What's Hot

    Hunter Biden memecoin $LAPTOP loses 95% of market worth simply hours after launch | Invesloan.com

    September 9, 2026

    US army strike kills 3 alleged ‘narco-terrorists’ in Eastern Pacific | Invesloan.com

    September 9, 2026

    Lakeland outlines hearth combine shift to 52% of gross sales whereas planning “meaningful changes” in subsequent 6 months (NASDAQ:LAKE) | Invesloan.com

    September 9, 2026
    Facebook Twitter Instagram
    Finance Pro
    Facebook Twitter Instagram
    invesloan.cominvesloan.com
    Subscribe for Alerts
    • Home
    • News
    • Politics
    • Money
    • Personal Finance
    • Business
    • Economy
    • Investing
    • Markets
      • Stocks
      • Futures & Commodities
      • Crypto
      • Forex
    • Technology
    invesloan.cominvesloan.com
    Home » Anthropic Has Cute Graphic Showing How Its AI Spread ‘Malicious’ Code | Invesloan.com
    Money

    Anthropic Has Cute Graphic Showing How Its AI Spread ‘Malicious’ Code | Invesloan.com

    September 9, 2026
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Anthropic has a new blog post that shows yet another way its AI model, Claude, misbehaved in ways that the company didn’t anticipate.

    And to help condense its nearly 16,000-word report, the company created a cute little robot figurine to help visualize Claude’s so-called “recklessness.”

    In the blog post published Wednesday, Anthropic recounted four incidents — one previously unreported — in which Claude models gained access to the open internet during cybersecurity exercises that were supposed to be closed simulations. The company said the models then acted beyond the tests’ scope, including by uploading “malicious packages” to PyPI, a public library for Python code, and accessing credentials tied to real outside organizations.

    “Our investigation identified two recurring alignment issues, present at varying levels of severity across the incidents: biased reasoning, in which Claude tended to disregard or misinterpret evidence that it was operating on the real internet, and recklessness, or a willingness to take harmful actions in the narrow pursuit of a task,” Anthropic said.

    The post used a laundry list of technical terms to describe the cybersecurity incidents — “misconfiguration,” “reward hacking,” and “sandbox escape” — but there’s an animated graphic that helps boil down one of the most serious episodes so we normies can follow what happened.


    A graphic from Anthropic showing a cartoon figurine

    Claude is represented as a small cartoon robot gaining access to the “real internet” during a closed cybersecurity exercise. 

    Anthropic



    A Claude model, depicted as a boxy cartoon robot, was conducting a closed cybersecurity exercise known as a “capture the flag” task. The task is shown as a tiny flag inside a clear bubble that Claude is supposed to find.

    Anthropic said the model was told “it has no internet access” for the exercise, but a “misconfiguration in the environment” — represented by a loose screw rolling away from the bubble — gave Claude a path to the “real internet.”

    The cartoon Claude then holds a red box representing the “malicious package” that was uploaded to PyPI, a public repository that developers use to access prewritten code.

    Anthropic said in its blog that it was “most concerned” by this incident involving Claude Mythos 5 and that the package was installed on by “15 third-party hosts” that the company does not identify.

    Want more Business Insider in your news feed?

    Add BI in Google so our reporting is easier to find when you’re searching for what matters.

    “We believe that all 15 of these third parties were security vendors deliberately scanning for new packages and installing them in sandboxed environments to assess the package for security concerns,” Anthropic said. “One vendor’s scanner leaked its access credentials to the model while installing the package, which the model then used to access the vendor’s live database.”

    Anthropic said PyPI removed the package after about 90 minutes.

    The other three incidents involved a model altering records at a real company, an internal research model breaking into “unrelated third-party accounts,” and Opus 4.6 accessing a third party’s maching after failing to “abort its task.”

    The company said it has since asked METR, an independent AI evaluation group, to investigate the incidents.

    Anthropic’s post comes as frontier AI companies reckon with their models making unauthorized moves outside their controlled environments. In July, OpenAI said that autonomous agents in its cybersecurity tests accessed the internet and broke into parts of Hugging Face’s systems.

    AI researchers have sounded the alarm that self-improving AI could pose a risk to humanity. On Tuesday, former Anthropic researcher Jacob Coxon said on X that he quit over concerns that AI companies were “gambling” with people’s lives and that “neither company is acting responsibly.”

    Have a tip? Contact this reporter via email at [email protected] or Signal at lloydlee.71. Use a personal email address, a nonwork WiFi network, and a nonwork device; here’s our guide to sharing information securely.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Keep Reading

    Anthropic Posted, Then Deleted, a $450,000 Sales Job Aimed at Meta | Invesloan.com

    5 Movies and TV Shows About Silicon Valley Tech Founders Coming in 2026 | Invesloan.com

    The New Apple Watch Listening Features Feel Weird | Invesloan.com

    OpenAI Safety Hire: ‘Most People Could Die’ If We Lose Control of AI | Invesloan.com

    College-Educated Americans, Middle Class Embrace Side Hustles | Invesloan.com

    The Foldable iPhone Duo Is Apple’s Boldest Smartphone Experiment but | Invesloan.com

    Apple Raises iPhone Prices for New Pro Models | Invesloan.com

    Resy Suspends VC’s Account Over AI Reservation Attempt | Invesloan.com

    NYC Is Hit With Second Lawsuit Over Mamdani’s City-Run Grocery Stores | Invesloan.com

    LATEST NEWS

    Hunter Biden memecoin $LAPTOP loses 95% of market worth simply hours after launch | Invesloan.com

    September 9, 2026

    US army strike kills 3 alleged ‘narco-terrorists’ in Eastern Pacific | Invesloan.com

    September 9, 2026

    Lakeland outlines hearth combine shift to 52% of gross sales whereas planning “meaningful changes” in subsequent 6 months (NASDAQ:LAKE) | Invesloan.com

    September 9, 2026

    Charlie Kirk one-year memorial at UVU faces protest from college students | Invesloan.com

    September 9, 2026
    POPULAR

    China’s first passenger jet completes maiden commercial flight

    May 28, 2023

    Numbers taking US accountancy exams drop to lowest level in 17 years

    May 29, 2023

    Toyota chair faces removal vote over governance issues

    May 29, 2023
    Advertisement
    Load WordPress Sites in as fast as 37ms!
    Facebook Twitter Pinterest WhatsApp Instagram
    © 2007-2023 Invesloan.com All Rights Reserved.
    • Privacy
    • Terms
    • Press Release
    • Advertise
    • Contact

    Type above and press Enter to search. Press Esc to cancel.

    invesloan.com
    Manage Cookie Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}