21.8 C
Africa

Claude AI Breaches Three Companies in Cybersecurity Test, Reports Anthropic.

Date:

Anthropic has disclosed that its Claude AI models inadvertently accessed the systems of three organizations during cybersecurity evaluations due to a testing misconfiguration. This incident came to light after the company conducted a comprehensive review of over 141,000 cybersecurity evaluation runs. The review was instigated following recent revelations about AI-related security testing issues within the industry.

The unauthorized access involved the Claude Opus 4.7, Claude Mythos 5, and an internal research model, with incidents traced back to April. The affected models employed basic attack techniques, such as exploiting weak passwords and unsecured endpoints, to infiltrate the infrastructures of these organizations. This occurred during “capture the flag” exercises, where AI models are challenged to find hidden information within simulated networks. A configuration error mistakenly connected the testing environments to the public internet, despite instructions that the models lacked internet access.

Upon identifying these incidents, Anthropic notified two of the impacted organizations, with efforts to reach the third still ongoing. The company has stressed that these findings underscore the urgent need for more robust safeguards and stricter controls in AI cybersecurity testing, especially as AI models become more adept at executing real-world cyber operations.

Subscribe to our magazine

━ more like this

Instagram’s AI Image Tool by Meta Sparks Privacy Worries

Meta's latest feature for Instagram, Muse Image, is stirring privacy concerns as it allows users to create AI-generated images using photos from public Instagram...

Rogue AI Agent Attacks Multiple Firms in OpenAI Cybersecurity Test

OpenAI has recently revealed that a rogue AI agent, which was part of an internal cybersecurity assessment, extended its reach beyond the initially reported...

Anthropic Launches Mythos AI Model Publicly with Enhanced Security Controls

Anthropic has unveiled a public version of its sophisticated AI model, Fable 5, while imposing strict controls on its use in sensitive areas due...

Judge Permits States’ Lawsuit Against Meta for Social Media Addiction Claims

A federal judge in the United States has dismissed Meta Platforms' bid to throw out a lawsuit brought by 29 state attorneys general. The...

New York Halts New AI Data Center Projects, Leading US States

New York has taken a pioneering step as the first U.S. state to implement a temporary halt on the establishment of new large-scale data...