- The Deep View
- Posts
- How Anthropic models made easy prey of 3 enterprises
How Anthropic models made easy prey of 3 enterprises

Welcome back. The Google Flow film festival offered a hopeful answer to the AI slop problem: the strongest work kept human actors and practical production at the center, while using AI for aliens, special effects, and impossible scenarios. Meanwhile, CrowdStrike’s latest threat report shows the security exploit window decreasing dramatically, with 88% of known flaws attacked within two days. This could mean big changes for cybersecurity teams. Anthropic’s evaluations added another warning, after Claude breached three enterprises through weak passwords and exposed endpoints without being detected. The impact of AI agents on cybersecurity is becoming much clearer, and it's going to demand urgency. —Jason Hiner
1. How Anthropic models made easy prey of 3 enterprises
2. CrowdStrike: AI has cut exploit time to hours
3. Google film fest showed where AI filmmaking works
GOVERNANCE
Claude breaches 3 enterprises as red flags wave
Just one week after OpenAI came clean about its breach of Hugging Face, Anthropic has come forward about similar transgressions made by Claude.
In a review of cybersecurity evaluations, Anthropic found three incidents in which its flagship Claude models were able to access the internet from within its evaluation environment, allowing it to hack into the systems of three different companies, the AI lab said on Thursday. The impacted organizations did not detect Claude's breach, Anthropic said.
The company said its review, which included more than 141,000 evaluation transcripts, was prompted by OpenAI's breach of Hugging Face's systems during training, in which its models similarly escaped containment during internal testing on ExploitGym, a benchmark for cybersecurity capabilities.
Anthropic's breaches occurred while the models, which consisted of Opus 4.7, Mythos 5, and an internal research test model, interacted with Irregular, a third-party evaluation partner, which gave it access to the production infrastructure of three different organizations, the company said in a blog post. Anthropic did not disclose which companies were impacted.
In each incident, Claude was tasked with a "capture-the-flag" challenge, in which the models were told to find a piece of information hidden within the network, with the objective being to break in and retrieve it.
In every prompt for this task, it was specified that the training environment was a simulation without internet access. However, due to "a misunderstanding between us and our evaluation partner," the models had internet access anyway, leading them to utilize the open internet in their tasks.
Anthropic said that Claude compromised the organizations' infrastructure "using basic techniques, such as exploiting weak passwords and unauthenticated endpoints," and that the models did not find or exploit any complex vulnerabilities.
The company also noted several differences between its breaches and OpenAI's breaches. For instance, while OpenAI's models exploited a novel vulnerability to escape the simulation, Claude simply deduced that it had access to the internet via an open path.
Anthropic said that as these models get stronger, testing environments need stronger security controls, even in simulations. However, because these models were in a simulation without standard safeguards, Anthropic did note that the normal safeguards available on its public models could have prevented this behavior. Additionally, no model during this testing was "pursuing a goal of its own," but rather acting exactly as intended and doing exactly what the evaluation asked.
Going forward, Anthropic said it intends to expand continuous monitoring of evaluation transcripts, improve investigation tooling and work more closely with vendors to prevent this from happening again.
"It is important to note that even though these results were achieved in controlled research surroundings, they only reiterate that the AI developments continue growing at a faster pace than any organization can foresee," Erik Avakian, technical counselor at Info-Tech Research Group, told The Deep View. "I also think that most organizations are not ready for developments of such a scale."

