anthropic20 articles
Capital One Releases AI Vulnerability Hunter to the Public
Capital One has open-sourced an internally developed AI-powered security tool called VulnHunter, designed to identify and fix software vulnerabilities at the code level. Unlike traditional scanners, it uses an agentic reasoning workflow to map attack paths, propose targeted code fixes, and reduce false positives that slow developer workflows. The company released it publicly on GitHub, citing the need for widely distributed defensive tools to address the interconnected risks of modern software supply chains.
Claude for Chrome Still Has an Unpatched Extension Hijack Bug, Eight Versions On
A security flaw in the Claude for Chrome extension allows any rogue browser extension with access to claude.ai to forge a synthetic click that triggers Claude to read a user's Gmail, Google Docs, or Calendar, bypassing the intended trust boundary. While an approval prompt exists in default mode, users who have enabled "Act without asking" receive no warning at all, earning the vulnerability a CVSS score of 9.6 Critical. Manifold Security reported both this issue and a related flaw involving a URL parameter that bypasses permission checks in May 2025, but as of July 14th, eight versions later, neither has been patched.
CISA Is Quietly Using Anthropic's Mythos to Hunt Bugs in Federal Government Code
CISA is reportedly using Anthropic's AI model, Mythos, to scan federal government code repositories for security vulnerabilities, with sources indicating the effort has already uncovered a large number of software flaws. The initiative is led by CISA's Attack Surface Evaluation team, with the NSA also believed to be utilizing the model. Despite this growing government reliance on Mythos, Anthropic has faced political tensions with the administration over its refusal to remove safeguards against autonomous weapons and surveillance use, and its public-facing model, Fable, experienced a temporary global shutdown following a dispute over foreign access.
Anthropic Signs $19B, 20-Year Lease Despite Never Having Turned a Profit
Anthropic, which has never turned a profit, has signed a 20-year, $19 billion lease with datacenter operator TeraWulf for a 401-megawatt facility in Kentucky that isn't expected to be operational until 2027–2028. The AI startup's ability to meet its payment obligations depends on its continued success in raising capital, with an IPO expected later this year. The deal carries financial risk for both parties, as TeraWulf is restructuring its own assets to finance the project, leaving it exposed if Anthropic's fundraising falters.
Anthropic quietly buried hidden tracking code in Claude Code. Now it's removing it.
Anthropic has announced it will remove hidden steganographic code from its Claude Code tool, which was secretly embedded in system prompts to detect and flag unauthorized resellers and rival AI companies — particularly Chinese labs — attempting to copy its models through repeated queries. A developer discovered the concealed mechanism, which used invisible Unicode markers, XOR encoding, and base64 to hide a domain blacklist, raising concerns about transparency in a tool that asks users for trust. Anthropic says stronger anti-distillation measures are already in place and the code removal was merged and scheduled for release on July 1st.
US Government Forces Anthropic to Pull Its Two Most Powerful Models Worldwide Over Foreign National Access Concerns
The US government issued an export control directive ordering Anthropic to block access to its two most advanced AI models, Fable 5 and Mythos 5, for all foreign nationals, citing national security concerns. Because compliance would be impossible without disabling the models entirely, Anthropic suspended global access to both, just days after rolling out Fable 5 for free to millions of users. Anthropic disputes the justification, stating the government's evidence amounts to a narrow, already-known jailbreak, and argues that applying this standard industry-wide would effectively halt all new frontier model deployments.
Anthropic Snaps Up OpenAI's Second-Ever Chip Engineer Ahead of Rival IPOs
Anthropic has hired Clive Chan, who was the second hardware employee in OpenAI's custom chip program, as both companies prepare for IPOs. The move comes as Anthropic is reportedly exploring the development of its own AI chips, which could reduce its reliance on Google TPUs and Amazon hardware while improving profit margins. Chan's exact role at Anthropic is unclear, but his expertise in custom silicon design could help the company build a dedicated chip team.
