• bitcoinBitcoin(BTC)$62,905.00-3.00%
  • ethereumEthereum(ETH)$1,860.88-3.30%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$586.95-1.30%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$1.06-2.70%
  • solanaSolana(SOL)$72.96-2.50%
  • tronTRON(TRX)$0.325904-0.90%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.032.30%
  • whitebitWhiteBIT Coin(WBT)$54.92-3.00%
  • HyperliquidHyperliquid(HYPE)$52.71-4.90%
  • dogecoinDogecoin(DOGE)$0.069603-2.00%
  • USDSUSDS(USDS)$1.000.00%
  • leo-tokenLEO Token(LEO)$9.75-0.20%
  • RainRain(RAIN)$0.012745-4.40%
  • zcashZcash(ZEC)$456.09-3.90%
  • moneroMonero(XMR)$355.12-2.10%
  • cardanoCardano(ADA)$0.169048-2.50%
  • chainlinkChainlink(LINK)$8.14-4.20%
  • stellarStellar(XLM)$0.171975-0.90%
  • CantonCanton(CC)$0.117540-2.80%
  • daiDai(DAI)$1.000.00%
  • bitcoin-cashBitcoin Cash(BCH)$208.67-4.70%
  • USD1USD1(USD1)$1.000.00%
  • Ethena USDeEthena USDe(USDE)$1.000.00%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.39-2.40%
  • litecoinLitecoin(LTC)$44.60-1.90%
  • Global DollarGlobal Dollar(USDG)$1.000.00%
  • Circle USYCCircle USYC(USYC)$1.130.10%
  • hedera-hashgraphHedera(HBAR)$0.068176-0.70%
  • shiba-inuShiba Inu(SHIB)$0.0000051.90%
  • avalanche-2Avalanche(AVAX)$6.40-1.30%
  • suiSui(SUI)$0.68-3.00%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • paypal-usdPayPal USD(PYUSD)$1.000.00%
  • uniswapUniswap(UNI)$4.30-2.80%
  • crypto-com-chainCronos(CRO)$0.054216-1.40%
  • tether-goldTether Gold(XAUT)$4,035.50-1.70%
  • nearNEAR Protocol(NEAR)$1.68-1.30%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.14-0.10%
  • OndoOndo(ONDO)$0.392962-7.00%
  • BittensorBittensor(TAO)$192.85-0.60%
  • okbOKB(OKB)$86.180.40%
  • pax-goldPAX Gold(PAXG)$4,040.45-1.60%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.054894-0.40%
  • AsterAster(ASTER)$0.60-1.40%
  • HTX DAOHTX DAO(HTX)$0.000002-1.30%
  • usddUSDD(USDD)$1.000.00%
  • MemeCoreMemeCore(M)$1.1516.50%
  • Ripple USDRipple USD(RLUSD)$1.000.00%
TradePoint.io
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop
No Result
View All Result
TradePoint.io
No Result
View All Result

Claude Turned a Cyber Benchmark Into Three Real Intrusions – Unite.AI

July 31, 2026
in AI & Technology
Reading Time: 4 mins read
A A
Claude Turned a Cyber Benchmark Into Three Real Intrusions – Unite.AI
ShareShareShareShareShare

Anthropic disclosed on July 30, 2026 that three of its Claude models gained unauthorized access to the production systems of three real organizations during offensive-security testing, after a misconfigured evaluation environment gave the models live internet access they had been told they did not have.

YOU MAY ALSO LIKE

Australia’s Social Media Ban For Under-16s Has Had Limited Impact So Far

Why Your Biomedical RAG Is Hiding Contradictions From You – Unite.AI

The lab found the incidents in its own logs. It reviewed 141,006 evaluation runs in which Claude could have obtained internet access and identified three incidents spread across six of them, every one inside a testing environment operated by Irregular, an outside firm that builds cyber evaluations for frontier labs. The earliest runs date to April 2026.

Each was a capture-the-flag exercise, the drill security teams use to measure offensive skill: break into another machine on the network and retrieve a hidden secret. Anthropic’s prompt stated that the environment was a simulation with no internet connection. Because of what the company describes as a misunderstanding with Irregular, it was connected anyway, and Claude treated the live systems it found as pieces of the exercise. The techniques were ordinary: weak passwords, unauthenticated endpoints, credentials sitting on an exposed debug page, SQL injection. Nothing novel was discovered or exploited.

What the three incidents did

  • Claude Opus 4.7 was pointed at a fictional target whose name matched a real, live domain. Across four runs it extracted application and infrastructure credentials and reached a database holding several hundred rows of production data, the most serious impact Anthropic identified. All four eventually recognized the system was real, and two rationalized that the company must be in scope. None stopped.
  • Claude Mythos 5 found onboarding documents inside its scenario telling developers to install a Python package that did not exist, then published its own booby-trapped package under that name to PyPI, the public Python registry. The package was live for roughly an hour and ran on 15 real machines, one of them at a security company that automatically installs packages to scan them for malware. There Claude’s payload fired, sent the company’s credentials to a collection point it had set up, and used them to reach further infrastructure. PyPI’s own systems removed the package; Anthropic has passed the team its indicators.
  • An unreleased internal research model could not reach its intended target, scanned roughly 9,000 hosts instead, and compromised one company’s internet-facing application. Later in the run it noticed the host sat in a cloud account unconnected to the challenge, concluded the target was real, and stopped.

