×
Amazon October Prime Day: 173+ early deals to shop now

Amazon October Prime Day: 173+ early deals to shop now

Table of Contents

Amazon Prime Day is no longer one glorious day of deals just for Prime members. The flagship Prime Day now spans four days in July, and Amazon has added another annual event in October, too. This year, Prime Big Deal Days returns tomorrow, spanning October 7 and 8. Amazon says its October Prime Day event will deliver millions of deals across categories, giving customers a head start on holiday shopping.

Before the sale begins tomorrow, it’s worth mapping out what gifts you need to buy or which household goods need restocking. But if you’re eager to get an even earlier jump on the holiday shopping, we have some good news. Early deals are already starting to creep in. There are some real gems already available to buy before the chaos of Prime Day takes hold.

Note: Deals marked with a 🔥 denote an all-time low price.

October Prime Day deals to come

Now that Prime Big Deal Days arrive in just a week’s time, Amazon is tantalizing customers with a preview of the deals to come. While these deals aren’t live yet, here’s what we know is to come.

  • Up to 45% off Bose headphones and speakers

  • Up to 40% off on select LG and Hisense TVs and monitors

  • Up to 50% off on select Amazon devices, including Kindle e-readers and Echo devices

  • Up to 65% off chargers and power banks from Anker

  • Up to 50% off vacuums from Shark and Eufy

  • One free grocery item on a Same-Day order at eligible locations

  • Prime members can use Grubhub+ to get $10 off orders of $20 or more

  • Prime members receive triple points on Kindle store purchases during Prime Big Deal Days

Best Apple deal

Why we picked this

“The second-generation AirPods Pro offer top-tier sound quality, excellent noise cancellation, and a battery life of about seven hours per charge. They’re our current favorite earbuds for Apple users, though that may soon change once we finish testing the newer AirPods Pro 3, which have a different design and five swappable ear tips (up from three), even better active noise cancellation, Live Translation, and extra health features. They’re a pretty significant upgrade on paper, but if price is your biggest concern, the AirPods Pro 2 are $79 cheaper for the time being.” — Haley Henschel, Senior Shopping Reporter

Read Mashable’s full review of the Apple AirPods Pro 2 (USB-C).

More AirPods deals

MacBook deals

  • Apple MacBook Air, 15-inch (M4, 16GB RAM, 256GB SSD) — $999 $1,199 (save $200)

  • Apple MacBook Pro, 14-inch (M4, 16GB RAM, 512GB SSD) — $1,399 $1,599 (save $200)

  • Apple MacBook Pro, 16-inch (M4 Pro, 24GB RAM, 512GB SSD) — $2,249 $2,499 (save $250)

  • Apple MacBook Pro, 14-inch (M4 Max, 36GB RAM, 1TB SSD) — $2,869 $3,199 (save $330)

  • Apple MacBook Pro, 16-inch (M4 Max, 36GB RAM, 1TB SSD) — $3,099 $3,499 (save $400)

Apple Watch deals

iPad deals

  • Apple iPad, 11-inch (A16, WiFi, 128GB) — $299 $349 (save $50)

  • Apple iPad mini (A17 Pro, WiFi, 128GB) — $399 $499 (save $100)

  • Apple iPad, 11-inch (A16, WiFi + cellular, 128GB) — $449 $499 (save $50)

  • Apple iPad Air, 11-inch (M3, WiFi, 128GB) — $449 $599 (save $150)

  • Apple iPad Air, 11-inch (M3, WiFi + cellular, 128GB) — $599 $749 (save $150)

  • Apple iPad Air, 13-inch (M3, WiFi, 128GB) — $649 $799 (save $150)

  • Apple iPad Air, 13-inch (M3, WiFi + cellular, 128GB) — $799 $949 (save $150)

  • Apple iPad Pro, 11-inch (M4, WiFi, 256GB) — $896.03 $999 (save $102.97)

  • Apple iPad Pro, 11-inch (M4, WiFi + cellular, 256GB) — $1,099 $1,199 (save $100)

  • Apple iPad Pro, 13-inch (M4, WiFi, 256GB) — $1,099 $1,299 (save $200)

  • Apple iPad Pro, 13-inch (M4, WiFi + cellular, 256GB) — $1,299 $1,499 (save $200)

More Apple deals

Best headphone and earbud deal

Why we picked this

“In the lead up to Amazon’s October Prime Day, we’re looking across categories for the best early savings. One of our favorite categories — headphones and earbuds — is looking a little sparse when it comes to deals, but that’s not to say that there are no good early deals. We’ve found a few great ones.

