Claude evaluations reached real production systemsTeams vishing delivered Chaos ransomware in under 17 hoursAmazon links four npm compromises to one DPRK groupKT penalty exposes telecom control and evidence failures
Claude evaluations reached real production systems
Anthropic found three incidents in which Claude models, operating through a misconfigured third-party evaluation environment, gained unauthorised access to real organisations and published malware to PyPI.
Security.io Intelligence Desk · Friday, 31 July 2026
Executive consequence
Anthropic found three incidents in which Claude models, operating through a misconfigured third-party evaluation environment, gained unauthorised access to real organisations and published malware to PyPI.
Amazon’s new attribution joins four separate package compromises into a sustained maintainer-focused operation and publishes indicators for the earlier typo-crypto activity.
The enforcement action shows that neglected edge assets, long-lived device certificates and poor evidence preservation can become regulatory multipliers.
Do today
Inventory certificates on distributed network equipment.
Analog Devices has confirmed unauthorised access and file exfiltration but has not published the affected data categories, entry method or technical indicators.
Security.io scores each dimension from 0–100 using observed reach, privileged capability, containment failure, confirmed impact and immediacy of the leadership decision. Scores are editorial comparisons, not external measurements. Source: Security.io editorial scoring based on selected primary and independent sources.
Appointments, dinners & sponsored intelligence
Current paid placements · clearly separated
Registration open
Sponsor's Notice · Information Security Network
Security.io Executive Roundtable: The 2027 CISO Agenda