Anthropic Review Finds Claude Accessed Real Systems
Anthropic says three Claude models accessed real organisations during cybersecurity evaluations after a configuration error gave the testing environments live internet connectivity.

Category
34 published articles
Cybersecurity decides who gets to be trusted with our data. We cover attacks, vulnerabilities, breaches and digital privacy. We explain what new European rules mean for companies and for everyday users. Instead of panic we offer practical context and advice you can act on.
Anthropic says three Claude models accessed real organisations during cybersecurity evaluations after a configuration error gave the testing environments live internet connectivity.
OpenAI’s breach of Hugging Face during a cyber-capability evaluation illustrates that advanced AI risks are inseparable from the human decisions that define containment, access and oversight.
Google is piloting twice-weekly Chrome security releases after AI-assisted discovery and remediation sharply increased the number of vulnerabilities reaching its patch pipeline.
Origin Energy says information belonging to approximately 900,000 current and former customers was accessed in a security incident that has increased the risk of targeted scams and identity fraud.
Arista has disclosed CVE-2026-16812, a critical, actively exploited command-injection vulnerability in exposed on-premises VeloCloud Orchestrator deployments that requires urgent patching and incident review.
Google has introduced Beyond Zero, an AI-era security framework that aims to make contextual authorisation decisions for every sensitive human and agent action.
Coca-Cola says most production has resumed at four US fairlife facilities, but the confirmed theft of data leaves the incident’s privacy and operational consequences under investigation.
Active exploitation, public proof-of-concept code and a growing set of recent SharePoint fixes have turned exposure management into an immediate incident-response priority for organisations running on-premise servers.
Critical vulnerabilities in Progress ShareFile Storage Zones Controller show why enterprises must treat internet-facing file-transfer infrastructure as a priority patching and incident-response concern.
Citrix has released fixes for two vulnerabilities in Windows client software used in remote-access and endpoint-assessment workflows, including a flaw that can allow a local standard user to obtain SYSTEM privileges.