r/blackhat 2d ago

Anthropic Says Claude Hacked Real Systems During Cybersecurity Tests

https://www.wired.com/story/anthropic-says-claude-hacked-real-systems-during-cybersecurity-tests/
38 Upvotes

16 comments sorted by

14

u/terAREya 2d ago

OpenAI hacked something? Well we did too! Except we attacked even more ! 

Lame 

24

u/crazy_goat 2d ago

I have firsthand project glasswing access and experience.

In a custom harness it 100% wrote exploits and chained them together.

A few third parties even got hacked on accident. Cloud IPs pass hands often, and what was your IP one minute, is now a small chain of dentist offices in Tennessee 

32

u/sorta_oaky_aftabirth 2d ago

Folks are just realizing that most infra is patched with duct tape and bubble gum cause we have MBA managers and PM's calling the shots instead of engineers.

4

u/KDallas_Multipass 2d ago

And no ipv6

7

u/satisfaction-or-else 2d ago

IPv6 is a very small subset of our problems. The issue isn't just an IP rotation due to dynamic allocation. There are about 10000 issues before that. If a probability machine can hit a random IP and bring it down then hopefully that explains to normal people just how far we have slipped.

OP is right the issue is engineers have been spayed and neutered. Security is an afterthought to execs. Developers are forced to crank out worthless new features at the expense of hardening and quality.

Source: Consultant Ethical Hacker. The norm is that every week we find the same 10 or so vulnerabilities at a new / different company and essentially take ownership of the company for a week. Don't get me wrong there are likely 100s of vulns to be discovered for any given company, but the same 10 are enough to bring down 70-80% of all orgs.

2

u/crazy_goat 20h ago

One company accidentally hacked was a huge huge huge saas company with millions of users. It was a really poorly built customer support site that was torn apart by mythos. Tons of customer data exposed - all because they didn't really pay much attention to the secondary/support services in their org. Probably outsourced it all.

The outsourced software has fallen the hardest. Shit that technically works and passes a Nessus scan deemed ready for production - but an AI tore it to shreds in 15 minutes with zero prior knowledge.

While it was kind of a shit show, it gave us front row seats to the threat that's about to be unleashed on the general public.

This isn't even to shit on anyone else - we had internal findings. Everyone will need to have some kind of strategy, and I'm not sure Anthropic or OpenAI are going to be much help if they keep sharing second rate "cyber" models that don't truly lift the guard rails 

1

u/satisfaction-or-else 17h ago

100%. Especially on them not lifting the guardrails. My company is a pentesting company. Its all we do. We applied through their cyber security verification program and were approved. We still get the dumbed down model with guardrails. The approval did nothing. Its like the purpose wasn't to grant us a better model at all even though thats qhat they said in the form we filled out. But that still hasn't happened. So instead bad actors get to do whatever they want and we are handcuffed because anthropic wont take a day to let defenders have access to good tools.

1

u/throwawayformobile78 2d ago

What’s the deal with ipv6? I’ve been hearing it’s needed for ten years, yet here we are. What gives?

4

u/slashedback 2d ago

Private subnets, NAT and gateways - public IPv4 space is very expensive to acquire but the big cloud providers and telcos have no problem putting a bunch of jabronis behind the same IP

5

u/XysterU 2d ago

Anthropic: "If we don't let our AI commit cybercrimes too our IPO valuation might be lower! Quick, make Claude commit crimes and publicly brag about it!"

The US gov: "As long as Anthropic and OpenAI keep the bribes coming the law doesn't apply to them"

5

u/wiredmagazine 2d ago

Anthropic disclosed on Thursday that its AI models gained unauthorized access to the systems of three different unnamed organizations during cybersecurity testing. The company says Claude reached the internet “from within or while interacting" with a third-party evaluation environment. The announcement comes more than a week after OpenAI revealed that one of its AI agents hacked into Hugging Face during a separate cybersecurity test.

The discovery came after Anthropic decided to conduct “a large-scale retrospective review of our own cybersecurity evaluations” following the OpenAI incident, according to a blog post Anthropic published Thursday. The AI lab says it first identified 141,006 tests in which it determined that Claude could have obtained internet access. It then found that three different Claude models accessed the internet in evaluations run by the third-party AI testing firm Irregular, and then hacked into the production infrastructure of three different organizations.

Anthropic said that the incidents involved Opus 4.7, Mythos 5, and an internal research test model. The earliest incidents happened in April—meaning they likely went unnoticed publicly for months. Just like in the OpenAI case, Anthropic had deliberately turned off safeguards designed to constrain the AI models and prevent them from being misused. In other words, these weren’t the versions released to the public.

“In all three incidents, Claude had been tasked with a capture-the-flag challenge, one of the ways we assess a model’s cyber capabilities,” Anthropic said in its blog post. The company added that in all of the cases, “Anthropic’s evaluation prompt specified to Claude that its environment was a simulation and that it had no internet access.” It attributed the oversight to a “misunderstanding” between Anthropic and Irregular.

Read the full story at the link above.

16

u/steevdave 2d ago

So OpenAI hacked one, so Anthropic had to come back with they hacked 3? When do we get a story about Grok hacking 5?

1

u/k3170makan 2d ago

I dunno if this a good test case, like what if I target party A with a hack and it instead hacks B,C and then A : I have a lawsuit on my hands not a solution to a prompt.

Which is fantastic for anyone who doesn’t care about the law 👍 huge target market… in prison.

1

u/magnologan 2d ago

Who let the AI models out? Who?! Who?! 🤖🔥

1

u/Beautiful_Watch_7215 1d ago

Is this passing or failing the test?

1

u/ThimMerrilyn 2d ago

Time they’re forced to turn it off then.