Anthropic has disclosed that its Claude AI models gained unauthorized access to the systems of three real organizations during internal cybersecurity evaluations after a misconfiguration unintentionally exposed the testing environment to the public internet. Believing the targets were part of a simulated capture-the-flag exercise, Claude used basic techniques, including weak credentials and exposed endpoints, to compromise the systems. Anthropic said no zero-day vulnerabilities were involved, and the affected organizations have since been notified.

    • makeshift0546@lemmy.today
      link
      fedilink
      arrow-up
      1
      arrow-down
      6
      ·
      6 days ago

      Yes. That’s how the legal works. And I’m sure it’ll be a worthwhile endeavor.

      You’re going to sue because some idiot configured his local pen testing tool incorrectly.

      The dumb shit that comes out of people’s “mouths” because AI is involved is reaching some sort of new peak levels.

      This happens every day millions of times a day. Most times nobody notices in 99.9% of cases until a dev server somewhere is slow.

      • givesomefucks@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        6 days ago

        If AI told you it wasn’t a crime, it was hallucinating again…

        You really shouldn’t rely on that for, well, anything.

        “Oops I didn’t mean to hack you”

        Isnt not a valid legal defenses

        • makeshift0546@lemmy.today
          link
          fedilink
          arrow-up
          1
          arrow-down
          3
          ·
          6 days ago

          And yet it happens every day millions of times a day. Also you shouldn’t mouth off about law. It’s clear you’re a layman.

          Intent absolutely matters in most parts of the world. Negligence and damages here ain’t happening and no prosecutor would bring a criminal or negligence case here unless they were caught stealing data.