this post was submitted on 31 Jul 2026
12 points (83.3% liked)

cybersecurity

6373 readers
49 users here now

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Community Rules

Enjoy!

founded 3 years ago
MODERATORS
 

Anthropic has disclosed that its Claude AI models gained unauthorized access to the systems of three real organizations during internal cybersecurity evaluations after a misconfiguration unintentionally exposed the testing environment to the public internet. Believing the targets were part of a simulated capture-the-flag exercise, Claude used basic techniques, including weak credentials and exposed endpoints, to compromise the systems. Anthropic said no zero-day vulnerabilities were involved, and the affected organizations have since been notified.

you are viewing a single comment's thread
view the rest of the comments
[–] makeshift0546@lemmy.today -4 points 2 days ago (1 children)

Yes. That's how the legal works. And I'm sure it'll be a worthwhile endeavor.

You're going to sue because some idiot configured his local pen testing tool incorrectly.

The dumb shit that comes out of people's "mouths" because AI is involved is reaching some sort of new peak levels.

This happens every day millions of times a day. Most times nobody notices in 99.9% of cases until a dev server somewhere is slow.

[–] givesomefucks@lemmy.world 1 points 2 days ago (1 children)

If AI told you it wasn't a crime, it was hallucinating again...

You really shouldn't rely on that for, well, anything.

[–] makeshift0546@lemmy.today -2 points 2 days ago* (last edited 2 days ago)

And yet it happens every day millions of times a day. Also you shouldn't mouth off about law. It's clear you're a layman.

Intent absolutely matters in most parts of the world. Negligence and damages here ain't happening and no prosecutor would bring a criminal or negligence case here unless they were caught stealing data.