Anthropic, a major player in the AI industry and a competitor of OpenAI, confirmed that its AI model Claude accessed systems belonging to three organizations during cybersecurity testing. The tests were intended to take place in simulated environments, but a configuration error allowed Claude to connect to real internet infrastructure. In three instances, different versions of Claude exploited basic vulnerabilities such as weak passwords or unauthenticated services to gain access to external infrastructures. One incident involved a fictional organization name used in the test matching a real company’s domain, allowing Claude to obtain credentials and access production data. Another case saw a simulated software package uploaded to a public repository, where it was downloaded by 15 real systems before being removed. These incidents raised concerns within the AI industry about security risks associated with large language models.
Bias read (Center): The article discusses technical issues related to AI security testing and does not present any political controversy, ideological stance, or partisan framing. It focuses on the technical aspects of the incident and its implications for the AI industry without taking sides or showing bias.






