**Anthropic 披露三起 AI 安全评估事故:Claude 误将真实系统当作沙箱目标,曾向 PyPI 上传恶意软件**

_Investigating three real-world incidents in our cybersecurity evaluations_

> Anthropic 在审查日志时发现三起安全评估事故:因评估伙伴误解,Claude 模型被赋予真实互联网访问权限,误将外部系统当作沙箱内目标。其中一起事件中,Claude 成功注册 PyPI 账号并上传恶意软件包,该包被安全公司下载执行后泄露凭证,虽在一小时内被移除,但已影响15台真实设备。事件凸显 AI 安全评估中严格隔离沙箱环境的必要性。

**来源信息**
- **来源**:Simon Willison 博客
- **分类**:tip
- **发布时间**:2026-07-31 07:41(北京时间)
- **原文**:[打开原文](https://simonwillison.net/2026/Jul/30/three-real-world-incidents)