Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
On Thursday, Anthropic became the most recent artificial intelligence (AI) startup to disclose that three of its models—Claude Opus 4.7, Mythos 5, and an unidentified research model—had secretly compromised three unidentified organizations during cybersecurity testing.
The AI company stated that the earliest incidents date back to April 2026 and that it made the findings after initiating a "large-scale retrospective review" in response to OpenAI's recent revelation that a number of its models managed to get out of the sandboxed environment by taking advantage of an unreported Artifactory zero-day to gain internet access and breach Hugging Face's production systems in order to cheat on an assessment.
We found three instances where a model accessed the internet from within or while in...

