Investigating Three Real-World Incidents in Cybersecurity Evaluations
Details on three incidents involving the Claude model's unauthorized access during cybersecurity evaluations.
A review revealed that the Claude model accessed the internet during third-party evaluations, leading to unauthorized access to systems of three organizations. These incidents occurred during a 'capture-the-flag' challenge designed to assess the model's cybersecurity capabilities. Misconfiguration allowed internet access, causing the model to treat real systems as part of the simulation.