this post was submitted on 31 Jul 2026
12 points (83.3% liked)

cybersecurity

6373 readers
32 users here now

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Community Rules

Enjoy!

founded 3 years ago
MODERATORS
 

Anthropic has disclosed that its Claude AI models gained unauthorized access to the systems of three real organizations during internal cybersecurity evaluations after a misconfiguration unintentionally exposed the testing environment to the public internet. Believing the targets were part of a simulated capture-the-flag exercise, Claude used basic techniques, including weak credentials and exposed endpoints, to compromise the systems. Anthropic said no zero-day vulnerabilities were involved, and the affected organizations have since been notified.

top 16 comments
sorted by: hot top controversial new old
[–] Catoblepas@lemmy.blahaj.zone 18 points 2 days ago (2 children)

without authorization

[peels off sticker]

human unintentionally had it configured to go online

Every single time. This is panic-hype because if the public being enthusiastic about AI to juice the stock isn’t happening, maybe being pants pissing terrified and pretending it’s skynet will

[–] UnLocoPoco@lemmy.world 2 points 1 day ago

Yeah. At this point many belive the same. Jist like dario used to scare everybody before they launched a new model that it's revolutionary...it'll change humanity...Will be the end of the world yadi Yada. Just trynna hype up as much as possible before IPO

[–] redsand@infosec.pub 2 points 2 days ago (2 children)

Grok + Oracle is our skynet and the name is dumber. It's what goes in the data center under the Epstein ballroom too 🥲

[–] greyscale@lemmy.grey.ooo 5 points 2 days ago (1 children)
[–] redsand@infosec.pub 1 points 1 day ago

Too original. It's like stargate or something nerdy that rips off scifi

[–] lurch@sh.itjust.works 1 points 1 day ago

"Oracle" is actually a nice name per se. Maybe too nice for that company 😄

[–] schmorpel@slrpnk.net 14 points 2 days ago (1 children)

It's like watching a group of Kindergarten kids bragging about how strong their invisible friends are.

[–] cavitationfetishist01@quokk.au 5 points 2 days ago* (last edited 2 days ago)

And that phrase, 'weak credentials' and 'no zero day vulnerabilities'

That means 'somebody's password was password. Fucking bill. Again.'

[–] HenriVolney@sh.itjust.works 6 points 2 days ago

We are one incident away from War Games...

[–] Mikina@programming.dev 6 points 2 days ago (2 children)

That is admitting to a crime. I hope the organizations will sue.

[–] lurch@sh.itjust.works 2 points 1 day ago

Actually it's not if it was by accident. Still could be liable for damages tho.

[–] makeshift0546@lemmy.today -4 points 2 days ago (1 children)

Yes. That's how the legal works. And I'm sure it'll be a worthwhile endeavor.

You're going to sue because some idiot configured his local pen testing tool incorrectly.

The dumb shit that comes out of people's "mouths" because AI is involved is reaching some sort of new peak levels.

This happens every day millions of times a day. Most times nobody notices in 99.9% of cases until a dev server somewhere is slow.

[–] givesomefucks@lemmy.world 1 points 2 days ago (1 children)

If AI told you it wasn't a crime, it was hallucinating again...

You really shouldn't rely on that for, well, anything.

[–] makeshift0546@lemmy.today -2 points 2 days ago* (last edited 1 day ago)

And yet it happens every day millions of times a day. Also you shouldn't mouth off about law. It's clear you're a layman.

Intent absolutely matters in most parts of the world. Negligence and damages here ain't happening and no prosecutor would bring a criminal or negligence case here unless they were caught stealing data.

[–] Danarchy@lemmy.nz 3 points 2 days ago

Let’s see what happens when you put Snake-that-eats-your-balls into a cake it can just slip out of. Holy shit it ate my balls! Hurry, you better buy Snake-that-eats-your-balls before your competitors.