Ahead of Prime Day, find the Beats Studio Buds for 47% off. That saves you $70 off its typical $149.95 MSRP. The Beats Studio Buds deliver well-balanced sound and active noise cancellation in a small package. Plus, like AirPods, they have easy connectivity to iOS systems, but unlike AirPods, they’re also well-suited for Android users.” — Samantha Mangino, Shopping Reporter

More headphone and earbud deals

Early Prime Day Bluetooth speaker deals

Best laptop deal

Why we like it

“The 13.8-inch Surface Laptop 7 with a Snapdragon X Elite chip is our favorite Windows laptop for most people. It’s beautiful, it’s about as fast as an M4 MacBook Air, and it lasts for nearly 23 hours on a single charge — that’s two longer than the M4 Pro-powered MacBook Pro, the longest-lasting MacBook we’ve tried. (Before you buy it, just double-check that its powerful ARM-based CPU is compatible with your go-to apps.) The black variant with 16GB of memory and 512GB of storage is marked down to $972 ahead of Prime Big Deal Days, which is a 31% discount on its $1,399.99 MSRP. It very briefly fell to $918.47 in late September, but this current offer beats its Prime Day deal in July.” — Haley Henschel, Senior Shopping Reporter

Read Mashable’s full review of the 13.8-inch Microsoft Surface Laptop 7.

More Windows laptop deals

  • Asus Vivobook 16 (AMD Ryzen AI 5 340, 16GB RAM, 512GB SSD) — $679.99 $799.99 (save $120)

  • Microsoft Surface Laptop, 13-inch (Snapdragon X Plus, 16GB RAM, 256GB SSD) — $729.99 $899.99 (save $170)

  • Microsoft Surface Laptop 7, 13.8-inch (Snapdragon X Plus, 16GB RAM, 512GB SSD) — $949.99 $1,199.99 (save $250)

  • Microsoft Surface Laptop 7, 15-inch (Snapdragon X Elite, 32GB RAM, 1TB SSD) — $1,549.99 $2,099.99 (save $550)

2-in-1 laptop deals

Gaming laptop deals

Best TV deal

Why we picked this

“The most affordable 65-inch QLED TV we’re seeing so far is the same one that was the cheapest 65-inch during Prime Day over the summer — but it’s even cheaper now. Snag Insignia’s QF Series QLED for $299.99 versus $329.99 in July.

If you’ve never had a QLED TV before, this XL Insignia model is a great low-stakes opportunity to upgrade. Customers in the reviews seem to be more than satisfied with its picture quality and color vibrancy for the price. As a budget QLED, you can’t expect this model to stunt in HDR like a premium Samsung QLED would. But compared to your old LED TV, you’ll quickly see the difference those quantum dots are making — they’ll especially pop when watching football in the daytime.” — Leah Stodart, Senior Shopping Reporter

More TV deals

42-inch to 50-inch TV deals

55-inch TV deals

65-inch and 70-inch TV deals

  • Hisense 65-inch E6 Cinema Series QLED 4K TV — $399.99 $549.99 (save $250) 🔥

  • LG 65-inch C5 OLED 4K TV — $1,496.99 $2,696.99 (save $1,200) 🔥

  • Samsung 65-inch The Frame 4K QLED TV (2024 model) — $1,197.96 $1,997.99 (save $800.03)

  • Samsung 65-inch S95D OLED TV (2024 model) — $1,297.99 $1,697.99 (save $400) 🔥

  • Sony 65-inch A95K QD-OLED 4K TV — $2,399 $3,499.99 (save $1,100.99)

  • Sony 65-inch Bravia 8 II QD OLED 4K TV — $2,998 $3,499.99 (save $501.99) 🔥

  • Insignia 70-inch F50 Series 4K Fire TV — $329 $499 (save $170) 🔥

75-inch and 77-inch TV deals

85-inch and up TV deals

  • Hisense 85-inch QD7 QLED 4K TV — $879.99 $1,299.99 (save $420)

