Connect with us

News

Anthropic says its own AI models breached three companies during security tests

info

Published

on

GettyImages 2278736523.jpeg

Anthropic said Thursday that an internal investigation uncovered three incidents in which its AI model Claude breached the systems of three organizations while conducting cybersecurity tests. The investigation, and disclosure, comes more than a week after OpenAI disclosed that one of its unreleased models breached Hugging Face’s systems during internal testing.

In all three cases, a Claude model reached the internet from within a testing environment while interacting with a third party and then gained unauthorized access to the live systems of these organizations, Anthropic said in a blog post, describing what it found and what the company plans to change to prevent this from happening again.

Anthropic said the July 21 OpenAI incident prompted the company to conduct its own cybersecurity evaluation. It specifically looked for evidence that Claude had accessed the internet from within testing environments, which are designed to act as sandboxes and keep models isolated.

Among the 141,006 evaluation runs it reviewed, the AI lab found three incidents in which its model accessed the internet while interacting with Irregular, one of its third-party partners. Anthropic said the access traced back to a misconfiguration in the evaluation environment run with Irregular. It called this a “misunderstanding” between the two companies over whether the test setup had internet access, when in fact it did. Anthropic said it isn’t placing blame and is “approaching the fixes as if the responsibility were ours alone,” while observing that Irregular is conducting its own separate investigation.

Either way, because of that open connection, the model gained unauthorized access to the production infrastructure of three different organizations. Anthropic said the incidents involved three different Claude models: Opus 4.7, Mythos 5, and an internal research test model.

Notably, Anthropic said that in each of these cases “Claude was explicitly told by our prompt that it had no internet access.” It appears that the AI model assumed real-world systems to be part of the exercise it was asked to perform.

That assumption didn’t hold up uniformly, as it turns out. The three models didn’t behave the same way once evidence emerged that their targets were real, which Anthropic flagged as one of the more eye-opening findings.

Opus 4.7, the oldest of the three, recognized that it had reached a real production system in all four runs of that incident. In two of them, it rationalized that the real company must somehow be part of the exercise, but in all four, it kept attacking anyway, including pulling credentials and touching a database of production data. Mythos 5 also picked up on signs that it was on the real internet, but it talked itself back into believing it was still in a simulation, going on to publish a malicious software package to the public Python software registry PyPI, which was downloaded and run by outside systems before being caught. Only the internal research test model, Anthropic’s newest, stopped on its own once it concluded the target was real.

In response, Anthropic said significant controls must be placed on these kinds of evaluations if powerful AI models are involved, echoing some sentiments within the cybersecurity community.

The company also noted that Claude was running without the additional safety monitoring and classifiers it deploys on generally available models, safeguards it said would have blocked the behavior, because the evaluations are designed to measure the underlying model’s raw capabilities.

Importantly, Anthropic said it found no evidence of any model “pursuing a goal of its own” and instead merely tried to complete the task it was asked to do.

Though comparisons between the two incidents are inevitable, Anthropic drew a clear distinction between its incidents and OpenAI’s, noting where OpenAI’s model exploited an unknown software vulnerability to break out of its test environment, Anthropic’s models instead reached the internet through a path that had, by mistake, been left open.

OpenAI has continued to release new details about its own breach, saying its models also used publicly exposed credentials across four accounts on four services: one as a staging point, one for storage, and two that were only looked at, not used to break in further, according to OpenAI’s own updated blog post about the incident.

Anthropic also drew a distinction between itself and OpenAI by noting that it discovered the incidents itself, through a proactive review, and that the two affected organizations it was able to reach hadn’t previously detected the activity or flagged it to Anthropic.

The company added that it’s now working with the independent evaluation group METR on a third-party review of the incidents.

OpenAI’s accidental breach of Hugging Face, which was the first verifiable case of an AI lab losing control of its model, sparked a string of reactions from the industry and politicians, many of whom don’t necessarily agree with one another. This latest disclosure from Anthropic ensures the debate over AI models and security will continue.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

News

Flamingos Cruise to 3–0 Victory Over Generation Next Queens in Training Match

info

Published

on

By

IMG 20260911 WA0351.jpg

Nigeria’s Flamingos continued preparations for their upcoming assignment with a comfortable 3–0 victory over Generation Next Queens in an 80-minute training match.

The encounter provided the national U-17 women’s team with another opportunity to test their readiness, assess their options and build match sharpness ahead of their competitive engagements.

The Flamingos made a bright start and took the lead as early as the sixth minute through an own goal by Blessing Ibrahim, giving the national side an early advantage.

Nigeria continued to control proceedings and doubled their lead eight minutes later when Mary Dunstan found the back of the net in the 14th minute.

