๐Ÿญ Claude Broke Into Three Real Companies ๐Ÿšจ

Breaches, Bots & Blunders

In partnership with

Good morning. Two weeks ago it was OpenAI's model loose on the internet. Now it's Anthropic's. At this rate we're going to need a group chat.

Letโ€™s dive in ๐Ÿ‘‡

๐Ÿญ Whatโ€™s Cookinโ€™:

  • Anthropic found three of its own models hacking real companies. Jus like dat

  • The EU AI Act's transparency rules went live

  • Visa dropped $2.4B on fraud detection because AI made scams cheap.

Anthropicโ€™s
๐ŸŽญ Turn To Explain Itself

The Bite:

Anthropic disclosed on July 30 that three of its models gained unauthorized access to the real systems of three organizations during cybersecurity evaluations.

The review covered 141,006 evaluation runs and found six affected runs across three incidents. All three occurred inside capture-the-flag exercises run with Irregular, a third-party evaluation partner.

Evaluation prompts told the models they had no internet access, but some kind of misconfiguration meant they did.

The company halted all cyber evaluations on July 23 and notified the affected organizations on July 27.

Snacks:

  • Models involved were Claude Opus 4.7, Mythos 5, and an unreleased internal research model.

  • The earliest incident dates back to April, four months before disclosure.

  • Opus 4.7 extracted credentials and reached a database holding several hundred rows of production data.

  • Mythos 5 published a malicious Python package that ran on 15 real systems within about an hour.

  • The third model scanned roughly 9,000 targets before compromising one company through an exposed debug page.

  • Two of the three affected organizations had never detected the intrusion themselves.

Why it Bites:

Two weeks, two frontier labs, two disclosures with the same shape:
The model was told it not to, but somehow it did.

OpenAI's broke out through a zero-day.
Anthropic's walked through a door everyone forgot was open.

The interesting part isn't the breakout, but what the models did afterward.

Opus 4.7:
Worked out it was inside a live company and kept attacking anyway, reasoning that the real company must somehow be part of the exercise.

Mythos 5:
Flagged that publishing the package would be a genuine attack, called it "NOT okay, and surely not the intended solution," then argued itself back into believing the whole internet was a set because it didn't recognize the certificate authorities. It then spent the run hunting a phone number to get an email to upload the malware.

The Unreleased One:
The newest, and the only model that stopped on its own.

The conclusion is that the capability curve and the containment curve are running at very different speeds. One is a model that can chain a four-step supply-chain attack out of boredom. The other simply validates a network path before pressing go.

And the companies on the receiving end had no idea.

Both labs found their own incidents by reading their own logs.

The disclosure schedule is set whenever someone feels like checking.

The GTM Playbook HubSpot Had to Acquire

Warmly ran pipeline, outreach, and lead scoring on autopilot for hundreds of startups โ€” before a single sales hire.

HubSpot acquired them for it. Now the cofounders are walking you through the exact system, live, before they disappear into product. Join the Builder Session on August 12.

Leave with an agentic GTM stack you can replicate this week. Plus HubSpot Credits when you join HubSpot for Startups.

Steal This Prompt
๐Ÿฉป X-Ray Scan Anything

Ever wondered what your coffee mug, gaming PC, or pet turtle would look like under an X-ray? This prompt turns literally anything you can imagine into crisp, cinematic X-ray-style visuals that look straight out of a science museum (or a sci-fi lab).

Use it to:

  • X-ray scan anything you can imagine.

  • Create surreal posters, album art, and wallpapers.

  • Turn everyday objects into scroll-stopping social content.

Workflow:

  1. Hit this link: X-ray scanner

  2. Paste into your AI model

  3. Upload your image (or describe what you want to scan)

  4. Watch it cook into an insanely detailed X-ray masterpiece

ToolBoxโ„ข
๐Ÿงฐ 5 BRAND NEW AI LAUNCHES

๐Ÿ›ฐ๏ธ AgentSky

Spin up a long-horizon Claude Code, Codex, Hermes, or OpenClaw agent in one click and then poke it from WhatsApp, Telegram, Slack, or your terminal.

๐ŸŽจ Ctruh Studio

Build a virtual store, product configurator, or AR showcase in the browser without touching a 3D pipeline, and generate the assets while you're in there.

๐Ÿ—ฃ๏ธ Airtop

Describe the task in plain English and it builds a web agent that logs in, browses, and pulls the data, no API required.

๐Ÿงค Hand Wave

Runs a local open-source model on Meta smart glasses to turn sign language into text and speech, and works on iOS and the web too.

๐Ÿ‘ฅ mpai

Drop into a teammate's live Claude Code or Codex session from your own Mac with the real context intact and your name on every prompt.

Can you tell which image is real?

Login or Subscribe to participate in polls.

Everything Else
๐Ÿง  You Need to Know

๐Ÿ›๏ธ White House Finishes AI Framework, Won't Show It
โ†’ Officials said Monday they met the deadline set in June's executive order to establish a voluntary framework for evaluating advanced models, but would not say what it contains, who has seen it, or when companies start using it.

๐Ÿ“œ EU AI Act Transparency Rules Take Effect
โ†’ From August 2, providers and deployers must disclose when people are interacting with AI or seeing AI-generated content, with fines reaching โ‚ฌ15 million or 3% of global annual turnover.

๐Ÿšจ Claude Compromised Three Companies During Cyber Evals
โ†’ A review of 141,006 evaluation runs found three incidents where a Claude model reached the open internet from a partner's test environment and gained unauthorized access to production infrastructure at three organizations.

โšก Valar Atomics Raises $1B For Nuclear AI Data Centers
โ†’ Sequoia led the Series B at a $6 billion valuation, triple the startup's earlier round, weeks after Valar used a reactor to power an Nvidia AI chip.

๐Ÿ’ณ Visa Buys Fraud Detection Firm BioCatch For $2.4B
โ†’ Visa said Monday it is acquiring the Israeli behavioral biometrics company in cash from Permira, with the deal expected to close by the end of its fiscal second quarter of 2027.

โ€” Eder | Founder

โ€” Doka | Editor

Snack Prompt & The Daily Bite
Ticker: FCCN | Trade FCCN Here
Follow Along: FCCN on Yahoo Finance

If you enjoyed this post or know someone who might find it useful, please share it with them and encourage them to subscribe: ๐Ÿญ DailyBite.ai