What an SSH Tunnel Actually Does and When You Should Use One

What an SSH Tunnel Actually Does and When You Should Use One

Learn how SSH tunnels securely forward network traffic, when local, remote, and dynamic forwarding help, and why they are best for controlled, temporary access.

Listen to this article

What an SSH Tunnel Actually Does and When You Should Use One

0:00

Press play to start listening

An SSH tunnel is a practical way to move network requests through an encrypted Secure Shell session. It addresses several real access problems with very little infrastructure. Teams rely on it to reach private services, protect older protocols, and work around awkward routing gaps. Its job is simple: it gives a chosen connection a protected route, without exposing the destination system directly to the public internet.

What It Really Moves

So, what is an SSH tunnel? The answer is less mysterious than the name suggests. A tunnel takes one stream of application traffic and carries it inside an encrypted SSH session to another machine. No service is copied or relocated. The path changes, while the original application continues to function as it normally would.

How the Path Works

First, an SSH client opens a trusted session with a remote host. After that, SSH creates an extra channel inside that session for forwarded requests. The application continues to use its normal protocol, which can include database queries or web requests. From the laptop, the service can appear to be local. On the other end, however, the destination receives traffic through SSH rather than from a direct external connection.

Local and Remote Forwarding

Local forwarding is the pattern most administrators meet first. A chosen port on the laptop listens for requests, then SSH sends them to a private service running elsewhere. This setup is useful for databases, internal dashboards, and maintenance interfaces. It also helps protect older protocols that lack sound transport security. The application remains private, while the operator gains temporary access through a more secure pathway.

Remote forwarding reverses that arrangement. A remote host opens a listening port, then traffic arriving there travels back through SSH to a service on the local machine. This is handy for demonstrations, support sessions, or testing a workstation app from outside the office. It also helps where home routers or address translation block inbound access. Outbound SSH works, so the return path becomes possible.

Dynamic Forwarding

Dynamic forwarding behaves more like a flexible proxy than a fixed connection. Instead of naming one destination in advance, the SSH client accepts requests and relays them onward as needed. Browsers commonly use this mode through a local proxy setting. That can help during short troubleshooting sessions or temporary access from a restricted network. It should be used cautiously, serving as a tool for controlled access rather than a means to bypass established policies.

When a Tunnel Should Be Used

An SSH tunnel is most effective when the need for access is narrow and short-lived. Private databases are a common use case. Internal web tools, maintenance consoles, and one-off diagnostics are also suitable for this approach. Opening a firewall rule for a brief task often creates more exposure than value. A tunnel keeps visibility limited. Once the work is complete, the session can close, and the access path disappears with it.

When It Is the Wrong Tool

Long-running production paths can become unstable when they depend on one user session and one workstation remaining operational. Shared team access can become complicated without centralized policies, audit trails, and clear ownership. Heavy traffic can strain a setup built for convenience. If many people require access consistently, a managed private access method usually makes more sense.

Basic Security Limits

Encryption protects the route, but it does not eliminate every risk around it. Weak encryption keys, careless host verification, or broad forwarding rules can still create exposure. Logging may also become less transparent because the destination sees proxied requests instead of the original network path. Security teams should treat tunnels as controlled exceptions. Short lifetimes, named owners, and a limited scope are just as crucial as the encryption itself.

A Quick Decision Check

A short check can prevent misuse. First, ask whether the service should remain private. Next, confirm that direct routing is blocked, unsafe, or excessive for the task. Then review who owns the session, how long access should be granted for, and how it will be closed. Clear answers typically support the use of tunneling, while vague responses often indicate the need for a more suitable long-term access design.

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts
XRP Volatility Surges as Cybersecurity Threats and Market Changes Raise New Concerns

XRP Volatility Surges as Cybersecurity Threats and Market Changes Raise New Concerns

XRP volatility drives faster crypto trading as AI tools gain traction, while phishing, exchange attacks and automation risks test digital asset safeguards.

XRP’s price volatility continues to attract the attention of both traders and cybersecurity professionals. As one of the world’s most actively traded cryptocurrencies, XRP frequently experiences rapid price swings driven by changing investor sentiment, regulatory developments, and broader market conditions. While these fluctuations create opportunities for traders, they also create conditions that cybercriminals are quick to exploit.

