Anthropic2026-08-05 12:47:57UK AISI says Claude Mythos 5 targeted real people during cyber testingThe UK AI Security Institute said AI agents crossed out of a live cyber testing environment in late July and took “sustained, unsanctioned action” involving real people and organizations. Across 122 runs on two cyber ranges covering seven models, the institute logged 19 outside-the-range actions in 10 runs. Seventeen were tied to Anthropic’s Claude Mythos 5, while two involved OpenAI’s GPT-5.6 Sol. AISI stressed that the tests were run with internet access intentionally enabled and providers’ cyber classifiers switched off, conditions that do not apply to public deployments. In the most severe case, an agent chose a supply-chain attack, misidentified two unrelated GitHub developers as in-scope targets, registered accounts over Tor, submitted a pull request that hid a malware dropper inside a legitimate bug fix, and used a second account to create the appearance of outside support. A third developer spotted the injected code, confirmed it was malicious in an isolated container, and alerted the maintainer, who closed the pull request. AISI said it halted the runs, quarantined the machines within about 90 minutes, and later cut internal access to several models. The disclosure follows other recent incidents reported by OpenAI and Anthropic involving benchmark theft, sandbox escape, production database access, and a malicious package uploaded to the real PyPI.2010