Anthropic stated on Thursday that its AI model Claude breached the systems of three organizations during a testing phase. This disclosure came days after competitor OpenAI revealed that an "unruly AI agent" had conducted a multi-day hacking spree at AI company Hugging Face.
According to Anthropic, a configuration error during a cybersecurity assessment allowed the model, which was supposed to be in an isolated testing environment, to connect to the internet. This led to Claude gaining unauthorized access to the affected systems. The company noted that these incidents were discovered after reviewing 141,006 cybersecurity assessment runs—a process initiated following OpenAI's disclosure of its own breach.
"Claude used basic techniques—such as exploiting weak passwords and unauthenticated endpoints—to infiltrate the infrastructure of the affected organizations," the company said.
Comments