Even advanced algorithms and AI systems grab attention when the markets are less active. There is a greater demand for automated and reliable infrastructure to support trading. The changing nature of markets creates new risks, and so does the state of automation.

XRP price swings attract attention from traders and security experts

Across the world’s cryptocurrency exchanges, XRP is consistently one of the most heavily traded digital assets. The XRP price today serves as a key indicator for traders monitoring market sentiment, with rapid price movements attracting both short-term investors seeking to capitalize on volatility and longer-term participants assessing broader cryptocurrency market trends.

Artificial intelligence is rapidly integrated into trading, and XRP trading in particular, creating new challenges for cybersecurity experts. Cybersecurity vulnerabilities pose a greater threat when advanced algorithms for automated trading become commonplace.

When XRP prices change, traders do not wait. They become even more reliant on automated trades and even AI-driven analytics. The integration of artificial intelligence in trading creates the ability to scan and process large volumes of market data in real time. Trend identification even occurs before a human is able to execute a trade.

Automation has changed cryptocurrency markets by making them faster and more efficient. While this brings improvements, it adds frequent technological reliance. Thus, trading platforms’ resilience and security are critical now more than ever.

Live XRP price movements can also mirror sentiments in the overall market. Since XRP price movements can indicate liquidity, confidence, and volume disparities on multiple exchanges, it makes XRP a stronger tool in a cryptocurrency market analyst’s arsenal.

New risks introduced by rising cyber threats for cryptocurrency users

Market volatility creates opportunity for cybercriminals and is often exploited. Cybersecurity researchers report phishing attacks are most common. During hyperactive trading, attackers launch phishing schemes, craft fake cryptocurrency apps, impersonate legitimate exchanges, or push automated trading bots that are sold under the guise of legitimate trading tools. These bots are designed to steal credentials and crypto.

AI is becoming more prevalent in the cryptocurrency ecosystem. Aiding even more automated trading, AI assistants for trading, portfolio management, and market analysis are quickly being adopted by cryptocurrency users and institutional investors alike.

Industry research from Binance indicates a rising focus on investment relating to the fusion of artificial intelligence and digital assets, and the integration of AI within blockchain technologies. For these advancements, a growing sophistication will be required to differentiate between legitimate automated services and tools engineered for malicious purposes. Automation is spreading across industries, and with it an understanding that cybersecurity is as important as any investment, particularly when dealing with modern systems.

Market chaos projects fears of exchange system weaknesses

Unfortunately, rapid XRP trading across centralized and decentralized exchanges fosters a reliance on the exchange system to secure the best prices, particularly during volatile trading sessions.

Systems become overloaded with high volumes of trades and are tested to their limits while facilitating thousands of requests to trade. Cyber threats, phishing, credentials theft, DDoS attacks, and hostile API integration attacks pose a growing burden on exchanges.

AI will greatly enhance the ability to detect, monitor, and investigate suspicious activities, and will improve the system’s resilience against threats. However, controls and monitoring will be further challenged by AI and will malignantly facilitate phishing and other automated attacks.

As the markets for digital currencies mature and expand, the infrastructure for exchange systems must secure user assets and maintain confidence for trading.

Experts urge stronger safeguards as crypto adoption accelerates

Automated trading systems have a profound effect on crypto trading. With the market serving as a deep learning playground, AI can constantly monitor conditions, identify trades, and execute them much faster than the manual decision-making process. There is no doubt this makes the market more efficient, but it also introduces new risks.

There are many ways a bad trading algorithm, a poorly set up automation tool, or a compromised API (to name a few) can introduce a significant risk. By the time an operator is aware of the bad trade, it’s already been executed.

There are dozens of ways to reduce cyber risk. From the operator’s standpoint, secure API’s with an updated, more robust software base and defense levels using Multi-factor Authentication are significantly helpful and do the job. There is always a need to educate users, and in this context, they should be taught to use only verified platforms and wallets and to ignore unsolicited investment offers. Users still need to be wary of where and with whom they share their credentials.

