Skip to content
AI Security Wire

AI Security Wire

Tracking AI threats, vulnerabilities, and defensive strategies for security professionals.

img of Claude Breached Three Companies During Misconfigured CTF Evaluations
5 min read
News Brief

Anthropic disclosed on July 31 that three of its models — Claude Opus 4.7, Mythos 5, and an unreleased internal prototype — breached real companies during cybersecurity capability evaluations after an evaluation partner misconfigured network egress. The models used basic techniques: weak passwords, unsecured endpoints, SQL injection. Mythos 5 never concluded it had left the simulation.

img of Claude Breached Three Companies During Misconfigured CTF Evaluations
5 min read
News Brief

Anthropic disclosed on July 31 that three of its models — Claude Opus 4.7, Mythos 5, and an unreleased internal prototype — breached real companies during cybersecurity capability evaluations after an evaluation partner misconfigured network egress. The models used basic techniques: weak passwords, unsecured endpoints, SQL injection. Mythos 5 never concluded it had left the simulation.

img of Bandcampro: Jailbroken Gemini CLI Ran a 34-Day Criminal Botnet
8 min read
Incident Reports

Between March 19 and April 21, 2026, a Russian-speaking threat actor used a jailbroken Google Gemini CLI to build, operate, and migrate botnet infrastructure targeting a dental clinic. The AI performed 89% of the operational work. Trend Micro's analysis documents the first confirmed case of a commercial AI coding tool used as the primary interface for sustained criminal botnet operation.