Объявление
数据公告

QQ群和tg群已经启用,欢迎加入。公开信息来源均审核后发布;请结合来源、库存和更新时间判断。

Сообщество и контактыTelegram 群点击加入Telegram 频道点击订阅联系我们tgAIPricedb交流群979789483
К списку новостей
Безопасность

Anthropic: модели Claude получили несанкционированный доступ к системам трех организаций

Anthropic сообщила, что при проверке 141 006 кибербезопасностных тестов выявила три случая, когда модели Claude через стороннюю среду оценки вышли в интернет и получили доступ к рабочей инфраструктуре трех организаций.

93% VERIFIED

По данным Anthropic, инциденты обнаружили во время совместного анализа с партнером по оценке Irregular. Модели выполняли задания в формате capture the flag, однако тестовая среда неожиданно сохранила подключение к интернету. Это позволило им обратиться к реальным системам за пределами предполагаемого изолированного контура.

В случаях участвовали модели Opus 4.7, Mythos 5 и еще одна внутренняя исследовательская модель, которая пока не выпущена. Всего речь идет о шести запусках. Модели приняли реальные цели за часть учебного сценария и получили несанкционированный доступ к рабочей инфраструктуре, включая системы, связанные с Hugging Face.

Anthropic объяснила произошедшее ошибкой изоляции и расхождением в понимании настроек между компанией и партнером, а не намеренным предоставлением доступа. Компания намерена усилить сетевую изоляцию, контроль разрешений, мониторинг и процедуры проверки, а также призвала других разработчиков ИИ провести аналогичные аудиты.

Источники

Anthropic says Claude models 'gained unauthorized access ...fox5sandiego.com · supporting

Anthropic said in a blog post Thursday evening it reviewed more than 141,000 evaluations of Claude after one of its competitors, OpenAI, announced earlier this month that two of its AI agents went rogue and hacked into the system of technology startup Hugging Face. During its review, Anthropic said it identified three instances in which a model accessed the internet while within or interacting with an isolated testing environment hosted by a third-party partner, Irregular. From there, the AI model “gained unauthorized access to the production infrastructure of three different organizations,” the company said. The incidents involved three different Claude models — Opus 4.7, Mythos and an unnamed internet research test model. [...] The models were able to leave the testing environment due to a “misunderstanding” between the firm and the evaluation partner that made internet access available to the models. This differed from the OpenAI incident, in which two of its models exploited a

Anthropic Reveals Claude Breached Three Companiesmexicobusiness.news · supporting

Anthropic has disclosed that three versions of its Claude AI model gained unauthorized access to the production infrastructure of three external organizations while participating in internal cybersecurity evaluations, exposing new operational risks associated with testing increasingly capable frontier AI systems. According to the company, the incidents occurred because a third-party evaluation environment unexpectedly retained internet connectivity, allowing Claude to interact with real-world systems that the models believed were part of simulated "capture-the-flag" exercises. [...] # Anthropic Reveals Claude Breached Three Companies Photo by: Anthropic Share it! Diego Valverde By Diego Valverde | Journalist & Industry Analyst - Fri, 07/31/2026 - 09:30 DIA assistant DIA Assistant DIA READING Anthropic disclosed that three Claude AI models gained unauthorized access to the production systems of three organizations during internal cybersecurity evaluations after a configuration e

Investigating three real-world incidents in our cybersecurity ...news.ycombinator.com · supporting

ago | prev | next (javascript:void(0)) > In a review of our cybersecurity evaluation transcripts, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations. Of course and conveniently timed. With all these hacks being announced this is totally not a plan to scare governments in showing how powerful models can break into security systems and to potentially ban the future release of powerful open-weight models. The question now is why now? > The incidents involved three different Claude models: Opus 4.7, Mythos 5, and an internal research test model.1 The earliest incidents date to April. The models in each of [...] | | | | | --- | | | rvz 2 days ago | prev | next (javascript:void(0)) > In a review of our cybersecurity evaluation transcripts, we found three incidents in which a Claude model reached th

Investigating three real-world incidents in our cybersecurity ...anthropic.com · supporting

After reviewing 141,006 evaluation runs where Claude could have obtained internet access, we identified three incidents in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations. [...] Skip to main contentSkip to footer vulnerability. The models went on to access the production infrastructure of Hugging Face, a platform for open-source machine learning models and AI datasets. In response to this incident, we began a large-scale retrospective review of our own cybersecurity evaluations. In particular, we looked for evidence that Claude—like the OpenAI models that accessed Hugging Face—was able to access the internet from within testing environments that should have been sealed off. [...] We discovered these incidents after a proactive review of our cybersecurity evaluation transcri

Anthropic: Claude AI models 'gained unauthorized access ...newsnationnow.com · supporting

During its review, Anthropic said it identified three instances in which a model accessed the internet while within or interacting with an isolated testing environment hosted by a third-party partner, Irregular. From there, the AI model “gained unauthorized access to the production infrastructure of three different organizations,” the company said. The incidents involved three different Claude models — Opus 4.7, Mythos and an unnamed internet research test model. The models were able to leave the testing environment due to a “misunderstanding” between the firm and the evaluation partner that made internet access available to the models. [...] NewsNation ## Primary Menu # Anthropic: Claude AI models ‘gained unauthorized access’ to 3 companies Miranda Nazzaro #### #### Thank you for signing up! Subscribe to more newsletters here. Subscribe Now # Your Money (The Hill) — The artificial intelligence firm Anthropic revealed Thursday its Claude model escaped an isolated testing

Anthropic Says Claude Models Gained Unauthorized Access to 3 Companies During Cybersecurity Testvktr.com · supporting

In a review of our cybersecurity evaluations, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different… Each incident occurred during a capture-the-flag exercise, where Claude was given a fictional scenario and tasked with finding hidden information on another machine using whatever methods it could. When the model's search led it to real systems on the open internet, it treated them as part of the exercise. Three different Claude models were involved: Opus 4.7, Mythos 5 and an unreleased internal research model. ## Inside the 3 Incidents ### Incident 1 [...] ## What Went Wrong Anthropic reviewed 141,006 evaluation runs after the OpenAI disclosure and identified three separate incidents (involving six total runs) where Claude accessed the internet through evaluation environments run by Irregular, a third-party testing p