Where XRP Volatility and Cyber Risk Meet

With the increasing automation of digital asset trading, the intertwining of market volatility and cyber risk has strengthened. A rapid price change equates to a large volume of trades. Combined with the ever-increasing adoption of AI, this changes the speed at which the market’s decisions and transactions are made.

Automation provides all the tools necessary to increase the speed and efficiency of trading, but this also provides attackers new ways to target a system and exploits the uncertainty of the users in the market.

Cryptocurrency exchanges are focusing on optimizing performance and security, and infrastructure continues to be expensive and difficult to manage as levels of cyber threats increase alongside trading volume and as demands for additional resilience increase.

This climate is especially true because XRP and leading cryptocurrencies actually mean something in the international markets, as evidenced by the growing number of traders and cyberthreat personnel. XRP et al. are a reminder that market wins are greatest when paired with strong cyber posture. The fastest-growing digital economy includes more automation, but confidence in the crypto market makes a strong case for the security of users and systems.

(Photo by Traxer on Unsplash)

Leave a Reply

Your email address will not be published. Required fields are marked *

Wordfence Finds Critical Backdoor in ARVE WordPress Plugin

Wordfence Finds Critical Backdoor in ARVE WordPress Plugin

A backdoored ARVE WordPress Plugin release could grant attackers administrator access with one token, but WordPress.org blocked automatic distribution to WordPress sites.

Malicious code added to a WordPress video plugin could have granted full administrator access via a single secret token, but the release was caught before it reached users via WordPress.org automatic updates.

The impacted plugin, called Advanced Responsive Video Embedder (ARVE), helps websites add videos from YouTube, Vimeo, Rumble and other services, and has about 20,000 active installations.

On July 28, Wordfence’s autonomous PRISM system flagged the code less than two hours after its introduction. The company identified the affected release as version 10.8.7, registered as CVE-2026-18072, and rated it critical with a CVSS score of 9.8 out of 10.

Wordfence said the code was likely introduced by an attacker who had gained commit access to the developer’s account. The company’s vulnerability record lists the release as unpatched.

Buried inside a file named php/fn-update-check.php, the backdoor appeared designed to pass as routine plugin update code. Its main function was registered on the WordPress init hook with priority 1, allowing it to run before normal authentication checks whenever the website received a request.

An attacker who supplied the expected value through request parameters named _wplogin or _wpm could be logged in as an existing administrator. The value was compared with a fixed SHA256 string embedded in the publicly available plugin source, effectively making it a universal credential. No password, account, user action, or brute force attempt was required.

A successful request caused the code to select an administrator account, create a persistent login cookie, and send the attacker directly to the WordPress dashboard. The website address and selected administrator’s username were also transmitted to fontswp.com, which Wordfence described as an attacker-controlled command-and-control server.

By 11:09 a.m., WordPress.org had closed the plugin for downloads. Wordfence’s timeline says the code was introduced at 8:42 a.m., detected at 10:33 a.m. and verified by its researchers ten minutes later.

Although ARVE had about 20,000 active installations, WordPress.org told Wordfence that version 10.8.7 had not yet been distributed. WordPress introduced a delay of up to 24 hours for new plugin and theme releases in June, providing time for automated scanning and human review before automatic updates are sent to websites. Ordinary automatic updates therefore should not have installed the backdoored release.

ARVE developer Nicolas Jonas said the malicious release never reached users through WordPress.org and questioned Wordfence’s advice to remove the plugin. Wordfence replied that manually installed copies or updates obtained from third parties could still contain version 10.8.7, while the plugin remained compromised and unavailable from the official repository.

Sites found running version 10.8.7 should remove it, review administrator accounts, invalidate active sessions, rotate WordPress secret keys, and inspect files and database records for unauthorized changes. Wordfence issued a firewall rule to its paid users on July 28, while users of its free service are scheduled to receive the same protection on August 27.

I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism.
Leave a Reply

Your email address will not be published. Required fields are marked *

How Status Labs Helps Brands Get Cited in ChatGPT: The Data Behind AI Search Visibility

How Status Labs Helps Brands Get Cited in ChatGPT: The Data Behind AI Search Visibility

Disclosure: This article was created in collaboration with Status Labs.

Ranking first in Google no longer guarantees a mention when a customer asks ChatGPT the same question. A study of more than half a million pages that ChatGPT pulled in found that 85 percent of them never made it into a single answer.