  • TCL 85-inch QM6K QLED 4K TV — $999.99 $1,499.99 (save $500)

  • Hisense 85-inch U7 QLED 4K TV (2025 model) — $1,499.99 $2,499.99 (save $1,000)

  • Hisense 85-inch Canvas QLED 4K TV — $2,047.99 $2,499.99 (save $452)

  • Hisense 85-inch U8 Mini LED QLED 4K TV (2025 model) — $2,247.99 $3,498 (save $1,250.01)

  • Sony 85-inch Bravia 9 Mini LED QLED 4K TV — $4,498 $4,799.99 (save $301.99)

  • Hisense 100-inch E6 Cinema Series QLED 4K TV — $1,999.99 $2,699.99 (save $700) 🔥

Best Kindle deal

Why we picked this

“The best Kindle deal isn’t actually on one of Amazon’s e-readers. Instead, Amazon is offering three months of Kindle Unlimited totally free. Think of it like a streaming service, except for e-books. Joining Kindle Unlimited gives you access to the Kindle Unlimited library, from which you can borrow. But unlike the library, there’s no due date on these borrowed books; the only restriction is that you can borrow up to 20 books at a time.

Leading up to and during Prime Big Deal Days, you can join Kindle Unlimited for three months — totally free. The promotion is available to everyone, even if you’ve already used up your free trial. This is a $35.97 value that you can score without spending a penny. Plus, you don’t actually need a Kindle to enjoy Kindle Unlimited. You can read from the Kindle library on your smartphone, tablet, or web browser.” — Samantha Mangino, Shopping Reporter

More Kindle deals

Best Amazon device deal

Why we picked this

“There’s no way around it: A shit ton of people are going to buy AirPods this October Prime Day. But for those who aren’t married to Apple’s earbuds (or how often they seem to break), just know that the latest version of Amazon’s Echo Buds with ANC are just $34.99 after a 71% discount. That beats their Prime Day price from July by $10, and you could get five pairs of Echo Buds for less than the $199.99 sale price of the AirPods Pro 2.

Amazon’s noise cancellation doesn’t level with the effectiveness of those AirPods or other top noise-cancelling earbuds, but casual music or podcast listeners may not care at this price point.” — Leah Stodart, Senior Shopping Reporter

More Amazon device deals

Fire tablet deals

Echo deals

Fire TV deals

Fire TV deals from non-Amazon brands

Blink home security deals

Other Amazon device deals

Best robot vacuum deal

Why we picked this

“When it comes to robot vacuums, I always turn to Mashable’s in-house robot vacuum expert, Leah Stodart. When I asked her about these deals, she pointed out that iRobot marked down the Roomba Plus 405 to $399.99, making it one of the most affordable combo robot vacuums and mops. That saves you $265.01 off its list price of $665 for 40% off.

Mashable Deals

The Roomba Plus 405 includes both vacuum and mopping abilities, featuring strong suction to really scrub at dirt and grime. It features four cleaning levels that you can adjust from the iRobot app. Plus, its dock not only empties the vacuum, but even cleans the mopping pads for a truly hands-free experience.

While we’re not sure what other combo vacuum and mop deals are coming during Prime Big Deal Days, we can safely say that the Roomba Plus 405 is one of the best deals you can get ahead of the event.” — Samantha Mangino, Shopping Reporter

More robot vacuum deals

More robot vacuum and mop deals

Best smartwatch deals

Why we picked this

“The Garmin vívoactive 5 was recently replaced as the newest model by the vívoactive 6, but the 5 still holds a special place in our hearts. This is what we’d call a perfect all-rounder fitness tracker, perfect for tracking long runs and cycles while also still having a great range of lifestyle features like sleep tracking, stress levels, and body battery. It’s also a vast improvement over the vívoactive 4, and even has a bright AMOLED display, making it appear even more high-tech.” — Lois Mackenzie, Mashable contributor

