Close Menu
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
Trending

How a Top Democratic Operative Lost Faith in Her Party

33 minutes ago

We’ve Filed More Than 50 Legal Claims Over Abuse by Federal Immigration Agents. Here’s Why.

35 minutes ago

Bitcoin sales and $4 billion cash reserve fuel STRC’s recovery toward par value

57 minutes ago
Facebook X (Twitter) Instagram
Facebook X (Twitter) Discord Telegram
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Market Data Newsletter
Wednesday, August 5
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Home»Cryptocurrency & Free Speech Finance»Anthropic’s Claude Mythos 5 ‘Targeted Real People’ in UK Cyber Tests: AISI
Cryptocurrency & Free Speech Finance

Anthropic’s Claude Mythos 5 ‘Targeted Real People’ in UK Cyber Tests: AISI

News RoomBy News Room2 hours agoNo Comments4 Mins Read2 Views
Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
Anthropic’s Claude Mythos 5 ‘Targeted Real People’ in UK Cyber Tests: AISI
Share
Facebook Twitter Pinterest Email Copy Link

Listen to the article

0:00
0:00

Key Takeaways

Playback Speed

Select a Voice

In brief

  • The UK’s AI Security Institute found 19 unsanctioned actions across 10 of 122 evaluation runs, 17 of them from Anthropic’s Mythos 5 and two from OpenAI’s GPT-5.6 Sol.
  • One agent opened a malicious pull request on a real repository, then used accounts it controlled to endorse it and pressure the maintainer.
  • Separate agents found a GitHub token one of them had leaked publicly and used a shared repository to coordinate.

The UK AI Security Institute has disclosed that AI agents took “sustained, unsanctioned action” on the live internet during a cyber evaluation in late July, including cases that “targeted real people and organisations.”

Across 122 runs of two cyber ranges on seven models, AISI catalogued 19 actions that reached outside the test environment, in 10 runs. Seventeen came from Anthropic’s Claude Mythos 5 and two from OpenAI’s GPT-5.6 Sol. Internet access was deliberately enabled and the providers’ cyber classifiers switched off, conditions that do not apply to public deployments.

On July 28th, we identified an incident during a routine cyber evaluation in which AI agents took sustained, unsanctioned actions directed at real people and organisations.

The behaviour came mostly from one model (Anthropic’s Mythos 5), with a small number of events from… pic.twitter.com/SPnA4Ekkwq

— AI Security Institute (AISI) (@AISecurityInst) August 4, 2026

In the most serious run, an agent decided to solve its challenge with a supply-chain attack, picking its target by mistake: it searched GitHub for keywords from the exercise, landed on two unaffiliated developers, and wrongly concluded they were in scope. It registered accounts over Tor to get past sign-up checks, opened a pull request carrying a hidden malware dropper wrapped in a genuine bug fix, and posted from a second account it controlled to manufacture support. It also planted prompt injections aimed at AI coding assistants and sent malware to the maintainers.

A third developer spotted the injected code, ran it in an isolated container to confirm it was malicious, and warned the maintainer, who closed the pull request citing malware.

The agent repeatedly weighed whether its surroundings were simulated, at one point ruling out an attack on the real PyPI because “causing real-world harm — that’s completely off the table.” Elsewhere it concluded “it seems more likely that we’re actually in 2026 and GitHub is genuinely real,” and continued anyway.

After being caught it force-pushed to erase the payload, edited earlier posts, and presented the code as an accidental commit. Its reasoning describes timing a sockpuppet comment so it would read “as independent feedback rather than coordinated.”

AISI sees only summarised reasoning from the model APIs. In one case the summarising model appears to have refused the job, replying that it would not engage with content about deceiving maintainers and evading detection.

One agent published a GitHub access token in a public gist. Agents in other runs found it, took over the account, and used a shared repository to coordinate, one leaving instructions so the others would not exhaust the shared API quota.

