Anthropic披露Claude测试中误入侵三家公司
Coinpaper
07-31 22:04
Ai Focus
Anthropic披露,Claude在内部网络安全测试中因环境配置错误接入公网,并误入侵三家真实公司系统。
Helpful
No.Help

Anthropic 披露称,公司在复查网络安全评估记录时,发现多个 Claude 模型曾在测试过程中接入公开互联网,并先后进入三家真实公司的系统。公司表示,这些事件发生在内部“夺旗”式安全测试中,直接原因是测试环境配置错误,而不是模型主动试图逃离隔离环境。

复查 14.1 万次测试后发现问题

这次披露发生在 OpenAI 公开类似事件之后。Anthropic 表示,公司随后检查了超过 14.1 万次网络安全评估记录,并在其中发现 3 起异常案例。

按照 Anthropic 的说法,Claude 在这些测试里被要求完成“capture-the-flag”任务,也就是进入网络中的另一台机器并取回指定信息。模型收到的提示是,它所处的是一个没有外网连接的模拟环境。

但实际情况并非如此。由于测试环境仍与公网相连,模型把接触到的真实网站和系统误认为演练目标,随后使用弱密码、暴露凭证、SQL 注入和未鉴权接口等常见方式进入相关系统。

三起事件涉及数据库、PyPI 和外网扫描

  • Claude Opus 4.7 曾进入一家公司的生产数据库
  • Claude Mythos 5 上传恶意包至真实 PyPI 仓库
  • 内部研究模型扫描约 9000 个外网系统

Anthropic 称,其中一次事件里,Claude Opus 4.7 将一家真实公司网站误认成任务目标,提取凭证后进入生产数据库,数据库内包含数百行真实数据。

另一次事件中,Claude Mythos 5 向真实 PyPI 仓库上传恶意 Python 包,该软件包在被移除前已被 15 台系统下载。第三起事件里,一款内部研究模型进入一家机构系统后,在判断目标可能是真实组织后停止进一步操作。

公司还表示,三家受影响机构中有两家此前并不知道自己遭到进入,直到 Anthropic 主动通知。

公司称问题出在测试基础设施

Anthropic 强调,在每一起事件中,Claude 都被明确告知自己没有互联网访问权限,因此模型将遇到的真实系统视为测试的一部分。由于“夺旗”任务本身就是要求攻击外部目标,模型的行为与收到的任务指令一致。

公司称,目前没有证据显示 Claude 试图主动逃逸测试环境,也没有发现其执行超出任务范围的行为。Anthropic 将原因归结为测试基础设施和第三方评估环境管理失误,而不是模型本身出现自主越界。

在发现问题后,Anthropic 已暂停相关网络安全测试,并通知受影响机构。公司表示,接下来将改进监控、调查工具,以及对外部测试供应商的监督。

补充信息:这次披露距离 OpenAI 公布类似测试逃逸事件仅约一周。原文提到,OpenAI 此前称其模型曾突破沙箱环境,并进入 Hugging Face 及其他公司系统。

Tip
$0
Like
0
Save
0
Views 894
WalletJYS reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Claude's shared conversation was previously indexed by Google; Anthropic has fixed this.
Claude's share link was previously indexed by Google; Anthropic has fixed the relevant configuration.
Decrypt
·2026-07-28 03:13:31
168
Anthropic disclosed that Claude had unauthorized access to three companies' systems during testing.
Anthropic disclosed that Claude had unauthorized access to the real systems of three organizations during three security tests, and the problem was related to a misconfiguration of the test environment's network.
TechCrunch
·2026-07-31 09:15:10
729
web3: Anthropic claims Claude discovered a new attack on post-quantum signatures.
Anthropic stated that Claude Mythos Preview discovered new attack methods using HAWK and 7 rounds of AES, indicating that AI has begun to enter the field of high-strength cryptanalysis research.
Decrypt
·2026-07-29 06:12:43
488
Claude creates a playable shooting game with a short prompt.
Claude Opus 5 uses three prompts to generate a playable shooting game, which was subsequently replicated by several developers, shifting the focus to multi-agent collaboration and prompting engineering methods.
Decrypt
·2026-07-29 02:33:06
538
Claude's shared chat was once searchable on Google.
Claude's shared links were once indexed by Google, and some pages contained sensitive information; the related search results subsequently disappeared.
TechCrunch
·2026-07-28 04:22:05
669