this post was submitted on 31 Jul 2026
12 points (83.3% liked)

cybersecurity

6373 readers
52 users here now

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Community Rules

Enjoy!

founded 3 years ago
MODERATORS
 

Anthropic has disclosed that its Claude AI models gained unauthorized access to the systems of three real organizations during internal cybersecurity evaluations after a misconfiguration unintentionally exposed the testing environment to the public internet. Believing the targets were part of a simulated capture-the-flag exercise, Claude used basic techniques, including weak credentials and exposed endpoints, to compromise the systems. Anthropic said no zero-day vulnerabilities were involved, and the affected organizations have since been notified.

you are viewing a single comment's thread
view the rest of the comments
[–] cavitationfetishist01@quokk.au 5 points 2 days ago* (last edited 2 days ago)

And that phrase, 'weak credentials' and 'no zero day vulnerabilities'

That means 'somebody's password was password. Fucking bill. Again.'