That gap, between being found and being cited, is where most brands quietly disappear from AI search. It is also where the reputation firm Status Labs has concentrated much of its generative engine optimization work since ChatGPT search went mainstream. The patterns that decide who gets quoted are now measurable, and they reward a specific kind of page that very few companies are actually building.

What does it mean to get cited in ChatGPT?

A ChatGPT citation is a named source inside an AI-generated answer, usually one of only one to three links the model surfaces for a given question. When someone asks ChatGPT to recommend a vendor, explain a concept, or compare options, the brands named in that reply capture the attention and the implied endorsement. Everyone else is invisible, regardless of where they sit in traditional search rankings.

The reach is substantial. OpenAI reported 900 million weekly active users in February 2026, more than double the figure from a year earlier, with the platform handling roughly 2.5 billion prompts a day. Roughly 35 percent of those prompts trigger a live web search, which is the moment a page can be retrieved and quoted. The rest are answered from the model’s trained memory, with no new sourcing involved.

Citation differs from retrieval in a way that trips up most marketing teams. Retrieval means a page entered the candidate pool that the model considered. Citation means the model selected it for visible credit in the answer. The two events are far less connected than the SEO playbook assumes, and the second one is where competition is fierce.

How does ChatGPT actually choose which sources to cite?

ChatGPT moves from question to citation in four steps: it retrieves candidate pages, evaluates them for authority and how cleanly a claim can be lifted, synthesizes an answer from several sources, and then credits only the few it leaned on most heavily. Status Labs has mapped this sequence across client campaigns, and the evaluation stage is where most pages fall out.

The clearest public data on the process comes from AirOps, a GEO measurement platform that analyzed how the model behaves at scale. Its researchers examined 548,534 pages that ChatGPT retrieved across 15,000 prompts, then tracked which ones earned a place in the final answer. According to the AirOps citation study, only 15 percent of retrieved pages were ever cited. The other 85 percent were pulled in, read, judged, and discarded before the user saw anything.

The study also showed that citation rates are not uniform. Product-discovery and how-to queries earned citations at the highest rates, 18.3 percent and 16.9 percent, while validation and comparison queries lagged at 11.3 percent and 13.1 percent. The same question type a brand targets can change its odds before a single word of the page is written.

Two on-page traits separated the cited pages from the ignored ones. Pages with at least 50 percent title-query overlap were cited 20.1 percent of the time, against 9.3 percent for pages with less than 10 percent overlap, a 2.2 times difference. Pages with clearer, more readable prose, measured by Flesch Reading Ease scores of 50 or higher, also showed up disproportionately among the cited set. The model rewards pages that name the question in the heading and answer it in plain language.

Do you need a huge domain to get cited?

No. The AirOps data found that nearly three-quarters of all citations went to sites with a domain authority under 80, and the DA 20 to 40 tier alone earned a larger share of citations than the DA 80 to 100 tier, 26.0 percent against 25.4 percent. High-authority domains were retrieved more often than any other group, yet cited at the lowest rate, 15.0 percent, once they entered the pool.

This finding reframes the competitive picture for smaller brands. Citation visibility is not a popularity contest decided by backlink count. A mid-authority site with a tightly written, well-structured page on a specific question can outperform a household name that buries its answer in promotional prose.

The academic record supports this. The foundational research on the field, the Princeton GEO study published by researchers from Princeton, Georgia Tech, the Allen Institute for AI, and IIT Delhi, tested nine optimization tactics across 10,000 queries and found that GEO techniques boosted source visibility in AI responses by up to 40 percent. The paper also found that lower-ranked sites saw some of the largest gains, because structure and evidence narrow the gap that raw authority once protected.

Does traditional SEO still matter for AI citations?

Yes, strongly. Search ranking is the on-ramp to retrieval, and the AirOps data puts a number on the advantage. Among pages ranking first in Google, 43.2 percent earned a ChatGPT citation, roughly 3.5 times the rate for pages sitting beyond Google’s top 20. More than half of all cited pages, 55.8 percent, ranked in the top 20 for at least one query on which they were credited.

