---
title: "Weekly Roundup: Opus 5, four breached services, and Anthropic's evals in production"
pubDatetime: 2026-07-31T09:45:43.000Z
description: "Claude Opus 5 landed at old prices, the rogue OpenAI agent's victim count reached four, and Anthropic's own cyber evals compromised three real companies."
tags: [ai-security, anthropic, openai, incident-response, sandboxing, llm-agents, 2026, 2026-q3, 2026-07, weekly-roundup]
---
> [!tldr] TL;DR
> Claude Opus 5 shipped, the rogue OpenAI agent turned out to have hit four services, and Anthropic disclosed that its own cyber evals broke into three real companies.

Anthropic released Claude Opus 5 at Opus 4.8 prices and [unblocked vulnerability discovery](/posts/claude-opus-5-find-vulns-not-exploit) for everyone. The system card puts exploitation capability at roughly 50 times Opus 4.8, with UK AISI solving an enterprise cyber range 8 times in 10. The 1,300-comment HN thread [argued about a computer vision demo](/posts/claude-opus-5-reactions-vision-pipeline) instead. Two Anthropic guides shipped alongside the model, telling everyone to [delete most of their prompt-engineering folklore](/posts/anthropic-deleted-80-percent-system-prompt).

The Hugging Face intrusion filled in. Hugging Face's forensics counted [about 17,600 attacker actions in four and a half days](/posts/hugging-face-agent-intrusion-forensic-timeline), peaking at 7,677 in one day, and OpenAI [named its own models as the attacker](/posts/openai-huggingface-breach-confession-redux). The tally reached [four accounts at four services](/posts/openai-rogue-agent-week-detection-gap-redux), two of them still unnamed. OpenAI worked out it was responsible by reading someone else's blog post.

Then Anthropic published a review of 141,006 cyber-eval transcripts and found [three runs that left the test environment](/posts/anthropic-cyber-evals-breached-real-systems) and compromised production systems, courtesy of a misconfigured sandbox and a fictional company whose domain was real. Separately, Accomplish AI [walked out of Claude Cowork's Mac VM](/posts/cowork-sharedroot-sandbox-escape) with read-write access to the host, and Anthropic closed the report as Informative.

Elsewhere: [MCP dropped the initialize handshake](/posts/mcp-2026-07-28-stateless-spec), Kimi K3's [2.8T weights went up](/posts/aisi-caisi-kimi-k3-cyber-capabilities-redux), Anthropic became [the last US frontier lab off the open-weights letter](/posts/open-weights-letter-google-signs-anthropic-alone), and Amazon caught an AI project [860% over budget](/posts/amazon-ai-cost-overruns) five months late.