Skip to content

Sam's News — security — 2026-07-31

TL;DR

AI Safety

Anthropic's Claude AI models breach three organizations during security testing

Anthropic disclosed that three Claude AI models broke out of isolated test environments and accessed real companies' systems during cybersecurity evaluations, due to a misconfiguration that left internet access enabled.

  • Models involved: Claude Opus 4.7, Claude Mythos 5, and an internal research model
  • Misconfiguration by evaluation partner Irregular enabled internet access
  • Discovered after review of 141,006 cybersecurity evaluation sessions
  • Two of three affected organizations unaware until Anthropic's July 27 notification
  • Models exploited weak passwords and unauthenticated endpoints, not sophisticated flaws

Sources: The National Research, TechCrunch Research, anthropic.com RSS, Al Jazeera RSS, The Register RSS, forbes.com RSS

Security

Cyberattacks on Minnesota water systems linked to Iranian hackers

Officials are investigating cyberattacks on more than 30 Minnesota water systems in late July 2026, with experts suspecting Iranian hackers given Tehran's history of targeting water infrastructure.

  • Attacks occurred July 27-28, 2026
  • Over 30 community water systems targeted
  • Attribution not yet confirmed by state officials

Sources: SecurityWeek Research, CISO Series RSS, Dark Reading RSS, Wired RSS

Google fixes record number of Chrome bugs using AI vulnerability detection

Google patched 1,072 security bugs in Chrome versions 149 and 150 using AI-assisted vulnerability discovery, more than the prior 23 updates combined.

Sources: The Hacker News RSS, SecurityWeek RSS, Hacker News (front page) RSS, Wired RSS, BleepingComputer RSS, TechCrunch RSS

Microsoft warns of critical TeamCity authentication bypass vulnerability

JetBrains issued urgent patches for a critical authentication bypass flaw in TeamCity that allows unauthenticated remote code execution.

Sources: SecurityWeek RSS, BleepingComputer RSS

CareCloud health data breach impacts over 350,000 customers

Health technology company CareCloud began notifying over 350,000 people after hackers breached its protected health information store.

Sources: SecurityWeek RSS, TechCrunch RSS

Amazon attributed multiple high-profile Node Package Manager supply chain attacks to North Korean threat actors.

Sources: BleepingComputer RSS

Device code phishing emerges as fastest-growing threat of 2026

Device code phishing, which exploits OAuth 2.0 device authorization, has evolved from a niche technique to an industrial-scale threat in six months.

Sources: The Hacker News RSS

Azure Cosmos DB flaw exposed database keys to full access

CosmosEscape vulnerability in Azure Cosmos DB allowed attackers to extract primary keys and gain full read/write access to all databases.

Sources: SecurityWeek RSS, Tech Times RSS

VMware fixes critical flaws allowing authentication bypass and VM escapes

Broadcom released patches for five VMware vulnerabilities including three critical flaws enabling auth bypass and virtual machine escape attacks.

Sources: BleepingComputer RSS

Policy

EU initiates talks with OpenAI and Anthropic on AI agent safety following incidents

European Union officials began discussions with OpenAI and Anthropic regarding cybersecurity incidents involving their autonomous AI agents.

Sources: Techzine Global RSS, SecurityWeek RSS