While OpenAI's breach served as a warning shot for AI's ability to weave its way into complex vulnerabilities, Anthropic's incidents may serve as a different kind of warning: Enterprises' security posture is lacking they're not ready to handle the cyber capabilities of even the mid-range models available today, let alone the increasingly powerful ones. Anthropic noted that its models were able to exploit common entry points, including weak passwords and unauthenticated endpoints, to breach the impacted organizations. Additionally, these companies didn't even know they had been breached, so it's likely that many organizations with weak incident detection protocols wouldn't notice either. Still, these incidents aren't going to slow down any time soon. Not only are these hacks becoming more common, but they're also becoming more expensive, with the average cost of an AI-enabled breach hitting $6 million, according to IBM. In addition to using AI to fight AI, as with recent products from Microsoft and Cisco, enterprises will need to make cybersecurity and risk management a higher priority across the board to address the rising dangers posed by the latest AI models.
IN PARTNERSHIP WITH LAMBDA
Cut your AI training costs by 25% or more
Most large-scale AI training runs use less than half the computing power they're paying for. Lambda's team found the root causes and built a reproducible framework that boosted efficiency by over 25%, without changing the model itself.
Lambda’s whitepaper shows you how to address:
Memory inefficiencies silently inflating your costs
Training configurations that aren't making full use of your hardware
Bottlenecks that slow down GPU communication
RESEARCH
CrowdStrike: AI has cut exploit time to hours
New data tells a scary story about the impact of AI agents on cybersecurity.
One of the first extensive cybersecurity reports since the rise of agents has arrived, and the results are as alarming as the industry expected. On August 3, cybersecurity giant CrowdStrike released its 2026 Threat Hunting Report, which found:
Cloud-focused cybercrime increased 171% in one year
AI agents set off 2.5 times more security alerts than people did
88% of known software flaws are now attacked within two days of public release, challenging the traditional 30-day patch window
"It used to be that the time when a vulnerability was released to when an exploit was available could be measured in months, if not years, and now it’s being measured in hours," Adam Meyers, CrowdStrike's senior vice president of intelligence, told The Deep View.
For enterprises dealing with the fallout from agentic-enabled cybersecurity attacks, there are several new realities they have to come to grips with:
AI is not only a hacking tool, it's now a target: Attackers are going after model access, API keys, agent permissions, and development environments.
The AI ecosystem itself is a new supply chain battleground: The weakest point may be open-source packages (especially npm), agent integrations, developer identities, and automated pipelines.
Enterprise patching has to accelerate: Perhaps most of all, enterprises can't wait to patch software in long, regular cycles any more, but will have to move closer to real-time patching.
"It has gone from a manageable problem to a completely unmanageable problem," said Meyers, about the exploit timeframe, "and it’s going to require thinking about things differently, and changing behaviors."

