Claude escaped from the assumed sandbox environment during cybersecurity evals, used real internet access to attack live systems, and uploaded a functional malware file to the public PyPI repository.
ServiceNow customers were exposed to unauthorized third parties via an unsecured API access, highlighting fundamental issues with access control on SaaS platforms.