More smartwatch deals

Best boring but essential deal

“Prime Day sales are the perfect time to restock your home or apartment with essentials like paper towels, cleaning products, batteries, and health necessities. An always-reliable Prime Day deal is Crest Whitestrips, and once again, they’re on a great discount before we head into October’s sale. The 22-treatment set has 44 strips in total, and it’s on sale for $29.99, which works out to a sweet 35% discount compared to the usual price of $45.99. Plus, this deal qualifies for Proctor and Gamble’s buy two, get $5 off coupon deal, so if you snag two boxes of Whitestrips, you’ll be saving even more.” — Lauren Allain, Mashable contributor

More essential deals

Best Lego deal

Why we like it

“For those looking to get a head start on holiday shopping, Lego’s advent calendars are a very fun pick-up. It’s even better when they can be found on sale. Right now, the 2025 Lego Minecraft Advent Calendar is down to its best price at Amazon, dropping from $44.99 to $38. If you’re looking to grab one for the kids to enjoy over the holidays, now is a great time to jump on it.” — Hannah Hoolihan, Mashable contributor

More Lego deals

Best portable power station deal

Why we like it

“A portable power station is one of the most useful items you can buy for your home this year. They’ve seen major advancements in both battery technology and user-friendliness recently and the Anker Solix C1000 portable power station is a standout model. It’s an idea combination of power (1,056Wh), plenty of ports, and it’s on sale ahead of Prime Day for $429, which is the lowest price Amazon has ever offered.

When the power gets knocked out by a storm this fall or winter, you’ll be able to use the C1000 to keep phones and laptops charged up. You can also use it to power up the coffee maker in the morning or plug in the WiFi router so you won’t have to suck down data.

Come summer, the Anker Solix C1000 can come along on camping trips and if you snag a solar panel, you’ll be in line for unlimited power.” — Lauren Allain, Mashable contributor

More portable power station deals

Source link
#Amazon #October #Prime #Day #early #deals #shop

The fact that this hack happened is a problem. So is the fact that it took a while for anyone to notice. And the fact that it seems no one is willing or able to do much to stop it. (And lest you think it’s just an OpenAI problem, since we recorded this episode Anthropic acknowledged its models have also hacked a bunch of other companies without either party knowing.) It might all just be a bunch of posturing and hype, but it’s also increasingly clear that the companies building large language models either can’t or won’t put the right guardrails on them. So who will?

After all that, it’s time for Brendan Carr is a Dummy, a bunch of vertical video news, and the smashing success of the Ferrari Luce. People are buying it! If one of them is you, we’d love to hear about it.

#time #panic #safetyAI,OpenAI,Podcasts,Policy,Vergecast">It’s time to panic about AI safetyWhen the phrase “OpenAI hacked Hugging Face” has more or less entered mainstream culture, you know we have an AI problem. This week, we learned more about exactly how OpenAI’s agent broke out of a sandbox and autonomously traversed the web, including a bunch of other supposedly secure web services, all in the name of cheating on a benchmark tests.The fact that this hack happened is a problem. So is the fact that it took a while for anyone to notice. And the fact that it seems no one is willing or able to do much to stop it. (And lest you think it’s just an OpenAI problem, since we recorded this episode Anthropic acknowledged its models have also hacked a bunch of other companies without either party knowing.) It might all just be a bunch of posturing and hype, but it’s also increasingly clear that the companies building large language models either can’t or won’t put the right guardrails on them. So who will?After all that, it’s time for Brendan Carr is a Dummy, a bunch of vertical video news, and the smashing success of the Ferrari Luce. People are buying it! If one of them is you, we’d love to hear about it.#time #panic #safetyAI,OpenAI,Podcasts,Policy,Vergecast

we have an AI problem. This week, we learned more about exactly how OpenAI’s agent broke out of a sandbox and autonomously traversed the web, including a bunch of other supposedly secure web services, all in the name of cheating on a benchmark tests.

The fact that this hack happened is a problem. So is the fact that it took a while for anyone to notice. And the fact that it seems no one is willing or able to do much to stop it. (And lest you think it’s just an OpenAI problem, since we recorded this episode Anthropic acknowledged its models have also hacked a bunch of other companies without either party knowing.) It might all just be a bunch of posturing and hype, but it’s also increasingly clear that the companies building large language models either can’t or won’t put the right guardrails on them. So who will?

