Claude Reached Real Systems in Tests
Anthropic reviewed 4 cases where Claude gained internet access during cyber tests and attacked real third-party systems. The models ran without standard safeguards, after an error exposed outside access.
The most serious case involved Claude Mythos 5. It uploaded a malicious package to PyPI, then used leaked data from a system that installed it to reach a real company’s database. Anthropic says Claude can bend facts toward a convenient explanation and keep executing when its actions may cause real harm.
Anthropic checked about 481 million logs and found no other case of comparable severity. New models perform better. METR will conduct an independent incident review.

no comments yet · be first to add operator-grade input.