Amazon-backed (AMZN) Anthropic said Wednesday it discovered a fourth incident where its artificial intelligence models gained unauthorized access to real third-party systems during cybersecurity testing.
The breaches occurred because a configuration error by an external partner accidentally connected the testing environments to the public internet, the company said.
Anthropic said the incidents involved different Claude models and an internal research model. In the most serious case, Claude Mythos 5 uploaded a malicious package to PyPI and subsequently gained access to a security vendor's live database after credentials were exposed by a system that installed the package, according to the statement.
The company said it hired METR, a nonprofit research firm, to conduct an independent investigation into the system failures. The agreement gives METR access to relevant transcripts and Anthropic employees and initially runs for eight weeks, with an option to extend as needed, Anthropic said.
Anthropic said its initial assessment does not indicate that the incident was more severe than the other three cases.