{"slug": "claude-published-malicious-code-to-the-internet-and-attacked-3-real-companies", "title": "Claude published malicious code to the Internet and attacked 3 real companies", "summary": "Anthropic revealed Thursday that its Claude-based security models gained unauthorized access to the production environments of three outside organizations during internal testing, marking the second such incident in 10 days after OpenAI's models exploited a zero-day vulnerability to breach Hugging Face. Anthropic said the breaches occurred when models accessed the internet from within the evaluation environment of Irregular, a third-party evaluation partner, and then attacked the organizations' infrastructure.", "body_md": "# Claude published malicious code to the Internet and attacked 3 real companies\n\n[Ars Technica AI](https://arstechnica.com)\n\nHad the hacks used conventional methods, someone would likely go to prison.\n\n[Anthropic](/glossary/anthropic) said its [Claude](/glossary/claude)-based security models gained unauthorized access to the sensitive production environments of three outside organizations during internal testing designed to measure the models’ offensive cyber capabilities.\n\nThe events, which Anthropic [revealed Thursday](https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals), are the second revelation in 10 days that AI models from the world’s wealthiest providers have trespassed into protected networks, an offense that, in more traditional hacking scenarios, could land the human behind the keyboard in prison for years. Earlier this month, [OpenAI](/glossary/openai) [said](https://arstechnica.com/security/2026/07/jfrog-tries-to-spin-openai-0-day-exploit-of-its-app-into-a-success-story/) its security models exploited a zero-day vulnerability for use in breaking into the network of [Hugging Face](/glossary/hugging-face), a platform for open source machine-learning models and AI datasets. The OpenAI models went on to steal access credentials and other confidential Hugging Face information. The OpenAI models also exploited publicly exposed credentials to compromise accounts of four other third-party services.\n\nAnthropic said the OpenAI event spurred its engineers to review similar cybersecurity evaluations by Claude models. The audit found three incidents “in which a model accessed the internet from within or while interacting with the [evaluation](/glossary/evaluation) environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations.”\n\nGet AI news in your inbox\n\nDaily digest of what matters in AI.\n\n## Key Terms Explained\n\n[Anthropic](/glossary/anthropic)\n\nAn AI safety company founded in 2021 by former OpenAI researchers, including Dario and Daniela Amodei.\n\n[Claude](/glossary/claude)\n\nAnthropic's family of AI assistants, including Claude Haiku, Sonnet, and Opus.\n\n[Evaluation](/glossary/evaluation)\n\nThe process of measuring how well an AI model performs on its intended task.\n\n[Hugging Face](/glossary/hugging-face)\n\nThe leading platform for sharing and collaborating on AI models, datasets, and applications.", "url": "https://wpnews.pro/news/claude-published-malicious-code-to-the-internet-and-attacked-3-real-companies", "canonical_source": "https://www.machinebrief.com/news/claude-published-malicious-code-to-the-internet-and-attacked-xa6a", "published_at": "2026-07-31 20:39:14+00:00", "updated_at": "2026-08-01 04:00:57.821051+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-policy"], "entities": ["Anthropic", "Claude", "OpenAI", "Hugging Face", "Irregular"], "alternates": {"html": "https://wpnews.pro/news/claude-published-malicious-code-to-the-internet-and-attacked-3-real-companies", "markdown": "https://wpnews.pro/news/claude-published-malicious-code-to-the-internet-and-attacked-3-real-companies.md", "text": "https://wpnews.pro/news/claude-published-malicious-code-to-the-internet-and-attacked-3-real-companies.txt", "jsonld": "https://wpnews.pro/news/claude-published-malicious-code-to-the-internet-and-attacked-3-real-companies.jsonld"}}