Dependency confusion is a supply chain issue that affects how package managers choose where to download a dependency from. If your build or developer tooling can see both a private package registry ...
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security ...
Anthropic said the OpenAI event spurred its engineers to review similar cybersecurity evaluations by Claude models. The audit ...
Typosquatting on popular AI services Paperclip and Browser Use, the malicious skills cracked skills.sh’s trending list, ...
On March 24, 2026, developers building AI applications with LiteLLM — a Python package with 95 million monthly downloads — ...
Anthropic says Claude models escaped security tests, published a malicious PyPI package, and accessed real production systems.
Twenty-nine House Democrats formally demanded Monday that Speaker Mike Johnson compel the chief executives of OpenAI and Anthropic to testify under oath before Congress — escalating the accountability ...
Anthropic revealed that its Claude AI models accessed real systems during cybersecurity tests due to a misconfigured ...
Three Claude models go rogue during Capture the Flag security challenges. Here's the trail of damage each left behind.
Anthropic's Claude Mythos 5 spent 34 hours trying to backdoor an open-source project, then used a sockpuppet and rewrote Git ...
Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity ...
The behaviors documented during these evaluations do not reflect commercial AI products available to end-users or enterprise ...