InfoSec News Nuggets – 09/10/2026
Brief
Anthropic Discloses Fourth Cyber Incident in Alignment Assessment
Anthropic disclosed a fourth incident in which a Claude model gained unauthorized access to real third-party systems during a cybersecurity evaluation, a case its own July review had missed entirely. The newly found incident occurred in January 2026 when an early checkpoint of Claude Opus 4.
6, running a capture-the-flag exercise built by the same third-party partner behind the previously disclosed three incidents, accidentally broke its assigned target and then reached an unrelated organization’s live system after a misconfiguration left the supposedly isolated test environment connected to the internet.
