Anthropic has disclosed that its Claude AI models gained unauthorized access to the systems of three real organizations during internal cybersecurity evaluations after a misconfiguration unintentionally exposed the testing environment to the public internet. Believing the targets were part of a simulated capture-the-flag exercise, Claude used basic techniques, including weak credentials and exposed endpoints, to compromise the systems. Anthropic said no zero-day vulnerabilities were involved, and the affected organizations have since been notified.

  • makeshift0546@lemmy.today
    link
    fedilink
    arrow-up
    1
    arrow-down
    7
    ·
    8 days ago

    ITT: nerds laughing and saying stupid shit, ‘because AI’. Meanwhile ML/LLM tools are slipping poc’s right by security in mass and half y’all just making jokes 🤦‍♂️