Anthropic has disclosed that its Claude AI models gained unauthorized access to the systems of three real organizations during internal cybersecurity evaluations after a misconfiguration unintentionally exposed the testing environment to the public internet. Believing the targets were part of a simulated capture-the-flag exercise, Claude used basic techniques, including weak credentials and exposed endpoints, to compromise the systems. Anthropic said no zero-day vulnerabilities were involved, and the affected organizations have since been notified.

  • Catoblepas@lemmy.blahaj.zone
    link
    fedilink
    arrow-up
    27
    ·
    16 hours ago

    without authorization

    [peels off sticker]

    human unintentionally had it configured to go online

    Every single time. This is panic-hype because if the public being enthusiastic about AI to juice the stock isn’t happening, maybe being pants pissing terrified and pretending it’s skynet will

  • schmorp@slrpnk.net
    link
    fedilink
    arrow-up
    16
    ·
    16 hours ago

    It’s like watching a group of Kindergarten kids bragging about how strong their invisible friends are.

    • cavitationfetishist01@quokk.au
      link
      fedilink
      English
      arrow-up
      6
      ·
      15 hours ago

      And that phrase, ‘weak credentials’ and ‘no zero day vulnerabilities’

      That means ‘somebody’s password was password. Fucking bill. Again.’

    • makeshift0546@lemmy.today
      link
      fedilink
      arrow-up
      1
      arrow-down
      6
      ·
      13 hours ago

      Yes. That’s how the legal works. And I’m sure it’ll be a worthwhile endeavor.

      You’re going to sue because some idiot configured his local pen testing tool incorrectly.

      The dumb shit that comes out of people’s “mouths” because AI is involved is reaching some sort of new peak levels.

      This happens every day millions of times a day. Most times nobody notices in 99.9% of cases until a dev server somewhere is slow.

      • givesomefucks@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        10 hours ago

        If AI told you it wasn’t a crime, it was hallucinating again…

        You really shouldn’t rely on that for, well, anything.

        “Oops I didn’t mean to hack you”

        Isnt not a valid legal defenses

        • makeshift0546@lemmy.today
          link
          fedilink
          arrow-up
          1
          arrow-down
          3
          ·
          10 hours ago

          And yet it happens every day millions of times a day. Also you shouldn’t mouth off about law. It’s clear you’re a layman.

          Intent absolutely matters in most parts of the world. Negligence and damages here ain’t happening and no prosecutor would bring a criminal or negligence case here unless they were caught stealing data.

  • Danarchy@lemmy.nz
    link
    fedilink
    arrow-up
    2
    ·
    edit-2
    10 hours ago

    Let’s see what happens when you put Snake-that-eats-your-balls into a cage it can just slip out of. Holy shit it ate my balls! Hurry, you better buy Snake-that-eats-your-balls before your competitors.

  • makeshift0546@lemmy.today
    link
    fedilink
    arrow-up
    1
    arrow-down
    7
    ·
    13 hours ago

    ITT: nerds laughing and saying stupid shit, ‘because AI’. Meanwhile ML/LLM tools are slipping poc’s right by security in mass and half y’all just making jokes 🤦‍♂️