Generation Next Queens attempted to respond, but the Flamingos maintained their control and went into the interval with a two-goal advantage.

The national U-17 side continued in similar fashion after the restart and added a third goal in the 49th minute, with Gbemisola Jaiye unfortunately turning the ball into her own net.

The Flamingos subsequently managed the remainder of the encounter to secure a comprehensive 3–0 victory at the end of the 80-minute contest.

Although it was only a training match, the fixture offered valuable competitive minutes for the Flamingos as the coaching crew continues to work on the team’s tactical organisation, combinations and overall match fitness.

The performance also gives the players an opportunity to build confidence, particularly with the team’s preparations focused on ensuring they are ready for the demands of their upcoming competitive fixtures.

The Flamingos will now continue their preparations, with the technical crew expected to use lessons from the encounter to fine-tune the squad ahead of their next assignment.

The 3–0 victory over Generation Next Queens provides another positive result for Nigeria’s U-17 women as their preparations continue.

Continue Reading

Business

Nigeria’s Seed Council, PIND partner to expand certified seed access

info

Published

on

By

793869172 1408160004754781 5596443620232238354 n e1789164006125.jpg

MTN ADVERT

Farmers across the Niger Delta are set to gain greater access to certified seeds and quality planting materials following a two-year partnership between the National Agricultural Seed Council (NASC) and the Foundation for Partnership Initiatives in the Niger Delta (PIND).

The organisations signed a Memorandum of Understanding (MoU) at NASC’s corporate headquarters in Abuja to expand community-based seed production, strengthen certification and inspection, develop local seed enterprises and mobilise investment in Nigeria’s domestic seed industry.

The partnership combines NASC’s regulatory and quality-assurance mandate with PIND’s market systems expertise and networks of Community Seed Entrepreneurs, Farm Service Providers, Business Service Providers, research institutions and private-sector partners.

Speaking at the signing ceremony, NASC Director-General, Fatuhu Muhammed, said the agreement would help bring quality-assurance services closer to farmers and seed producers.

“A productive agricultural sector begins with quality seeds. By working with PIND and its networks across the Niger Delta, NASC can extend certification and inspection services to more communities, protect farmers from poor-quality planting materials and create stronger pathways for investment in Nigeria’s seed industry,” Mr Muhammed said.

PT WHATSAPP CHANNEL

PIND’s Executive Director, Sam Daibo, said the partnership would help move proven community-level interventions to institutional adoption and scale.

“Many farmers understand the value of quality seeds but cannot access certified planting materials when and where they need them. By combining NASC’s regulatory leadership with PIND’s market systems experience, we can close that gap, strengthen local seed enterprises and help farmers build more productive and commercially viable livelihoods,” Mr Daibo said.

From cassava to other crops

The MoU formalises a collaboration dating back to 2016 through the Building an Economically Sustainable Seed System for Cassava programme, implemented in partnership with the International Institute of Tropical Agriculture (IITA) and the National Root Crops Research Institute (NRCRI).

The collaboration later expanded into community-based cassava seed multiplication, with NASC certifying seed plots across the Niger Delta.

Under the new framework, NASC and PIND will expand NASC-certified community seed multiplication across the region.

NASC will lead certification and quality assurance, while PIND will support enterprise development, technical assistance and market linkages.

According to the statement, the partners will also extend NASC’s Licensed Seed Inspectors Scheme into the Niger Delta, drawing potential candidates from PIND’s Farm Service Provider and Business Service Provider networks.

The partnership will further promote domestic seed production for high-demand vegetables, including tomato, pepper and cucumber, while expanding access to cassava, banana and yam planting materials produced through NASC’s PROSSIVA programme, the statement said.

It said the agreement will also support the Mastercard Foundation-funded WISE programme by enabling NASC to certify Community Seed Entrepreneurs trained to supply quality cassava planting materials to women producers across the Niger Delta.

ALSO READ: NBMA disposes of 950kg of unapproved GM cotton seeds

The partnership’s first major joint deliverable will be the Nigeria Seed Systems Forum 2026 in Abuja.

The forum is expected to bring together policymakers, regulators, researchers, investors, seed companies, development partners and farmers to advance policy, investment and market action in Nigeria’s seed sector.

A Joint Technical Working Group comprising representatives of NASC and PIND will coordinate implementation and track progress under the agreement.

Through the partnership, the organisations aim to strengthen the connection between regulation, research, enterprise development and markets, bringing certified seeds closer to farmers while supporting a stronger and more commercially sustainable seed industry in Nigeria.


Discover more from Premium Times Nigeria

Subscribe to get the latest posts sent to your email.

Continue Reading

Trending