AI Bosses Back Push for Bioweapon Screening Laws Before Someone Does Something Stupid
CEOs of major AI companies, including OpenAI's Sam Altman, Anthropic's Dario Amodei, and Google DeepMind's Demis Hassabis, have signed a public letter urging Congress to pass laws requiring synthetic DNA and RNA providers to screen customers and orders to prevent the development of biological weapons. The letter warns that rapid AI advancements are eroding the knowledge barriers that have historically kept dangerous biological agents out of bad actors' hands, making it easier to design harmful pathogens using large language models. While some voluntary screening measures already exist, signatories argue that stronger federal regulations and additional safeguards from AI companies themselves are needed to close critical gaps.
EU's Cyber Watchdog Gets Access to Anthropic's Scary Vulnerability-Finding AI
Anthropic has agreed to grant the EU's cybersecurity agency ENISA access to its powerful AI model, Mythos, through Project Glasswing — making ENISA the first European entity to join the initiative. Mythos has drawn significant concern due to its ability to autonomously discover and exploit software vulnerabilities at unprecedented speed and scale, raising fears about lowering the barrier for sophisticated cyberattacks. While the European Commission views the access as essential for assessing AI-related cyber risks, the terms are still being negotiated, and it remains unclear whether the US agency CISA has been granted similar access.
Men Use AI Coding Tools Twice as Much as Women in Social Science, Anthropic Finds
An Anthropic study of social scientists found that men use AI coding agents—tools that automatically write code—more than twice as often as women, with the gap persisting across disciplines and career levels. Economists and early-career researchers at top universities are the heaviest adopters, with code generation for data analysis being the dominant use case at 97%. While 88% of respondents are optimistic about AI boosting their own productivity, 70% are more skeptical about its broader impact on their field, citing concerns about peer review overload and research quality.
Claude Gets 28 Enterprise Security Integrations Because Apparently That's What It Takes to Trust an AI at Work
Anthropic has integrated Claude with 28 enterprise security and compliance platforms — including CrowdStrike, Microsoft, Okta, and Palo Alto Networks — to make the AI assistant easier to govern within corporate IT environments. Central to this rollout is the Claude Compliance API, which gives security teams programmatic access to conversation content and activity logs, allowing them to apply existing monitoring policies to Claude just as they would other workplace software. Organizations already using one of the supported platforms can connect Claude with minimal setup, with data flowing automatically into their existing dashboards and workflows.
How a Lobster Mascot and a Bunch of Obsessives Dragged the AI Agent Era Into Existence
In late 2025, Anthropic's Claude Code — particularly the Opus 4.5 release — ignited a wave of AI agent enthusiasm among technically skilled users, enabling individuals to build and oversee complex software at a scale previously requiring entire teams. Alongside it, developer Peter Steinberger created OpenClaw, an open-source personal AI agent that became the fastest-growing project in GitHub history, drawing mainstream tech attention including a prominent endorsement from Nvidia's Jensen Huang. While the tools remain imperfect, risky, and expensive, they signal a broader shift toward autonomous AI agents that could soon reshape how all computer users work — and potentially displace many jobs in the process.
Anthropic Plans Public Release of Mythos Bug-Hunter, Admits Nobody Has the Safeguards to Do It Yet
Anthropic has announced plans to eventually make its Mythos AI model — which excels at finding security vulnerabilities in code — publicly available, but only once sufficient safeguards are developed, which the company admits do not yet exist. In the meantime, access is being expanded through its "Project Glasswing" programme to additional partners, including allied governments. Mythos has already identified over 23,000 flaws across 1,000+ open-source projects, though the volume of discoveries is straining an already overloaded security ecosystem, with many maintainers struggling to keep pace with the volume of reported vulnerabilities.
DeepSeek's 75% Price Cut Is Now Permanent. That's a 34x Gap on Output Tokens Versus GPT-5.5.