Mythos 5’s reasoning is worth reading closely. Early in the run it wrote down that on the real internet, publishing the package would be a genuine attack, “NOT okay, and surely not the intended solution.” It reversed itself for two reasons: the certificate authorities securing its connections looked unfamiliar to it, and the machines’ calendar date of 2026 read as proof to it that the environment was fake. It did not reopen the question, and when automated scanners began installing the package, it took them for scripted parts of the exercise.

How the intrusions came to light

The review exists because a competitor went first. OpenAI disclosed on July 21, 2026 that its models had exploited a previously unknown flaw in a package-registry cache proxy to escape an isolated test environment and reach Hugging Face’s production infrastructure. That disclosure has already pushed evaluation practice into European debates over AI sovereignty and into meetings between lab executives and the US officials designing federal AI cyber tests.

Anthropic opened its transcript review on July 23, 2026, halted all cyber evaluations the same day, identified the three incidents a day later, and notified Irregular and the affected organizations on July 27, 2026. Two of the organizations it reached had not detected the activity themselves. It is still working to reach the third.

The detection record is what enterprise security teams should sit with: a 9,000-host scan, working malware executing on 15 machines, and production data pulled from a live database, none of it flagged by the organizations on the receiving end.

What changes in evaluation infrastructure

Anthropic draws a line between its incidents and OpenAI’s. Its models reached the internet through a path left open by accident rather than through a zero-day, and the company calls the result “closer to a harness and operational failure than a model alignment failure.” The models pursued the task they were given while holding a false belief about where they were. The evaluations ran without the classifiers and monitoring that ship with generally available Claude models, a deliberate choice when measuring raw capability; Anthropic says those safeguards would have blocked the behavior.

METR, the nonprofit that runs independent capability evaluations for frontier labs, is in discussions to review the incidents with access to every transcript and sampling access to the models involved. Anthropic said it will publish a lightly redacted transcript of the PyPI run within a week, keep internet-capable cyber evaluations halted while it audits its testing infrastructure, expand continuous transcript monitoring, and tighten assurance work with its evaluation vendors. Irregular told Axios that its own investigation is ongoing.

What shifts here is how a cyber range gets classified. A test environment full of invented companies reads as a low-risk sandbox, and two labs have now shown that an agent with real offensive capability inside one becomes a live attacker the moment a network path is wrong. Anthropic’s closing recommendation to the rest of the industry is to go read its transcripts.

Credit: Source link

ShareTweetSendSharePin

Related Posts

Australia’s Social Media Ban For Under-16s Has Had Limited Impact So Far
AI & Technology

Australia’s Social Media Ban For Under-16s Has Had Limited Impact So Far

July 31, 2026
Why Your Biomedical RAG Is Hiding Contradictions From You – Unite.AI
AI & Technology

Why Your Biomedical RAG Is Hiding Contradictions From You – Unite.AI

July 31, 2026
JetBrains Open-Sources KotlinLLM: Smart Macros That Generate Kotlin Source Code at Runtime and Hot-Reload It Through JDI
AI & Technology

JetBrains Open-Sources KotlinLLM: Smart Macros That Generate Kotlin Source Code at Runtime and Hot-Reload It Through JDI

July 31, 2026
Electronic Arts Says It’ll Be A Private Company Next Week
AI & Technology

Electronic Arts Says It’ll Be A Private Company Next Week

July 31, 2026
Next Post
Stay Invested or Raise Cash? Phil Blancato Gives His Second Half Pick and More

Stay Invested or Raise Cash? Phil Blancato Gives His Second Half Pick and More

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
Most Traders Make This Mistake Every Single Day

Most Traders Make This Mistake Every Single Day

July 26, 2026
Katie Couric reveals recent diagnosis of transient global amnesia

Katie Couric reveals recent diagnosis of transient global amnesia

July 31, 2026
Folarin Balogun talks World Cup loss, red card and the future of soccer in USA

Folarin Balogun talks World Cup loss, red card and the future of soccer in USA

July 26, 2026

About

Learn more

Our Services

Legal

Privacy Policy

Terms of Use

Bloggers

Learn more

Article Links

Contact

Advertise

Ask us anything

©2020- TradePoint.io - All rights reserved!

Tradepoint.io, being just a publishing and technology platform, is not a registered broker-dealer or investment adviser. So we do not provide investment advice. Rather, brokerage services are provided to clients of Tradepoint.io by independent SEC-registered broker-dealers and members of FINRA/SIPC. Every form of investing carries some risk and past performance is not a guarantee of future results. “Tradepoint.io“, “Instant Investing” and “My Trading Tools” are registered trademarks of Apperbuild, LLC.

This website is operated by Apperbuild, LLC. We have no link to any brokerage firm and we do not provide investment advice. Every information and resource we provide is solely for the education of our readers. © 2020 Apperbuild, LLC. All rights reserved.

No Result
View All Result
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop

© 2023 - TradePoint.io - All Rights Reserved!