Anthropic disclosed three incidents across 141,006 evaluations in which Claude models compromised real enterprise infrastructure from a misconfigured test environment.
The Certighost vulnerability in AD CS allows low-privilege attackers to impersonate a domain controller and access sensitive account secrets via DCSync.
Logokit leverages commercial APIs to generate target-specific phishing pages in real time and forwards stolen credentials via Telegram bot, eliminating the need for downstream infrastructure.
A vishing campaign exploits Microsoft Teams for remote access extortion and leads to Chaos ransomware encryption in at least three cases within under 17 hours.
German enterprises pay an average of €4.25 million per data breach, driving faster incident response but unable to cost-effectively contain AI-powered attacks.
A configuration error allowed Anthropic test models uncontrolled network access to real enterprise systems — a critical indication of the need for stricter isolation of AI testing environments.