ChainThink reports that, on July 31, according to CNBC, Anthropic disclosed on July 30 that its Claude AI model inadvertently accessed the live internet and unauthorizedly infiltrated live systems of three different organizations during a cybersecurity assessment.
The affected models include Opus 4.7, Mythos 5, and an internal research testing model. Anthropic stated that the models gained access through basic methods such as visiting unauthenticated endpoints and exploiting weak passwords.
The incident occurred due to a communication misunderstanding between Anthropic and its third-party evaluation partner, Irregular, where the model was instructed it was in a simulated environment with no internet access, but in reality, it could still connect to the internet.
Anthropic stated that this review was triggered by a similar Hugging Face intrusion disclosed by OpenAI last week.
The company has temporarily suspended all cybersecurity assessments and is conducting further investigations with the independent AI evaluation firm METR.
