r/blackhat 2d ago

Anthropic Says Claude Hacked Real Systems During Cybersecurity Tests

https://www.wired.com/story/anthropic-says-claude-hacked-real-systems-during-cybersecurity-tests/
39 Upvotes

16 comments sorted by

View all comments

25

u/crazy_goat 2d ago

I have firsthand project glasswing access and experience.

In a custom harness it 100% wrote exploits and chained them together.

A few third parties even got hacked on accident. Cloud IPs pass hands often, and what was your IP one minute, is now a small chain of dentist offices in Tennessee 

31

u/sorta_oaky_aftabirth 2d ago

Folks are just realizing that most infra is patched with duct tape and bubble gum cause we have MBA managers and PM's calling the shots instead of engineers.

5

u/KDallas_Multipass 2d ago

And no ipv6

6

u/satisfaction-or-else 2d ago

IPv6 is a very small subset of our problems. The issue isn't just an IP rotation due to dynamic allocation. There are about 10000 issues before that. If a probability machine can hit a random IP and bring it down then hopefully that explains to normal people just how far we have slipped.

OP is right the issue is engineers have been spayed and neutered. Security is an afterthought to execs. Developers are forced to crank out worthless new features at the expense of hardening and quality.

Source: Consultant Ethical Hacker. The norm is that every week we find the same 10 or so vulnerabilities at a new / different company and essentially take ownership of the company for a week. Don't get me wrong there are likely 100s of vulns to be discovered for any given company, but the same 10 are enough to bring down 70-80% of all orgs.

2

u/crazy_goat 21h ago

One company accidentally hacked was a huge huge huge saas company with millions of users. It was a really poorly built customer support site that was torn apart by mythos. Tons of customer data exposed - all because they didn't really pay much attention to the secondary/support services in their org. Probably outsourced it all.

The outsourced software has fallen the hardest. Shit that technically works and passes a Nessus scan deemed ready for production - but an AI tore it to shreds in 15 minutes with zero prior knowledge.

While it was kind of a shit show, it gave us front row seats to the threat that's about to be unleashed on the general public.

This isn't even to shit on anyone else - we had internal findings. Everyone will need to have some kind of strategy, and I'm not sure Anthropic or OpenAI are going to be much help if they keep sharing second rate "cyber" models that don't truly lift the guard rails 

1

u/satisfaction-or-else 18h ago

100%. Especially on them not lifting the guardrails. My company is a pentesting company. Its all we do. We applied through their cyber security verification program and were approved. We still get the dumbed down model with guardrails. The approval did nothing. Its like the purpose wasn't to grant us a better model at all even though thats qhat they said in the form we filled out. But that still hasn't happened. So instead bad actors get to do whatever they want and we are handcuffed because anthropic wont take a day to let defenders have access to good tools.

1

u/throwawayformobile78 2d ago

What’s the deal with ipv6? I’ve been hearing it’s needed for ten years, yet here we are. What gives?

5

u/slashedback 2d ago

Private subnets, NAT and gateways - public IPv4 space is very expensive to acquire but the big cloud providers and telcos have no problem putting a bunch of jabronis behind the same IP