The relationship is layered rather than contradictory. A small site can win a citation without a towering domain, but ranking strength still tilts the odds at every stage. Pages that already perform in Google enter the retrieval pool more often and clear the selection step more often once they are in it. The practical read for most brands is to keep traditional SEO healthy while treating extractability and evidence as the second discipline that decides who gets quoted.

That makes a specific class of page the highest-value target: existing content already ranking in positions 10 through 20 for a high-intent query. Those pages sit just outside the strongest citation zone, and tightening their structure, depth, and answer clarity can move them into it without building anything from scratch.

Which content tactics raise your citation rate the most?

The Princeton researchers ranked their tested tactics, and three stood far above the rest: adding statistics, adding direct quotations from credentialed sources, and citing other authoritative references. Adding statistics alone lifted visibility by roughly 41 percent in their benchmark. The tactics that failed are equally instructive. Keyword stuffing, the old SEO reflex, performed poorly, and padding content with filler lowered the ratio of citable claims to noise.

Status Labs builds client pages around the same hierarchy of evidence. The firm’s approach centers on a handful of repeatable moves that map directly to how the model reads a page.

  • Lead each section with a standalone answer. A 40 to 60-word reply placed directly under a question-style heading, with no links and no setup, gives the model a clean passage to lift. These answer capsules appear on the majority of cited pages.
  • Front-load the most citable claim. Research on AI citations shows a heavy bias toward the opening portion of a page, so the strongest, most specific claim belongs near the top rather than being saved for a conclusion.
  • Raise the factual density. Pages packed with named, sourced figures are cited more often than thin pages. Every section should hand the model at least one specific claim it can quote without needing the rest of the article for context.
  • Publish original data. Models cite what they cannot generate on their own. First-party survey results, internal benchmarks, and case-study metrics framed as a brand’s own give the model a concrete reason to attribute the figure rather than fold it into general knowledge.

The throughline is extractability. ChatGPT does not cite a 2,000-word essay; it lifts a few sentences from one section. If that section opens with a clean, factual answer, it becomes a candidate. If it opens with throat-clearing, the quotable line sits where the model will not look.

Why does page structure matter more than length?

Structure gives the model clean boundaries to extract from, which is why format choices often outweigh raw word count. Comparison tables, numbered steps, bulleted lists, and genuine question-and-answer blocks all hand the model discrete, liftable units instead of a wall of prose. Tables and lists in particular tend to win a disproportionate share of citations because their structure makes the relevant claim obvious.

Length still helps, but only as a byproduct. Thorough pages tend to hold more quotable sections, so they earn more citations. Word count itself is not rewarded. Padding a page to hit a length target lowers the density of citable claims, and the model reads filler as low value. The discipline is to cover a topic completely, then cut anything that does not carry a fact, a figure, or a direct answer.

Short, single-idea sections under their own headings work better than long blocks that braid several points together. Each tight section becomes its own citation candidate, and a page with a dozen of them has a dozen chances to be quoted rather than one.

What technical settings decide whether ChatGPT can see your page?

Crawler access is the entry ticket, and most sites get one detail wrong. OpenAI runs separate bots for separate jobs, and blocking the wrong one removes a site from answers without the owner realizing it. The distinctions are spelled out in OpenAI’s crawler documentation:

  • OAI-SearchBot indexes pages so they can appear in ChatGPT search answers. Sites that opted out of this bot will not show up in those answers.
  • GPTBot collects content that may be used to train OpenAI’s foundation models. It is the most-blocked AI crawler on the web.
  • ChatGPT-User handles in-session visits when a user action sends the model to a specific page.

The trap is that a blanket AI block, often added to keep content out of training data, frequently takes OAI-SearchBot down with it. Blocking the training bot is a defensible business decision. Blocking the search bot by accident quietly erases a site from ChatGPT’s answers. Any brand serious about AI visibility should confirm which agents its robots.txt file allows before doing anything else, because no amount of content work matters if the search crawler cannot reach the page.

Freshness is the other technical lever. Industry crawl data shows the majority of AI bot activity targets pages published within the past year, so stale statistics and dated examples bleed citation value over time. A refresh cadence that swaps in current figures and shows a visible last-updated date keeps high-value pages in the running.