After all that, it’s time for Brendan Carr is a Dummy, a bunch of vertical video news, and the smashing success of the Ferrari Luce. People are buying it! If one of them is you, we’d love to hear about it.

#time #panic #safetyAI,OpenAI,Podcasts,Policy,Vergecast">It’s time to panic about AI safety

When the phrase “OpenAI hacked Hugging Face” has more or less entered mainstream culture, you know we have an AI problem. This week, we learned more about exactly how OpenAI’s agent broke out of a sandbox and autonomously traversed the web, including a bunch of other supposedly secure web services, all in the name of cheating on a benchmark tests.

The fact that this hack happened is a problem. So is the fact that it took a while for anyone to notice. And the fact that it seems no one is willing or able to do much to stop it. (And lest you think it’s just an OpenAI problem, since we recorded this episode Anthropic acknowledged its models have also hacked a bunch of other companies without either party knowing.) It might all just be a bunch of posturing and hype, but it’s also increasingly clear that the companies building large language models either can’t or won’t put the right guardrails on them. So who will?

After all that, it’s time for Brendan Carr is a Dummy, a bunch of vertical video news, and the smashing success of the Ferrari Luce. People are buying it! If one of them is you, we’d love to hear about it.

#time #panic #safetyAI,OpenAI,Podcasts,Policy,Vergecast
Anthropic said Thursday that an internal investigation uncovered three incidents in which its AI model Claude breached the systems of three organizations while conducting cybersecurity tests. The investigation, and disclosure, comes more than a week after OpenAI disclosed that one of its unreleased models breached Hugging Face’s systems during internal testing.

In all three cases, a Claude model reached the internet from within a testing environment while interacting with a third party and then gained unauthorized access to the live systems of these organizations, Anthropic said in a blog post, describing what it found and what the company plans to change to prevent this from happening again.

Anthropic said the OpenAI episode earlier this month prompted the company to conduct its own cybersecurity evaluation. It specifically looked for evidence that Claude had accessed the internet from within testing environments, which are designed to act as sandboxes and keep models isolated.

Among the 141,006 evaluation runs it reviewed, the AI lab found three incidents in which its model accessed the internet while interacting with Irregular, one of its third-party partners. Anthropic said the access traced back to a misconfiguration in the evaluation environment run with Irregular. It called this a “misunderstanding” between the two companies over whether the test setup had internet access, when in fact it did.

Anthropic said it isn’t placing blame and is “approaching the fixes as if the responsibility were ours alone,” while observing that Irregular is conducting its own separate investigation.

Because of that open connection, the model gained unauthorized access to the production infrastructure of three different organizations. Anthropic said the incidents involved three different Claude models: Opus 4.7, Mythos 5, and an internal research test model.

Notably, Anthropic said that in each of these cases “Claude was explicitly told by our prompt that it had no internet access.” It appears that the AI model assumed real-world systems to be part of the exercise it was asked to perform.

That assumption didn’t hold up uniformly, as it turns out. The three models didn’t behave the same way once evidence emerged that their targets were real, which Anthropic flagged as one of the more eye-opening findings Thursday.

Opus 4.7, the oldest of the three, recognized that it had reached a real production system in all four runs of that incident. In two of them, it rationalized that the real company must somehow be part of the exercise, but in all four, it kept attacking anyway, including pulling credentials and touching a database of production data. Mythos 5 also picked up on signs that it was on the real internet, but it talked itself back into believing it was still in a simulation, going on to publish a malicious software package to the public Python software registry PyPI, which was then downloaded and run by outside systems before being caught. Only the internal research test model, Anthropic’s newest, stopped on its own once it concluded the target was real.

In response, Anthropic said significant controls must be placed on these kinds of evaluations if powerful AI models are involved, echoing some sentiments within the cybersecurity community.

The company also noted that Claude was running without the additional safety monitoring and classifiers it deploys on generally available models — safeguards it said would have blocked the behavior, because the evaluations are designed to measure the underlying model’s raw capabilities.

Importantly, Anthropic said it found no evidence of any model “pursuing a goal of its own” and instead merely tried to complete the task it was asked to do.

