a separate investigation.

The three models reacted differently.

Anthropic stated that the models involved were Opus 4.7, Mythos 5, and an internal research test model. Notably, these models were explicitly told in the prompts that "there is no internet access," yet they still misidentified a real-world system as part of the test task.

  • Opus 4.7 identified the target as a real system in all four runs.
  • Two of these attacks continued, resulting in the extraction of credentials and access to the production database.
  • Mythos 5 has released malware packages to PyPI.

Anthropic stated that while Mythos 5 realized it might have accessed the real internet, it subsequently reinterpreted the scenario as a simulation test, leading to the malware package being downloaded and executed by an external system. In contrast, the latest internal research test model automatically stopped operating after confirming the target was a real system.

Anthropic will tighten testing controls

Anthropic stated that more stringent controls are needed when such high-capability models are used in security assessments. The company also pointed out that the tests in question did not enable additional security monitoring and classifiers for publicly deployed models, as these assessments were originally intended to measure the models' raw capabilities.

The company stated that there is no evidence that the models were pursuing their own goals; they were simply continuously performing assigned tasks. Anthropic also stated that these incidents were discovered through proactive review by the company, and the affected institutions were previously unaware of them. The company is currently collaborating with the independent assessment firm METR to conduct a third-party review of the incidents.

Additional information:Anthropic distinguished this case from a recent OpenAI case, stating that OpenAI's model exploited an unknown software vulnerability to escape the test environment, while Claude's problem was accessing the internet through a mistakenly opened network path.

Tip
$0
Like
0
Save
0
Views 294
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Eurozone industrial production fell 0.1% month-on-month in July: Total volume nearly stagnant, while durable goods show a clear weakening
Eurostat released its first estimate on September 16: In July 2026, quarter-on-quarter industrial production in the eurozone declined by 0.1%, and in the EU by 0.3%. Both regions saw a decrease of 0.1% in June. Compared to a year ago, industrial production in the eurozone remained unchanged, while in the EU it grew by 0.3%. The overall change is minimal, appearing almost like a flat line, but there are clear differences among industries: production of energy, capital goods, and intermediate goods increased quarter-on-quarter, whereas the production of durable consumer goods saw a significant decline. European industry has not experienced a widespread downturn, nor has there been a strong expansion.
币百科
·2026-09-17 10:18:40
39
UK inflation rose to 3.1% in August: Oil prices drive up overall inflation, while core indicators have not accelerated accordingly for now
The Office for National Statistics of the UK announced on September 16 that in August 2026, the Consumer Price Index CPI rose by 3.1% year-on-year, higher than 2.9% in July; the index including the cost of own housing CPIH rose by 3.3% year-on-year, also higher than the previous month's 3.1%. Both indices increased by 0.5% month-on-month, compared to a month-on-month increase of 0.3% in August 2025. The main factor driving annual inflation upwards was transportation, particularly car fuel costs. At the same time, the core CPI remained at 2.6% year-on-year, and the core CPIH also stayed at 2.9%; there was no acceleration in the rise in service prices either. The overall index has rebounded significantly, but the pressure is mainly concentrated on goods and energy.
币百科
·2026-09-17 10:17:28
36
Google Survey: Scientists Save Nearly 7 Hours per Week Due to AI; After Efficiency Increases, Experiments Become a New Bottleneck
On September 15th, Google updated AI and Economy ATLAS, and announced a study in collaboration with Google DeepMind and MIT FutureTech. The study analyzed 2,600 professional AI models and surveyed over 600 scientists from the United States and the United Kingdom. The results showed that nearly half of the surveyed scientists used some form of AI daily, and they reported saving nearly 7 hours per week as a result. However, the study also found that with the rapid generation of more hypotheses, there was a backlog in physical experiments, clinical validation, and result verification. This conclusion is more comprehensive than the claim that "AI speeds up scientific research": while models can streamline some mental processes, they cannot automate...
CoinMeta
·2026-09-17 10:16:17
34
OpenAI Testing "Sponsored Agents": Ads No Longer Just Wait for Clicks, but Require Answers in Conversations
On September 16th, OpenAI announced a new round of product updates for ChatGPT Ads, among which Sponsored Agents has drawn the most attention. After seeing the ads, users can proactively enter an agent dialogue sponsored by merchants and clearly labeled with relevant information. There, they can continue to ask questions about size, features, applicable scenarios, etc., before deciding whether to visit the merchants' websites. OpenAI also introduced an ad management plugin, suggestions for copywriting and images, as well as text adaptation features. Additionally, HubSpot and Shopify were integrated into the system. It is important to note that the sponsored agent feature is currently only being tested with some advertisers in the United States and has not yet been fully rolled out to users worldwide or all merchants.
CoinMeta
·2026-09-17 10:14:59
37
U.S. officials say large oil companies may invest in Venezuela
U.S. officials say large oil companies may invest in Venezuela; Brent crude oil prices rose to $108.75, with markets focusing on global supply prospects.
Coinpaper
·2026-09-16 22:28:27
45
View More