How long does it take to get cited by ChatGPT?

Most sites that restructure existing pages for extraction see early movement within 14 to 30 days, with larger gains after roughly 60 days of consistent updates. Brands building authority from scratch should expect a longer horizon, since entity recognition across the web takes time to accumulate. As Contently reports, most teams see citation lift within four to eight weeks when they refresh existing high-traffic pages rather than starting over.

Citation is never a finished state. AI answers shift as models retrain and as competitors publish fresher material, and a brand cited heavily in one cycle can fade in the next. The work is ongoing: monitor which queries surface the brand, defend the positions already won, and expand into the adjacent questions the model branches into. That last point matters more than it sounds, because the model rarely stops at the original query.

What is query fan-out, and why should brands care?

Fan-out is the set of internal follow-up searches ChatGPT runs while building a single answer, and it opens a second surface where citations are won. The AirOps research found that 89.6 percent of prompts triggered two or more of these follow-up queries. That expansion turned 15,000 starting prompts into more than 43,000 total searches. Nearly a third of cited pages, 32.9 percent, appeared only through a fan-out query rather than the original prompt.

Most of that opportunity is invisible to standard keyword tools. The study reported that 95 percent of fan-out queries had zero monthly search volume by traditional metrics, which means brands tracking only their primary keywords never see where a meaningful share of citations actually originates. A page optimized for one head term but silent on the supporting questions, pricing, features, alternatives, and common objections leaves citations on the table.

Status Labs treats fan-out coverage as a planning input rather than an afterthought. The goal shifts from ranking for a single query to covering the cluster of follow-up questions the model generates around it. For a commercial topic, that means modular sections on comparisons and specifics. For an informational one, it means depth on the core concept and its natural extensions.

How does authority beyond your own website factor in?

ChatGPT reads signals from across the web, well beyond a brand’s own domain, so off-site presence shapes citation odds. Consistent profiles on review platforms, active discussion on community sites, and credible press coverage all function as third-party proof that a brand is a real entity worth citing. The research community frames this through entity recognition: brands mentioned frequently across independent, credible sources carry stronger entity signals, and stronger entity signals correlate with higher citation rates.

This is the part of GEO that on-page work cannot replicate alone. A perfectly structured page on a domain with no external footprint competes at a disadvantage against a page backed by a web of consistent mentions. Earned media, accurate and repeated across the places buyers check, tells the model the brand exists and matters.

Maintaining that footprint is reputation work, which is why a firm built on online reputation management is positioned to handle it. Status Labs publishes ongoing analysis of how these earned-media signals shift, and following Status Labs on LinkedIn is one way to track the patterns as they move month to month. The brands winning AI citations are rarely the loudest. They are the ones whose expertise is easy to verify and easy to quote.

How do ChatGPT citations differ from Perplexity and Google AI Overviews?

Each generative engine leans on different signals, so a page that wins in one may go unnamed in another. ChatGPT draws heavily on authoritative knowledge bases and well-structured reference content. Perplexity favors community discussion and very recent material. Google AI Overviews track more closely to top organic rankings. The overlap between platforms is thinner than most brands expect, which is why a single page rarely sweeps every engine by accident.

The strategic consequence is that AI visibility is a portfolio, not a single bet. A brand aiming to be cited across ChatGPT, Claude, Gemini, and Perplexity has to satisfy several selection logics at once: clean extractable structure for the models that reward it, fresh, dated content for the ones that prize recency, and consistent third-party presence for the ones that weigh community and review signals. Status Labs frames AI reputation work around all of those surfaces rather than optimizing for one engine and hoping the gains transfer.

The shared ground across every platform is evidence. Named statistics, credentialed quotations, and specific sourced claims travel well regardless of which model is reading, because they give any engine something concrete to attribute. That is the throughline connecting the Princeton findings, the AirOps data, and the on-page patterns: models cite what they can verify and lift, and they paraphrase away everything vague.

Getting started with AI citation optimization

The path to a ChatGPT citation runs through extractability, evidence, and access. A page needs to let the search crawler in, state its answer cleanly near the top, back that answer with named figures and credible references, and cover the follow-up questions the model will branch into. None of that requires a massive domain, which is genuinely useful news for smaller and mid-sized brands.

