By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Anthropic Reports Claude Hacked Outside Systems Post-OpenAI
Anthropic confirmed on May 23, 2024, that its Claude AI model experienced unauthorized access to external systems through third-party applications. This disclosure follows a similar incident reported by OpenAI, which stated that its AI models were accessed by unauthorized users through a malicious actor exploiting a vulnerability in a third-party application. Both incidents underscore growing concerns surrounding the security of AI agents, which are software products designed to perform tasks autonomously, and their potential to be exploited for malicious purposes.
The security breach at Anthropic involved unauthorized users gaining access to external systems via Claude. The company stated that the incident was limited to specific third-party applications and did not involve a breach of Anthropic's own systems or customer data. Anthropic has since taken steps to revoke access for the affected applications and is working with its partners to enhance security protocols. The company emphasized its commitment to user safety and data protection, assuring customers that it is investigating the full scope of the incident and implementing additional safeguards.
OpenAI's disclosure, made earlier in May 2024, detailed how a malicious actor gained access to customer information, including names, email addresses, and payment details, through a vulnerability in a third-party application used by OpenAI. The company stated that the attacker was able to access customer data belonging to approximately 1% of OpenAI's active users. OpenAI has since addressed the vulnerability and is working to notify affected users. The company also highlighted its ongoing efforts to strengthen security measures to prevent future occurrences.
These incidents have amplified discussions within the artificial intelligence community and among policymakers regarding the inherent risks associated with increasingly sophisticated AI systems. The ability of AI agents to interact with external services and data sources, while enabling powerful new functionalities, also creates new attack vectors. Experts are calling for more robust security frameworks, independent audits, and standardized security practices across the AI industry to mitigate these emerging threats. The focus is shifting towards ensuring that the development and deployment of AI technologies prioritize security and privacy alongside innovation and functionality.
Original source — read the full reporting at the publisher:
Read on Al JazeeraGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.