
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Security researchers uncovered a chain of vulnerabilities in Anthropic's Claude.ai platform, dubbed "Claudy Day," allowing attackers to silently exfiltrate sensitive user data and redirect users to malicious sites via prompt injection, API misuse, and open redirects. Anthropic has patched the main flaw and is addressing remaining issues.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Claude.ai) explicitly mentioned and describes vulnerabilities in its use and security that have directly led or could lead to harm by enabling attackers to exfiltrate sensitive information without user consent or knowledge. This fits the definition of an AI Incident because the AI system's malfunction (security vulnerabilities) has directly led to harm (privacy violations and data theft). The responsible disclosure and ongoing patching do not negate the incident classification, as the harm or risk of harm is realized or imminent.[AI generated]