Though comparisons between the mishaps of these fiercely competitive companies are inevitable, Anthropic in its blog post drew a clear distinction between its cybersecurity tests and those of OpenAI, noting where OpenAI’s model exploited an unknown software vulnerability to break out of its test environment, Anthropic’s models instead reached the internet through a path that had, by mistake, been left open.

Anthropic also drew a distinction between itself and OpenAI by noting that it discovered the incidents itself, through a proactive review, and that the two affected organizations it was able to reach hadn’t previously detected the activity or flagged it to Anthropic. (In contrast, Hugging Face detected the recent intrusion of its own systems first; it was only in the following days that OpenAI identified and disclosed that its own AI agent was the perpetrator.)

The company added that it’s now working with the independent evaluation group METR on a third-party review of the incidents.

OpenAI’s accidental breach of Hugging Face, which was the first verifiable case of an AI lab losing control of its model, has sparked a string of wildly differing reactions from the industry and politicians. This latest disclosure from Anthropic ensures the debate over AI models and security will continue.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

#Anthropic #models #breached #companies #security #tests #TechCrunchAnthropic,OpenAI">Anthropic says its own AI models breached three companies during security tests | TechCrunch
Anthropic said Thursday that an internal investigation uncovered three incidents in which its AI model Claude breached the systems of three organizations while conducting cybersecurity tests. The investigation, and disclosure, comes more than a week after OpenAI disclosed that one of its unreleased models breached Hugging Face’s systems during internal testing.

In all three cases, a Claude model reached the internet from within a testing environment while interacting with a third party and then gained unauthorized access to the live systems of these organizations, Anthropic said in a blog post, describing what it found and what the company plans to change to prevent this from happening again.







Anthropic said the OpenAI episode earlier this month prompted the company to conduct its own cybersecurity evaluation. It specifically looked for evidence that Claude had accessed the internet from within testing environments, which are designed to act as sandboxes and keep models isolated.

Among the 141,006 evaluation runs it reviewed, the AI lab found three incidents in which its model accessed the internet while interacting with Irregular, one of its third-party partners. Anthropic said the access traced back to a misconfiguration in the evaluation environment run with Irregular. It called this a “misunderstanding” between the two companies over whether the test setup had internet access, when in fact it did. 

Anthropic said it isn’t placing blame and is “approaching the fixes as if the responsibility were ours alone,” while observing that Irregular is conducting its own separate investigation.

Because of that open connection, the model gained unauthorized access to the production infrastructure of three different organizations. Anthropic said the incidents involved three different Claude models: Opus 4.7, Mythos 5, and an internal research test model.

Notably, Anthropic said that in each of these cases “Claude was explicitly told by our prompt that it had no internet access.” It appears that the AI model assumed real-world systems to be part of the exercise it was asked to perform.


That assumption didn’t hold up uniformly, as it turns out. The three models didn’t behave the same way once evidence emerged that their targets were real, which Anthropic flagged as one of the more eye-opening findings Thursday.

Opus 4.7, the oldest of the three, recognized that it had reached a real production system in all four runs of that incident. In two of them, it rationalized that the real company must somehow be part of the exercise, but in all four, it kept attacking anyway, including pulling credentials and touching a database of production data. Mythos 5 also picked up on signs that it was on the real internet, but it talked itself back into believing it was still in a simulation, going on to publish a malicious software package to the public Python software registry PyPI, which was then downloaded and run by outside systems before being caught. Only the internal research test model, Anthropic’s newest, stopped on its own once it concluded the target was real.

In response, Anthropic said significant controls must be placed on these kinds of evaluations if powerful AI models are involved, echoing some sentiments within the cybersecurity community.







The company also noted that Claude was running without the additional safety monitoring and classifiers it deploys on generally available models — safeguards it said would have blocked the behavior, because the evaluations are designed to measure the underlying model’s raw capabilities.

Importantly, Anthropic said it found no evidence of any model “pursuing a goal of its own” and instead merely tried to complete the task it was asked to do.

Though comparisons between the mishaps of these fiercely competitive companies are inevitable, Anthropic in its blog post drew a clear distinction between its cybersecurity tests and those of OpenAI, noting where OpenAI’s model exploited an unknown software vulnerability to break out of its test environment, Anthropic’s models instead reached the internet through a path that had, by mistake, been left open.

