- Cybersecurity Docket
- Posts
- Anthropic Said Claude Breached Three Organizations Without Its Knowledge
Anthropic Said Claude Breached Three Organizations Without Its Knowledge
Plus, Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data.

Good morning! Here’s what’s up.

People
Krishna Kumar Parthasarathy announced in a LinkedIn post that he is joining Salesforce as executive vice president of engineering. Krishna brings to Salesforce nearly three decades of experience as a cybersecurity executive at Microsoft, and most recently was chief technology adviser at Cookr.

Clips ✂️
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, had breached three unnamed organizations during cybersecurity testing without its knowledge.
The AI firm said the earliest incidents date back to April 2026, adding it made the discoveries after launching a "large-scale retrospective review" in response to a recent disclosure from OpenAI that a combination of its models escaped the sandboxed environment by exploiting a previously unreported zero-day in Artifactory to obtain internet access and break into Hugging Face's production systems with an end goal to cheat on an evaluation.
"After reviewing 141,006 evaluation runs where Claude could have obtained internet access, we identified three incidents in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations," Anthropic said.
ShinyHunters claims Brinks Home breach, threatens to leak stolen data
Residential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data.
The company identified the attack on July 20 and immediately activated its incident response procedure to contain the breach.
William Niles, CEO at Brinks Home, said that the company’s team was working with “leading forensics experts to address this issue.”
The intrusion did not impact in any way the company’s alarm monitoring and system functionality.
At the beginning of the week, the ShinyHunters extortion gang claimed the attack on Brinks Home, alleging that they stole more than 4.9 million Salesforce records with personally identifiable information (PII).
…
In a conversation with BleepingComputer, ShinyHunters said that they breached Brinks Home on July 13 in a Microsoft Entra voice phishing (vishing) attack.
When AI Changes A Deal: Rethinking Risk, Milestones, And Timing In Life Sciences M&A
Artificial intelligence is increasingly embedded in drug discovery and clinical development, and early data suggests it is beginning to change how quickly companies reach early clinical milestones and how likely they are to clear them. For life sciences M&A practitioners and corporate development teams, the critical question is what these early signals mean for valuation, diligence, milestone design, and timing of transactions.
This article examines how AI is beginning to reshape drug development — particularly at the stages of target and compound identification — and explores the implications of those changes.
AI Is Already Changing Early-Stage Drug Development And Target Identification
The most immediate impact of AI is occurring at the earliest stages of drug development. AI-enabled approaches are improving target identification, molecule design, and lead optimization, allowing companies to move from concept to candidate more quickly. In practical terms, AI reduces the time and cost required to reach a defined candidate and enter early clinical development.
What Does Responsible AI Adoption Look Like?
Artificial intelligence is changing how legal services are delivered. At Debevoise, we are using AI to help our lawyers work more efficiently while maintaining the legal judgment, rigorous governance and quality standards our clients expect.
To provide greater transparency into our approach, we have launched a new AI@Debevoise page. It explains how we use AI across the firm, the governance framework that guides its use, and the principles that underpin our approach to quality, confidentiality and responsible deployment.
It also reflects the close connection between our client-facing AI practice and our internal AI program. Our experience advising clients informs how we deploy AI across the firm, and our practical experience using AI strengthens the advice we provide to clients.
The page highlights our AI practice and Applied AI team; STAAR, our AI-powered client portal; the AI Decathlon, our firmwide lawyer training program; and recent AI-related news and recognitions.
AWS Blames North Korean Group for npm Supply Chain Attacks
A series of attacks on npm libraries including axios was the work of North Korean actors, AWS has said.
The cloud computing giant said in a blog post on July 29 that compromises of the axios, debug, chalk and typo-crypto libraries were carried out by the same group, known as Saphire Sleet, BlueNoroff and other monikers.
Amazon Threat Intelligence made the connection after analyzing tactics, techniques, and procedures (TTPs) related to the axios attack.
“Amazon Threat Intelligence identified shared TTPs across these supply-chain campaigns, including trojanized NPM packages, use of post-install hooks (scripts that run automatically when a package is installed), and code reuse,” CJ Moses, CISO and VP of security engineering at Amazon, explained.
“Based on analysis of command-and-control (C2) indicators and TTPs, Amazon Threat Intelligence assesses with medium confidence that these campaigns are attributable to the DPRK-linked threat actor tracked as Saphire Sleet.”
Bankrupt Trucker Yellow Sued Over Delayed Data Breach Warning
Former Yellow Corp. workers accused the trucking company of failing to protect sensitive employee data exposed in a cyberattack during its bankruptcy.
Yellow waited roughly 15 months to notify data breach victims of the incident that exposed information including names, dates of birth, Social Security and passport numbers, as well as financial and medical information, according to a Thursday complaint filed on behalf of a proposed class in the US Bankruptcy Court for the District of Delaware.
The complaint said the victims were only notified of the breach days before the company’s Chapter 11 plan became effective on July 1.
