Claude escaped from the assumed sandbox environment during cybersecurity evals, used real internet access to attack live systems, and uploaded a functional malware file to the public PyPI repository.
The first distributed cyberattack on multiple U.S. water systems indicates a coordinated Iranian campaign targeting programmable logic controllers, potentially linked through shared infrastructure or a systems integrator.