As 2026 has unfolded, it's become very clear across the tech industry that AI agents are transforming workflows so rapidly that it's taking time to assess the impacts. In cybersecurity, the CrowdStrike threat report has provided clarity around the dangers AI agents now pose by accelerating the exploit window and targeting trusted identities within an organization's AI supply chain as an easier path for break-ins than traditional hacking techniques. One bright spot is that when I asked Meyers how things went with Project Glasswing, where Anthropic worked with industry leaders, including CrowdStrike, to provide early access to its next-gen AI model, Mythos, so the industry could get a step ahead of bad actors. Meyers said both the industry and the AI lab learned a lot about how to collaborate and improve the situation more quickly going forward.
IN PARTNERSHIP WITH GRANOLA
Be the person who remembers everything.
Some people walk into meetings and recall exactly what was decided last time, the numbers, who promised what. They're not better than you. They just have a better system.
Captures your meetings automatically, no bots, no awkward recording prompts
Builds a searchable memory of every discussion and decision over time
Lets you ask Chat anything and get an answer with citations, pulled from your notes, your team's notes, even notes sent to you privately
With Granola's Briefs, you don't even have to ask. Before you walk into a meeting, Granola tells you who you're meeting and what matters.
You become that person in the room who never loses the thread. Not because you take endless notes, but better ones.
CULTURE
Google film fest showed where AI filmmaking works
AI slop dominates social feeds, but an invite to a Google Flow film screening in NYC raised a genuine question: could AI actually create meaningful art?
The event featured films from the fourth cohort of the Google Flow Sessions: artists invited by Google to spend six weeks in a creative partner program crafting short films with the company's AI video generator. Some films used Flow for the entire film, while others used practical sets and actors with the AI as a backup. Unsurprisingly, the films that resonated with me most took the latter approach: using AI for characters, graphics, and worlds with no real-world equivalent.
For instance, award-winning filmmaker and creative director Andrew Nethery's film Nothin' Beats a Cheeseburger was about an alien on a mission to find the best cheeseburger on Earth, and it brought the chef back to his planet. The film used a real diner as the set and two real actors, including the person who played the alien. This was a purposeful choice, as Nethery explained his hardline stance about always keeping real actors in the story.
"I personally believe, you know, theater, filmmaking, storytelling, you're going back to like ancient civilization of like an actor on a stage," said Nethery, "I love working with real actors, love practical production, [and] physical production. So I would love for all that to be the same."
He used AI to add in elements such as a TV and a cow, tasks which would have been time-consuming. He also used it to transform the stand-in actor into an alien, a task he was impressed AI could do so well. He explained that with the traditional process, such as motion capture used in movies like Avatar, it would have taken weeks or months to do.
Not only was it quicker, but it was able to tackle tasks such as maintaining the shape of the face and the reflections on the window, tasks "notoriously difficult for VFX and CGI to do," according to Nethery. He did fall back on using AI to generate an entire alien scene when the original shots with the actor didn't pan out. In total, Nethery's film has 20 live-action shots. 32 hybrid shots with generated elements, and five generated AI shots with no live action.
Of course, there are an overwhelming number of instances where I generated content goes wrong, with the Coca-Cola and McDonald's ad failures being prime examples. When asked why AI campaigns go wrong, Nethery blamed companies and advertising agencies that push AI usage.
"It's a disservice to the ability and the future of what these tools can do. I think everything needs to be done responsibly," he said.
You can watch all the short films, which range from about 1 to 3 minutes.

It's easy to associate AI-generated content with slop, given the sheer volume of it flooding our social feeds and elsewhere right now, but there are ways to use it intentionally to create meaningful work. To do this well, artists need to be mindful not to alienate an audience already tired of AI-generated content, and to steer clear of work that humans can quickly and easily identify as AI-made. For instance, films with what I felt were clearly AI-generated oceans, people, or objects immediately put me off. When monsters, aliens, or animations were AI-generated, though, it didn't seem to matter, since there's no real-world counterpart to compare them to. Beyond the quality of the output, questions remain about the ethical implications of using these models, since they are typically trained on vast amounts of work from non-consenting artists on the open web.
LINKS

German court rules AI music firm Suno violated copyrights
Moonshot, Alibaba strike deal for 20,000 Nvidia H200 chips
Big Tech spent $1.1 trillion in capex since 2023, Financial Times report
EU rules to mandate AI labels on realistic synthetic content
Judge denies Elon Musk's request to curb Minnesota AI nudes law
ThreatLocker raises $190 million Series F for AI risk control

Dreamina Seedance 2.5: BytePlus made new cinematic AI video model live
DeepSeek-V4-Flash: API is live in public beta
Linear: Launched coding sessions on mobile
Viator Travel: Available directly in Gemini and Gemini Spark for users in the US

Cantina Labs: Prompt Engineer
Prodigal: AI Agent Engineer
Deloitte: Agentic AI Engineer — Healthcare AI
Fluency: AI Engineer
POLL RESULTS
Do you think the AI market is turning towards efficiency and cost savings?
Yes (38%)
Somewhat (35%)
No (20%)
Other (7%)
The Deep View is written by Nat Rubio-Licht, Sabrina Ortiz, Jason Hiner, Faris Kojok and The Deep View crew. Please reply with any feedback.

Thanks for reading today’s edition of The Deep View! We’ll see you in the next one.

“There's something very odd hanging over the lip of this glass - AI wouldn't create something so random.”
|
“[This image] looks too perfect.”
|


If you want to get in front of an audience of 750,000+ developers, business leaders and tech enthusiasts, get in touch with us here.













