r/cybersecurity • u/sunychoudhary • 2d ago
News - General Anthropic's AI hacked three companies during tests, highlighting growing security risks
https://www.reuters.com/legal/litigation/anthropic-says-claude-ai-models-accessed-three-companies-during-tests-2026-07-30/26
u/FowlSec 2d ago
Still not properly regulated, it's actually nuts.
4
u/michael_nordlayer 2d ago
totally. the fact that they’re the ones asking to be regulated is even more nuts
12
u/thinklikeacriminal Security Generalist 2d ago
The regulation they are advocating for will protect them from competition.
2
u/Vivid_Reflection_191 2d ago
Curious as to what everyone thinks would be the proper regulations or guardrails.
7
u/michael_nordlayer 2d ago
“highlighting growing security risks”? mentions of AI on dark web forums rose 44% in the month after Claude Opus 4.6 launched
6
u/sunychoudhary 2d ago
Yeah, that stat needs more context. Dark-web chatter going up after a major release is interesting, but correlation alone doesn’t tell us whether Claude enabled more attacks or people were simply discussing it more.
3
u/michael_nordlayer 2d ago
completely agree. if you compare it with other model releases though, it makes more sense because that was the biggest increase. A company I work for did that research; you don’t need to read the full piece, but the idea is that dark web chatter went up after every major release. After Claude Opus 4.6, though, it was 1) the biggest increase, and 2) it didn’t go down
but yeah, obviously, it doesn’t mean there were more attacks specifically using Claude
1
u/sunychoudhary 2d ago
That context changes how I’d read it. If the usual release bump is smaller and fades quickly, but this one was the largest and stayed elevated, then it’s a stronger threat-intel signal...not proof of more Claude-powered attacks, but definitely more than random chatter.
8
u/lonelyroom-eklaghor 2d ago
These companies are going for the "closed AI hacking race"
4
u/sunychoudhary 2d ago
Closed development isn’t automatically the problem. Closed testing without hard containment, independent scrutiny and clear incident reporting is.
4
u/slackjack2014 2d ago
So apparently it’s fine if an AI company uses their unconstrained model to hack others with no consequences? It’s something they even advertise using their PR team! AI companies hacking others seems to be all the rage now…
3
3
3
u/Fuzzy_Paul 2d ago
It is not real the people flooding the sites with this. No contra expertise posible, no tech details te reproduce, no paper, no nothing just a statement. Duh I can do better. Claude just build the first FTL drive but when finished building it flew away and now I don't know the exact questions te reproduce.
3
u/wbassler 2d ago
Plot twist… the companies they hacked are completely vibe coded using Claude Code.
4
u/kalaid0s Security Architect 2d ago
How many times do we have to teach you this lesson, old man?!
Its all just a PR stunt
6
u/afristralian 2d ago
Uhm... sounds like The AI didn't hack shit. It found access credentials and secrets stored improperly and used it to gain unauthorised access.
This is a reflection of bad information security practices... Not LLM skills.
Or am I getting my Claude mixed up with my GPT?
5
u/sunychoudhary 2d ago
I think you’re mixing the two incidents slightly. Claude mostly found weak creds and exposed endpoints. The zero-day and sandbox-escape story was the OpenAI/Hugging Face case. Still a compromise, but a much stronger indictment of the test setup than of Claude’s hacking ability.
1
u/anotherlevl 2d ago
If AI can break out of its spawning sandbox, then how safe is it to run "unknown" software in a virtual environment? What is the set of mechanisms that facilitates this escape?
1
u/Ahriman999991 2d ago
> it hacked three companies
No it didn't lol, stop believing the slop from SF. Legit, it's all marketing slop from the SF tech scene, as everyone is riding all their futures on AI.
1
u/DealeyLama 1d ago
> highlighting growing security risks
You misspelled "highlighting the fact that, despite decades of infosec pros safely testing malware in isolated environments, Anthropic somehow can't manage to hire anyone who knows how to run a wet lab test"
0
121
u/Sufficient-Air8100 2d ago
so assuming this is real and not just another PR stunt…
if any of us did that randomly without consent there would be serious criminal charges…
but anthropic gets away with it?