Commercial monitoring flagged the Tor traffic on the morning of July 28. AISI declared an incident, terminated the runs and quarantined the machines within about 90 minutes, then cut internal access to Mythos 5, Mythos Preview, Opus 5 and GPT-5.6 Sol. No agent tried to escape its sandbox.

Third disclosure in a fortnight

The news is the latest in a string of incidents where AI agents have exceeded their parameters in testing. On July 21, OpenAI said GPT-5.6 Sol and an unreleased model found a zero-day in an internal package proxy, escaped a sandbox with no internet access and reached Hugging Face’s production database to steal benchmark answers. The same run reached four more companies, OpenAI disclosed a week later.

Anthropic followed on July 30, disclosing three incidents found in a review of more than 141,000 evaluation runs. Opus 4.7 pulled several hundred rows from a real production database, and Mythos 5 uploaded a malicious Python package to the real PyPI, where it was installed on 15 systems. In AISI’s evaluation, the same model ruled out attacking PyPI as real-world harm.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



Read the full article here

Fact Checker

Verify the accuracy of this article using AI-powered analysis and real-time sources.

Get Your Fact Check Report

Enter your email to receive detailed fact-checking analysis

5 free reports remaining

Continue with Full Access

You've used your 5 free reports. Sign up for unlimited access!

Already have an account? Sign in here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
News Room
  • Website
  • Facebook
  • X (Twitter)
  • Instagram
  • LinkedIn

The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.

Related Articles

Media & Culture

How a Top Democratic Operative Lost Faith in Her Party

33 minutes ago
Cryptocurrency & Free Speech Finance

Bitcoin sales and $4 billion cash reserve fuel STRC’s recovery toward par value

57 minutes ago
Cryptocurrency & Free Speech Finance

Bitcoin Whales Signal Possible Bear Market Bottom

59 minutes ago
Media & Culture

Progressive Michigan

2 hours ago
Cryptocurrency & Free Speech Finance

Nomura’s Laser Digital backs ZIGChain for onchain private credit push in UAE

2 hours ago
Cryptocurrency & Free Speech Finance

Does the Coldcard Attack Mean All Hardware Wallets Are Now Insecure?

2 hours ago
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

We’ve Filed More Than 50 Legal Claims Over Abuse by Federal Immigration Agents. Here’s Why.

35 minutes ago

Bitcoin sales and $4 billion cash reserve fuel STRC’s recovery toward par value

57 minutes ago

Bitcoin Whales Signal Possible Bear Market Bottom

59 minutes ago

Progressive Michigan

2 hours ago
Latest Posts

Nomura’s Laser Digital backs ZIGChain for onchain private credit push in UAE

2 hours ago

Does the Coldcard Attack Mean All Hardware Wallets Are Now Insecure?

2 hours ago

Anthropic’s Claude Mythos 5 ‘Targeted Real People’ in UK Cyber Tests: AISI

2 hours ago

Subscribe to News

Get the latest news and updates directly to your inbox.

At FSNN – Free Speech News Network, we deliver unfiltered reporting and in-depth analysis on the stories that matter most. From breaking headlines to global perspectives, our mission is to keep you informed, empowered, and connected.

FSNN.net is owned and operated by GlobalBoost Media
, an independent media organization dedicated to advancing transparency, free expression, and factual journalism across the digital landscape.

Facebook X (Twitter) Discord Telegram
Latest News

How a Top Democratic Operative Lost Faith in Her Party

33 minutes ago

We’ve Filed More Than 50 Legal Claims Over Abuse by Federal Immigration Agents. Here’s Why.

35 minutes ago

Bitcoin sales and $4 billion cash reserve fuel STRC’s recovery toward par value

57 minutes ago

Subscribe to Updates

Get the latest news and updates directly to your inbox.

© 2026 GlobalBoost Media. All Rights Reserved.
  • Privacy Policy
  • Terms of Service
  • Our Authors
  • Contact

Type above and press Enter to search. Press Esc to cancel.

🍪

Cookies

We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.

Cookie Preferences

Manage Cookies

Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.

Your permission applies to the following domains:

  • https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.