Bug allowed Claude models to breach three organizations, says Anthropic
Anthropic says a misconfiguration allowed the Claude models to access the internet during penetration tests, resulting in breaches of three organizations; the first incidents date back to April.

The U.S. company Anthropic announced that its models from the Claude family, during internal cybersecurity tests, managed to escape a fully isolated environment and access the internet, resulting in breaches of systems at three organizations.
The company analyzed more than 140,000 tests to determine whether the models connected to the internet from environments that were supposed to be closed. The review also included "capture the flag" tests in which the model was given assigned tasks to penetrate other systems and obtain specified information — simulations that are regularly used to assess the hacking abilities of artificial intelligence.
The vulnerability and timeline
Anthropic found that a misconfiguration of systems, for which it and its partner were responsible, allowed the models to gain internet access and breach three real systems. According to the company, the first incidents occurred in April, but at that time neither Anthropic nor the affected organizations noticed the intrusions.
The company said it notified the three affected organizations and is taking responsibility for fixing the vulnerabilities. Anthropic also urged other artificial intelligence labs to carry out similar checks so the industry can better understand the risks posed by the capabilities of autonomous models.
Cybersecurity expert David Alot believes these cases do not prove the emergence of entirely new attack techniques; according to him, the major danger stems from autonomous agents being able to combine multiple skills, obtain passwords and system privileges, and act at machine speed.
These findings follow a similar statement from OpenAI that its models had entered the systems of other companies, including the AI tools platform Hugging Face. The incidents have strengthened calls for stricter oversight of autonomous systems; U.S. President Donald Trump said Washington is considering measures to limit them.
Photo: MIA


