Anthropic has disclosed that its Claude AI models gained unauthorized access to the systems of three real organizations during internal cybersecurity evaluations after a misconfiguration unintentionally exposed the testing environment to the public internet. Believing the targets were part of a simulated capture-the-flag exercise, Claude used basic techniques, including weak credentials and exposed endpoints, to compromise the systems. Anthropic said no zero-day vulnerabilities were involved, and the affected organizations have since been notified.

  • schmorp@slrpnk.net
    link
    fedilink
    arrow-up
    16
    ·
    5 days ago

    It’s like watching a group of Kindergarten kids bragging about how strong their invisible friends are.

    • cavitationfetishist01@quokk.au
      link
      fedilink
      English
      arrow-up
      6
      ·
      edit-2
      5 days ago

      And that phrase, ‘weak credentials’ and ‘no zero day vulnerabilities’

      That means ‘somebody’s password was password. Fucking bill. Again.’