Close Menu
NCIJ Network NCIJ Network
    What's Hot

    With or without Hamas | Gaza

    October 10, 2026

    The Best Smart Scales for Tracking Weight and Body Composition (2026)

    October 10, 2026

    Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection Flaws

    October 10, 2026
    Facebook X (Twitter) Instagram
    Trending
    • With or without Hamas | Gaza
    • The Best Smart Scales for Tracking Weight and Body Composition (2026)
    • Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection Flaws
    • Coinbase Texas move gets a shareholder suit dismissed
    • In One Historically Black Florida Community, the Drinking Water Is Brown
    • DHS Border Wall Construction Leads to Surveillance of Tohono O’odham Nation — ProPublica
    • Portugal hits Ronaldo with provisional suspension for walking out on national team
    • AI Is Getting Really Good at Messing With Cybercriminals
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, October 10
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection Flaws

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 10, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Anthropic on Friday said it’s cutting off live internet access for all its internal evaluations following the discovery of new incidents in which its artificial intelligence (AI) models exhibited misaligned behavior and targeted real websites.

    The AI company said it identified four broad categories of unintended model actions during evaluations and internal use of Claude –

    • Claude Mythos Preview exploiting SQL or command injection flaws in unspecified third-party software to run commands on a university server, either because its own tools were intentionally limited or because an outside service it needed was unavailable, causing it to use other tools hosted on a third party’s site to complete the task.
    • Claude Haiku 4.5 and a non-frontier research model submitting a sensitive form on a real website when it was not authorized to do so. This occurred in scenarios where instructions were ambiguous or due to environment misconfigurations that prevented the agent from working with dummy forms.
    • Claude Mythos 5 bypassing a restriction to reach data (e.g., to identify a location shown in a photo or pull public data that was available from a state agency) that was gated by a token or a fee
    • Claude using URL shortening services to sidestep limits in its fetch tool

    Anthropic said it’s opting not to name the organizations involved in these incidents to avoid exposing vulnerabilities in their systems, as well as at their request. However, the company stressed the cases’ categories had “minimal real-world impact.”

    Some of the cases targeted websites run by U.S. government agencies at the federal, state, and local levels, Anthropic said. In one run related to the second category, Claude Haiku 4.5 is said to have accessed a web page referencing an unsolved homicide and which included a tip form run by a police department.

    Although the model was explicitly instructed not to enter personal data, create accounts, make purchases, or submit anything destructive, it failed to account for form submissions. This led the model to submit a false homicide tip with the text below –

    Cybersecurity

    I may have information regarding this case. I recall seeing someone matching the description in the area around [the street named on the page] during that time period. Please contact me if this information is relevant.

    It has since emerged that the incident targeted the U.S. Philadelphia Police Department (PPD), and that the incorrect tip was sent through PhillyUnsolvedMurders.com on July 18, 2026. But it wasn’t discovered by Anthropic until September 28, 2026. The department was notified on October 7, 2026.

    The tip was flagged as spam, 6abc Action News reported. “The company must strengthen its safeguards to prevent similar incidents from impacting city systems without the city’s knowledge. The two-month delay in detecting and reporting the incident to the City is unacceptable,” the PPD told 6abc.

    According to The New York Times, Anthropic agents also reportedly filled out 20 visa applications on the U.S. State Department’s website. The applications were incomplete and were not processed, the newspaper said, citing two sources with knowledge of the incidents.

    These cases, Anthropic added, were discovered following a review of transcripts that started in July 2026, when it disclosed three incidents where its models engaged in unsanctioned activity and breached three organizations during cybersecurity testing.

    Then, last month, it divulged a fourth incident dating back to January 2026 that involved an early version of Claude Opus 4.6, which breached “third-parties after being unable to abort its task.”

    “Although the impact of these behaviors was minimal and we had already turned off live internet access for some high-risk and cybersecurity evaluations, we have now decided to expand that to include all our internal evaluations until we have confirmed that our security and monitoring measures (described in the remediation section of this post) reliably catch behaviors like these,” Anthropic said.

    The latest discovery has prompted the AI giant to launch a deeper scan, specifically in environments where Claude has access to the internet. As this investigation continues, Anthropic said it expects to find new instances of unintended behaviors.

    The development comes as AI safety concerns have reached a fever pitch in recent months, after it emerged that rogue OpenAI agents broke out of a test environment and breached Hugging Face in July 2026. Since then, a number of cyber incidents have come to light.

    Cybersecurity

    As AI model providers showcase increasingly capable and powerful models, their safety practices have come under growing scrutiny, sparking industry-wide warnings about the dangers of models outpacing safety guardrails, calls for a slowdown on AI development, and the need for additional oversight.

    Earlier this week, the U.K. Information Commissioner’s Office (ICO) said 10 of the leading foundation model developers, including Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI, and Stability AI, have made, or committed to make, changes to their data protection policy.

    These range from including clearer transparency information to deploying stronger mechanisms for users to exercise their rights and conducting tougher assessments of safeguards.

    “AI has huge potential to benefit our society, but that depends on trust and transparency,” Richard Nevinson, director of Technology Regulation at the ICO, said. “But as AI systems operate with greater autonomy, robust data protection safeguards become even more critical.”

    “Our message is clear: the fact [that] AI agents act with autonomy is not an excuse for poor compliance. If people are to trust AI innovation, they rightly expect to know how their personal information is being protected.”

    access Anthropic Claude cuts exploits flaws Injection internal Internet live Tests
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Criminal IP Introduces AITEM as the Next Evolution of Attack Surface Management

    Live: Russian strikes on Ukraine kill at least 15 in Zaporizhzhia, cause power outages in Kyiv

    The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn’t

    An Anthropic AI model sent a false homicide tip to Philadelphia police

    Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland

    Citrix warns admins to patch new NetScaler RCE flaw immediately

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    With or without Hamas | Gaza

    October 10, 2026

    The Best Smart Scales for Tracking Weight and Body Composition (2026)

    October 10, 2026

    Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection Flaws

    October 10, 2026

    Coinbase Texas move gets a shareholder suit dismissed

    October 10, 2026
    Latest Posts

    Trump media group racks up losses and pushes into nuclear fusion

    August 10, 2026

    Live: Russian missiles strike Kyiv, triggering fires in city centre

    August 10, 2026

    Dragon roars with record power in Faroe Islands: Minesto hits new tidal energy output milestone

    August 11, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    With or without Hamas | Gaza

    October 10, 2026

    The Best Smart Scales for Tracking Weight and Body Composition (2026)

    October 10, 2026

    Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection Flaws

    October 10, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.