Anthropic also drew a distinction between itself and OpenAI by noting that it discovered the incidents itself, through a proactive review, and that the two affected organizations it was able to reach hadn’t previously detected the activity or flagged it to Anthropic. (In contrast, Hugging Face detected the recent intrusion of its own systems first; it was only in the following days that OpenAI identified and disclosed that its own AI agent was the perpetrator.)

The company added that it’s now working with the independent evaluation group METR on a third-party review of the incidents.

OpenAI’s accidental breach of Hugging Face, which was the first verifiable case of an AI lab losing control of its model, has sparked a string of wildly differing reactions from the industry and politicians. This latest disclosure from Anthropic ensures the debate over AI models and security will continue.


When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.#Anthropic #models #breached #companies #security #tests #TechCrunchAnthropic,OpenAI

Hugging Face’s systems during internal testing.

In all three cases, a Claude model reached the internet from within a testing environment while interacting with a third party and then gained unauthorized access to the live systems of these organizations, Anthropic said in a blog post, describing what it found and what the company plans to change to prevent this from happening again.

Anthropic said the OpenAI episode earlier this month prompted the company to conduct its own cybersecurity evaluation. It specifically looked for evidence that Claude had accessed the internet from within testing environments, which are designed to act as sandboxes and keep models isolated.

Among the 141,006 evaluation runs it reviewed, the AI lab found three incidents in which its model accessed the internet while interacting with Irregular, one of its third-party partners. Anthropic said the access traced back to a misconfiguration in the evaluation environment run with Irregular. It called this a “misunderstanding” between the two companies over whether the test setup had internet access, when in fact it did.

Anthropic said it isn’t placing blame and is “approaching the fixes as if the responsibility were ours alone,” while observing that Irregular is conducting its own separate investigation.

Because of that open connection, the model gained unauthorized access to the production infrastructure of three different organizations. Anthropic said the incidents involved three different Claude models: Opus 4.7, Mythos 5, and an internal research test model.

Notably, Anthropic said that in each of these cases “Claude was explicitly told by our prompt that it had no internet access.” It appears that the AI model assumed real-world systems to be part of the exercise it was asked to perform.

That assumption didn’t hold up uniformly, as it turns out. The three models didn’t behave the same way once evidence emerged that their targets were real, which Anthropic flagged as one of the more eye-opening findings Thursday.

Opus 4.7, the oldest of the three, recognized that it had reached a real production system in all four runs of that incident. In two of them, it rationalized that the real company must somehow be part of the exercise, but in all four, it kept attacking anyway, including pulling credentials and touching a database of production data. Mythos 5 also picked up on signs that it was on the real internet, but it talked itself back into believing it was still in a simulation, going on to publish a malicious software package to the public Python software registry PyPI, which was then downloaded and run by outside systems before being caught. Only the internal research test model, Anthropic’s newest, stopped on its own once it concluded the target was real.

In response, Anthropic said significant controls must be placed on these kinds of evaluations if powerful AI models are involved, echoing some sentiments within the cybersecurity community.

The company also noted that Claude was running without the additional safety monitoring and classifiers it deploys on generally available models — safeguards it said would have blocked the behavior, because the evaluations are designed to measure the underlying model’s raw capabilities.

Importantly, Anthropic said it found no evidence of any model “pursuing a goal of its own” and instead merely tried to complete the task it was asked to do.

Though comparisons between the mishaps of these fiercely competitive companies are inevitable, Anthropic in its blog post drew a clear distinction between its cybersecurity tests and those of OpenAI, noting where OpenAI’s model exploited an unknown software vulnerability to break out of its test environment, Anthropic’s models instead reached the internet through a path that had, by mistake, been left open.

Anthropic also drew a distinction between itself and OpenAI by noting that it discovered the incidents itself, through a proactive review, and that the two affected organizations it was able to reach hadn’t previously detected the activity or flagged it to Anthropic. (In contrast, Hugging Face detected the recent intrusion of its own systems first; it was only in the following days that OpenAI identified and disclosed that its own AI agent was the perpetrator.)

The company added that it’s now working with the independent evaluation group METR on a third-party review of the incidents.

