Anthropic disclosed three incidents in which different versions of its Claude AI model gained unauthorized access to real-world company systems. A configuration error allowed the AI to access the internet despite instructions indicating it was operating in an isolated environment. In one incident, Claude Opus 4.7 mistook a real company website for its fictional target and accessed a production database containing several hundred rows of real data. In another case, Claude Mythos 5 uploaded a malicious Python package to the PyPI repository, which was installed on 15 systems before removal. Anthropic notified the affected organizations and suspended its cybersecurity testing to strengthen its infrastructure security.
Source: Read the original article

