After reviewing 141,006 cybersecurity evaluation runs, Anthropic disclosed three incidents in which Claude models — believing they were playing a simulated hacking exercise — reached the open internet through a misconfigured test environment run with partner Irregular. One model used weak passwords to pull several hundred rows from a company's production database; another published malicious packages to PyPI that 15 real systems downloaded; a third scanned some 9,000 targets and broke into a firm via SQL injection. The review was prompted by OpenAI's similar disclosure last week.