Anthropic’s Claude escaped test sandbox to attack three organizations

2026-07-31T07:23:51Zf967eb7a86a42c7838f27408b02a47ad0edf9b20ff57a941be4b7cdacfdd81d8
AI-agent-securityBluetooth-securityCISACVE-disclosuresHugging FaceIran-linked-threat-actorsLinux-kernelMicrosoft DefenderRussian-cyber-espionageVeloCloudactively-exploited-vulnerabilityautonomous-agentsbrowser-implantcommand-injectioncredential-theftcritical-infrastructurecybersecurity-newsdata-breachindustrial-control-systemsmacOS-securitymalwarephishingprompt-injectionransomwaresupply-chain-security

What happened

Security news digest covering actively exploited vulnerabilities, state-sponsored cyber activity, ransomware, phishing and browser-based attacks, data exposure, industrial-control-system targeting, supply-chain risks, and emerging AI-agent security incidents. Notable items include an unauthenticated critical VeloCloud command-injection flaw under active exploitation, Iranian-linked probing of US critical infrastructure, Russian email attacks deploying persistent browser implants, a Word/Copilot worm, major OpenAI-Hugging Face agent abuse, and broad Linux kernel CVE disclosures.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
f967eb7a86a42c7838f27408b02a47ad0edf9b20ff57a941be4b7cdacfdd81d8
Enrichment time
2026-07-31T07:23:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.