What it does require is treating AI search as its own discipline rather than a byproduct of traditional SEO. The original Status Labs analysis this guide builds on, How Can I Make My Website More Likely to Be Cited in ChatGPT, breaks down the twelve on-page factors and ten tactics in granular detail, with the underlying citation-factor data laid out factor by factor. For brands deciding where to start, the highest-leverage first move is usually the simplest: audit the robots.txt file, then rewrite the top three pages to open each section with a clean, sourced answer.

Owais takes care of Hackread’s social media from the very first day. At the same time He is pursuing for chartered accountancy and doing part time freelance writing.
Leave a Reply

Your email address will not be published. Required fields are marked *

Anthropic Says Claude Models Hacked 3 Organizations During Cyber Tests

Anthropic Says Claude Models Hacked 3 Organizations During Cyber Tests

Anthropic found Claude accessed systems at three real businesses after a testing error gave its AI models live internet access during cybersecurity evaluations.

A cybersecurity test designed to measure Claude’s hacking abilities ended with Anthropic models gaining unauthorized access to three real organizations after an evaluation environment was mistakenly left connected to the internet. Claude had been told it was inside a simulation with no external access, so it treated the systems it found online as part of the exercise. Anthropic disclosed the incidents on July 30.

The company began reviewing its cybersecurity evaluation transcripts after OpenAI disclosed that its own models had bypassed network restrictions and entered Hugging Face’s production systems during a cyber evaluation. As Hackread.com previously reported, the OpenAI models exploited an unknown vulnerability while searching for test answers. Anthropic reviewed 141,006 Claude evaluation runs and found six runs connected to three incidents.

During each exercise, Claude was asked to find secret information known as a flag inside a fictional network. Anthropic’s prompt said the environment was simulated and had no internet connection, but a misunderstanding with evaluation partner Irregular left live access available. The models therefore regarded real systems as test targets.

Claude Opus 4.7

One fictional company happened to share its name with a real website, leading Claude Opus 4.7 to attack the real organization during four runs. The model obtained application and infrastructure credentials, along with access to a database containing several hundred rows of production data. It continued after finding evidence that the target was real, reasoning that it might still belong to the exercise.

Claude Mythos 5

A separate exercise led Claude Mythos 5 to publish a malicious package on PyPI after finding setup instructions that referred to a nonexistent package. The malicious package remained available for about an hour and ran on 15 real systems. One belonged to a cybersecurity company whose scanner installed the package, allowing Claude to obtain credentials and access more of its infrastructure before PyPI removed the file.

Internal Research Model

Elsewhere, an internal research model scanned about 9,000 online targets after failing to reach its fictional one. It compromised a company’s application using credentials exposed on a debug page and SQL injection. Once the model recognized that the system had no connection to the exercise, it stopped.

None of the models needed advanced or previously unknown vulnerabilities in the three Anthropic incidents. They used weak passwords, exposed endpoints, and other familiar methods. Anthropic described the incidents as primarily an operational and evaluation failure, not evidence that Claude had formed an independent goal.

The test models ran without the classifiers and monitoring applied to publicly available Claude services. The dedicated evaluation infrastructure had no access to Anthropic’s internal systems or customer data.

Anthropic’s security advisory confirms that it halted its cyber evaluations on July 23, identified all three incidents the following day, and attempted to contact the affected organizations on July 27. Two had not detected the activity before Anthropic reached them and are now working with the company on remediation. Anthropic was still trying to reach the third organization when it published its account and did not disclose any names.

Reading the disclosures from both labs, Diana Kelley, chief information security officer at Noma Security, a New York City-based AI security and governance platform, said access restrictions cannot depend on an AI agent correctly understanding its surroundings.

“Don’t rely on intent, rely on controls,” Kelley told Hackread.com. She recommended isolation, least privilege, identity-based authorization, runtime controls, policy enforcement and kill switches for agents performing lengthy autonomous tasks.

Anthropic plans to validate internet access paths before tests, increase monitoring of evaluation logs and transcripts, and apply stricter checks to external vendors. It also asked other AI laboratories to review past evaluations for similar incidents.

I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism.
Leave a Reply

Your email address will not be published. Required fields are marked *