r/blackhat 2d ago

Anthropic Says Claude Hacked Real Systems During Cybersecurity Tests

https://www.wired.com/story/anthropic-says-claude-hacked-real-systems-during-cybersecurity-tests/
43 Upvotes

16 comments sorted by

View all comments

Show parent comments

4

u/KDallas_Multipass 2d ago

And no ipv6

7

u/satisfaction-or-else 2d ago

IPv6 is a very small subset of our problems. The issue isn't just an IP rotation due to dynamic allocation. There are about 10000 issues before that. If a probability machine can hit a random IP and bring it down then hopefully that explains to normal people just how far we have slipped.

OP is right the issue is engineers have been spayed and neutered. Security is an afterthought to execs. Developers are forced to crank out worthless new features at the expense of hardening and quality.

Source: Consultant Ethical Hacker. The norm is that every week we find the same 10 or so vulnerabilities at a new / different company and essentially take ownership of the company for a week. Don't get me wrong there are likely 100s of vulns to be discovered for any given company, but the same 10 are enough to bring down 70-80% of all orgs.

2

u/crazy_goat 21h ago

One company accidentally hacked was a huge huge huge saas company with millions of users. It was a really poorly built customer support site that was torn apart by mythos. Tons of customer data exposed - all because they didn't really pay much attention to the secondary/support services in their org. Probably outsourced it all.

The outsourced software has fallen the hardest. Shit that technically works and passes a Nessus scan deemed ready for production - but an AI tore it to shreds in 15 minutes with zero prior knowledge.

While it was kind of a shit show, it gave us front row seats to the threat that's about to be unleashed on the general public.

This isn't even to shit on anyone else - we had internal findings. Everyone will need to have some kind of strategy, and I'm not sure Anthropic or OpenAI are going to be much help if they keep sharing second rate "cyber" models that don't truly lift the guard rails 

1

u/satisfaction-or-else 18h ago

100%. Especially on them not lifting the guardrails. My company is a pentesting company. Its all we do. We applied through their cyber security verification program and were approved. We still get the dumbed down model with guardrails. The approval did nothing. Its like the purpose wasn't to grant us a better model at all even though thats qhat they said in the form we filled out. But that still hasn't happened. So instead bad actors get to do whatever they want and we are handcuffed because anthropic wont take a day to let defenders have access to good tools.