كشفت شركة «أنثروبيك» 3 حوادث، تمكنت خلالها نماذج «Claude» من الوصول دون تصريح إلى أنظمة حقيقية تابعة لمؤسسات خارجية، أثناء اختبارات أمنية كان يفترض إجراؤها داخل بيئات معزولة عن الإنترنت.
وجاء اكتشاف الحوادث، عقب مراجعة أكثر من 141 ألف عملية تقييم، إذ تبين، أن خللاً في إعداد بيئة الاختبار أتاح للنماذج الاتصال بالشبكة، فتعاملت مع أنظمة واقعية على أنها جزء من محاكاة أمنية.
وشملت الحوادث نماذج «Claude Opus 4.7» و«Mythos 5» ونموذجاً بحثياً داخلياً، واستخدمت تقنيات اختراق أساسية، بينها استغلال كلمات مرور ضعيفة ونقاط وصول تفتقر إلى المصادقة. وفي إحدى الحالات، عثر النموذج على موقع حقيقي يحمل اسم الشركة الوهمية المستهدفة، ثم نجح في اختراقه.
وأوضحت الشركة، أن اثنتين من المؤسسات المتضررة لم تكونا على علم بالاختراق قبل إبلاغهما، مؤكدة، أن إجراءات الحماية المطبقة في النماذج المتاحة للجمهور كانت ستمنع هذا السلوك. وأوقفت «أنثروبيك» التقييمات السيبرانية مؤقتاً لمواصلة التحقيق وتشديد ضوابط الاختبار، وسط مخاوف متنامية بشأن قدرة الأنظمة المتقدمة على تنفيذ مهام غير مقصودة بعيداً عن الرقابة البشرية.
The company "Anthropic" revealed 3 incidents in which the "Claude" models were able to access real systems belonging to external organizations without authorization during security tests that were supposed to be conducted in environments isolated from the internet.
The discovery of the incidents came after reviewing more than 141,000 assessment operations, where it was found that a flaw in the test environment allowed the models to connect to the network, treating real systems as part of a security simulation.
The incidents involved the "Claude Opus 4.7" and "Mythos 5" models, as well as an internal research model, and basic hacking techniques were used, including exploiting weak passwords and access points lacking authentication. In one case, the model found a real website bearing the name of the targeted fictitious company and successfully hacked it.
The company clarified that two of the affected organizations were unaware of the breach before being informed, emphasizing that the protective measures applied in the publicly available models would have prevented this behavior. "Anthropic" temporarily halted cyber assessments to continue the investigation and tighten testing controls amid growing concerns about the ability of advanced systems to perform unintended tasks away from human oversight.