Deepseek has made its 75% price discount on its flagship model, Deepseek V4 Pro, permanent, with output tokens now priced at just $0.87 per million — roughly 34 times cheaper than GPT-5.5's $30 per million. While Deepseek V4 Pro lags behind top frontier models like GPT-5.5 and Opus 4.7 in raw performance, the dramatic price gap makes it particularly attractive for token-heavy applications like agentic AI systems. However, raw token pricing doesn't tell the whole story, as token consumption per task also significantly affects real-world costs.
Anthropic's Claude Mythos Is Finding Bugs Faster Than Anyone Can Fix Them
Anthropic's Claude Mythos Preview AI model, working with around 50 partners through Project Glasswing, identified over 10,000 critical security vulnerabilities in system-critical software within just one month, with some partners reporting a tenfold increase in bug discovery rates. However, the pace of discovery far outstrips the ability of organizations to verify and patch the flaws, with only 97 of 23,019 open-source vulnerabilities found having been fixed so far. Anthropic warns this creates a dangerous transition period where AI models can rapidly find and potentially exploit vulnerabilities faster than defenders can respond, and acknowledges that no company currently has safeguards strong enough to prevent misuse of such capabilities.
Flagged as a Pentagon Supply Chain Risk, Anthropic Is Probably Getting the NSA Contract Anyway
Despite being flagged as a supply chain risk by the Pentagon due to its refusal to allow unrestricted lawful use of its technology, Anthropic will likely continue supplying its Claude-based "Mythos" model to the NSA, with the arrangement personally approved by White House Chief of Staff Susie Wiles. Mythos is reportedly the only short-term solution for the NSA's classified networks because it can run on older chips, unlike models from competitors that require Nvidia's latest hardware. A contract being finalized includes a clause preventing the model from processing Americans' data, and the White House intends to use it as a template for future AI agreements.
Anthropic Buys Stainless: SDK Infrastructure as the New AI Moat
Anthropic is acquiring Stainless, an SDK and developer tooling company, for reportedly over $300 million, as part of its broader strategy to control more of the AI technical stack. The deal is notable because Stainless currently generates SDKs used by Anthropic's rivals, including OpenAI and Google, and the platform is set to shut down on September 1, 2026, forcing those competitors to find alternatives. Analysts view the move as both offensive — giving Anthropic insight into competitor API development and dominance over integration tooling — and defensive, preventing rivals from gaining the same advantage.
Anthropic Quietly Fixed a Claude Code Sandbox Bypass Nobody Told You About
Anthropic quietly fixed two vulnerabilities in Claude Code's network sandbox that could have allowed attackers to bypass network restrictions and exfiltrate sensitive data. The second flaw, discovered by researcher Aonan Guan, involved a SOCKS5 null-byte injection trick that could fool the allowlist filter into permitting connections to unauthorized hosts. Guan has criticized Anthropic for lacking transparency, noting no CVE was assigned to his finding and no public disclosure or release notes warned users — though Anthropic states the fix was deployed before his bug bounty report was submitted.
Andrej Karpathy Ditches the Classroom for Anthropic's Pretraining Team
Andrej Karpathy, a prominent AI researcher and OpenAI co-founder, has announced he is joining rival AI lab Anthropic, where he will work on the pre-training team and help build a new team using Claude to accelerate pretraining research. The hire is seen as a major win for Anthropic in the intense competition for top AI talent. Karpathy, who previously led Tesla's Autopilot AI team and has become a widely followed AI educator, said he is excited to return to research and development at "the frontier of LLMs."
Margin Call: Why AI's Biggest Players Are Building on Sand
Leading AI companies like Anthropic and OpenAI are currently unprofitable, losing money even on premium subscriptions, and are under growing pressure to raise revenue while facing inevitable commoditisation of their models. Cheaper open-weight models from China and API proxy networks are eroding the pricing power of US frontier labs, with Chinese models expected to match current leaders by end of 2026. The likely long-term winners are platform gatekeepers like Apple, Google, and Microsoft, who control software distribution, while pure-play AI labs face shrinking margins and an increasingly difficult path to profitability.