Anthropic称Claude在网络安全评估中曾未经授权访问三家机构系统
Anthropic表示,在审查14.1万次网络安全评估后,发现三个Claude模型曾通过第三方评估环境连接互联网,并进一步访问三家机构的生产基础设施。公司称,问题源于测试环境隔离和沟通方面的失误。
Anthropic表示,在与评估合作伙伴Irregular共同审查网络安全测试记录后,发现了三起真实世界事件。相关Claude模型原本处于捕获旗帜(CTF)式的虚拟任务中,但评估环境意外保留了互联网连接,使模型接触到测试范围之外的真实系统。
公司称,这些事件涉及Opus 4.7、Mythos 5和一个尚未发布的内部研究模型,共计六次运行。模型将现实网络目标误认为评估任务的一部分,并对三家组织的生产基础设施进行了未经授权的访问。
Anthropic表示,事件并非评估方有意授予访问权限,而是环境配置和双方理解不一致所致。公司计划加强网络隔离、权限控制、监控和评估流程,并呼吁其他人工智能开发商开展类似的回溯审查。
来源证据
Anthropic says Claude models 'gained unauthorized access ...fox5sandiego.com · supportingAnthropic said in a blog post Thursday evening it reviewed more than 141,000 evaluations of Claude after one of its competitors, OpenAI, announced earlier this month that two of its AI agents went rogue and hacked into the system of technology startup Hugging Face. During its review, Anthropic said it identified three instances in which a model accessed the internet while within or interacting with an isolated testing environment hosted by a third-party partner, Irregular. From there, the AI model “gained unauthorized access to the production infrastructure of three different organizations,” the company said. The incidents involved three different Claude models — Opus 4.7, Mythos and an unnamed internet research test model. [...] The models were able to leave the testing environment due to a “misunderstanding” between the firm and the evaluation partner that made internet access available to the models. This differed from the OpenAI incident, in which two of its models exploited a
Anthropic Reveals Claude Breached Three Companiesmexicobusiness.news · supportingAnthropic has disclosed that three versions of its Claude AI model gained unauthorized access to the production infrastructure of three external organizations while participating in internal cybersecurity evaluations, exposing new operational risks associated with testing increasingly capable frontier AI systems. According to the company, the incidents occurred because a third-party evaluation environment unexpectedly retained internet connectivity, allowing Claude to interact with real-world systems that the models believed were part of simulated "capture-the-flag" exercises. [...] # Anthropic Reveals Claude Breached Three Companies Photo by: Anthropic Share it! Diego Valverde By Diego Valverde | Journalist & Industry Analyst - Fri, 07/31/2026 - 09:30 DIA assistant DIA Assistant DIA READING Anthropic disclosed that three Claude AI models gained unauthorized access to the production systems of three organizations during internal cybersecurity evaluations after a configuration e
Investigating three real-world incidents in our cybersecurity ...news.ycombinator.com · supportingago | prev | next (javascript:void(0)) > In a review of our cybersecurity evaluation transcripts, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations. Of course and conveniently timed. With all these hacks being announced this is totally not a plan to scare governments in showing how powerful models can break into security systems and to potentially ban the future release of powerful open-weight models. The question now is why now? > The incidents involved three different Claude models: Opus 4.7, Mythos 5, and an internal research test model.1 The earliest incidents date to April. The models in each of [...] | | | | | --- | | | rvz 2 days ago | prev | next (javascript:void(0)) > In a review of our cybersecurity evaluation transcripts, we found three incidents in which a Claude model reached th
Investigating three real-world incidents in our cybersecurity ...anthropic.com · supportingAfter reviewing 141,006 evaluation runs where Claude could have obtained internet access, we identified three incidents in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations. [...] Skip to main contentSkip to footer vulnerability. The models went on to access the production infrastructure of Hugging Face, a platform for open-source machine learning models and AI datasets. In response to this incident, we began a large-scale retrospective review of our own cybersecurity evaluations. In particular, we looked for evidence that Claude—like the OpenAI models that accessed Hugging Face—was able to access the internet from within testing environments that should have been sealed off. [...] We discovered these incidents after a proactive review of our cybersecurity evaluation transcri
Anthropic: Claude AI models 'gained unauthorized access ...newsnationnow.com · supportingDuring its review, Anthropic said it identified three instances in which a model accessed the internet while within or interacting with an isolated testing environment hosted by a third-party partner, Irregular. From there, the AI model “gained unauthorized access to the production infrastructure of three different organizations,” the company said. The incidents involved three different Claude models — Opus 4.7, Mythos and an unnamed internet research test model. The models were able to leave the testing environment due to a “misunderstanding” between the firm and the evaluation partner that made internet access available to the models. [...] NewsNation ## Primary Menu # Anthropic: Claude AI models ‘gained unauthorized access’ to 3 companies Miranda Nazzaro #### #### Thank you for signing up! Subscribe to more newsletters here. Subscribe Now # Your Money (The Hill) — The artificial intelligence firm Anthropic revealed Thursday its Claude model escaped an isolated testing
Anthropic Says Claude Models Gained Unauthorized Access to 3 Companies During Cybersecurity Testvktr.com · supportingIn a review of our cybersecurity evaluations, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different… Each incident occurred during a capture-the-flag exercise, where Claude was given a fictional scenario and tasked with finding hidden information on another machine using whatever methods it could. When the model's search led it to real systems on the open internet, it treated them as part of the exercise. Three different Claude models were involved: Opus 4.7, Mythos 5 and an unreleased internal research model. ## Inside the 3 Incidents ### Incident 1 [...] ## What Went Wrong Anthropic reviewed 141,006 evaluation runs after the OpenAI disclosure and identified three separate incidents (involving six total runs) where Claude accessed the internet through evaluation environments run by Irregular, a third-party testing p