OpenAI’s accidental breach of Hugging Face, which was the first verifiable case of an AI lab losing control of its model, has sparked a string of wildly differing reactions from the industry and politicians. This latest disclosure from Anthropic ensures the debate over AI models and security will continue.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

#Anthropic #models #breached #companies #security #tests #TechCrunchAnthropic,OpenAI">Anthropic says its own AI models breached three companies during security tests | TechCrunch

Anthropic said Thursday that an internal investigation uncovered three incidents in which its AI model Claude breached the systems of three organizations while conducting cybersecurity tests. The investigation, and disclosure, comes more than a week after OpenAI disclosed that one of its unreleased models breached Hugging Face’s systems during internal testing.

In all three cases, a Claude model reached the internet from within a testing environment while interacting with a third party and then gained unauthorized access to the live systems of these organizations, Anthropic said in a blog post, describing what it found and what the company plans to change to prevent this from happening again.

Anthropic said the OpenAI episode earlier this month prompted the company to conduct its own cybersecurity evaluation. It specifically looked for evidence that Claude had accessed the internet from within testing environments, which are designed to act as sandboxes and keep models isolated.

Among the 141,006 evaluation runs it reviewed, the AI lab found three incidents in which its model accessed the internet while interacting with Irregular, one of its third-party partners. Anthropic said the access traced back to a misconfiguration in the evaluation environment run with Irregular. It called this a “misunderstanding” between the two companies over whether the test setup had internet access, when in fact it did.

Anthropic said it isn’t placing blame and is “approaching the fixes as if the responsibility were ours alone,” while observing that Irregular is conducting its own separate investigation.

Because of that open connection, the model gained unauthorized access to the production infrastructure of three different organizations. Anthropic said the incidents involved three different Claude models: Opus 4.7, Mythos 5, and an internal research test model.

Notably, Anthropic said that in each of these cases “Claude was explicitly told by our prompt that it had no internet access.” It appears that the AI model assumed real-world systems to be part of the exercise it was asked to perform.

That assumption didn’t hold up uniformly, as it turns out. The three models didn’t behave the same way once evidence emerged that their targets were real, which Anthropic flagged as one of the more eye-opening findings Thursday.

Opus 4.7, the oldest of the three, recognized that it had reached a real production system in all four runs of that incident. In two of them, it rationalized that the real company must somehow be part of the exercise, but in all four, it kept attacking anyway, including pulling credentials and touching a database of production data. Mythos 5 also picked up on signs that it was on the real internet, but it talked itself back into believing it was still in a simulation, going on to publish a malicious software package to the public Python software registry PyPI, which was then downloaded and run by outside systems before being caught. Only the internal research test model, Anthropic’s newest, stopped on its own once it concluded the target was real.

In response, Anthropic said significant controls must be placed on these kinds of evaluations if powerful AI models are involved, echoing some sentiments within the cybersecurity community.

The company also noted that Claude was running without the additional safety monitoring and classifiers it deploys on generally available models — safeguards it said would have blocked the behavior, because the evaluations are designed to measure the underlying model’s raw capabilities.

Importantly, Anthropic said it found no evidence of any model “pursuing a goal of its own” and instead merely tried to complete the task it was asked to do.

Though comparisons between the mishaps of these fiercely competitive companies are inevitable, Anthropic in its blog post drew a clear distinction between its cybersecurity tests and those of OpenAI, noting where OpenAI’s model exploited an unknown software vulnerability to break out of its test environment, Anthropic’s models instead reached the internet through a path that had, by mistake, been left open.

Anthropic also drew a distinction between itself and OpenAI by noting that it discovered the incidents itself, through a proactive review, and that the two affected organizations it was able to reach hadn’t previously detected the activity or flagged it to Anthropic. (In contrast, Hugging Face detected the recent intrusion of its own systems first; it was only in the following days that OpenAI identified and disclosed that its own AI agent was the perpetrator.)

The company added that it’s now working with the independent evaluation group METR on a third-party review of the incidents.

OpenAI’s accidental breach of Hugging Face, which was the first verifiable case of an AI lab losing control of its model, has sparked a string of wildly differing reactions from the industry and politicians. This latest disclosure from Anthropic ensures the debate over AI models and security will continue.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

#Anthropic #models #breached #companies #security #tests #TechCrunchAnthropic,OpenAI

Post Comment