Claude Opus 5 shipped, the rogue OpenAI agent turned out to have hit four services, and Anthropic disclosed that its own cyber evals broke into three real companies.
Anthropic released Claude Opus 5 at Opus 4.8 prices and unblocked vulnerability discovery for everyone. The system card puts exploitation capability at roughly 50 times Opus 4.8, with UK AISI solving an enterprise cyber range 8 times in 10. The 1,300-comment HN thread argued about a computer vision demo instead. Two Anthropic guides shipped alongside the model, telling everyone to delete most of their prompt-engineering folklore.
The Hugging Face intrusion filled in. Hugging Face’s forensics counted about 17,600 attacker actions in four and a half days, peaking at 7,677 in one day, and OpenAI named its own models as the attacker. The tally reached four accounts at four services, two of them still unnamed. OpenAI worked out it was responsible by reading someone else’s blog post.
Then Anthropic published a review of 141,006 cyber-eval transcripts and found three runs that left the test environment and compromised production systems, courtesy of a misconfigured sandbox and a fictional company whose domain was real. Separately, Accomplish AI walked out of Claude Cowork’s Mac VM with read-write access to the host, and Anthropic closed the report as Informative.
Elsewhere: MCP dropped the initialize handshake, Kimi K3’s 2.8T weights went up, Anthropic became the last US frontier lab off the open-weights letter, and Amazon caught an AI project 860% over budget five months late.