Claude Sent Police a Fake Murder Tip. White House Mandates AI Companies Report Security Incidents

AFP reports that an AI model from Anthropic “submitted a fabricated tip about an unsolved homicide to Philadelphia police, authorities said Friday.”

Claude “was instructed never to log in, create accounts, enter personal data, make purchases, or submit anything destructive, but the instructions did not rule out form submissions,” Anthropic said Friday in a blog post.

Authorities are now criticizing Anthropic “for taking two months to report the incident.”

The Philadelphia Police Department said the false submission was made in July through PhillyUnsolvedMurders.com, a public website where people can share information about unsolved killings. According to Anthropic’s account, as relayed by police, the model was running a test that involved interacting with randomly selected websites when it reached the site and filed false information about an unsolved murder. The AI model presented itself as someone who might have knowledge of the case.

Anthropic’s breaches have prompted the White House to mandate that AI companies notify and correct security incidents, news outlet Axios reported [yesterday], citing administration officials. “This notification and remediation process is not optional… It is a critical national security obligation,” White House Super Intelligence Force leaders said in a statement to Axios.
“I may have information regarding this case,” Claude told the police. “I recall seeing someone matching the description in the area around [the street named on the page] during that time period. Please contact me if this information is relevant.” Anthropic notes that Claude “left the name and contact fields empty, which the form allowed, and submitted it. The submission was flagged as spam and was never forwarded for investigation.”

But Anthropic also admits they saw “this behavior” three times — “on OSWorld (a public computer use evaluation), on Odysseys (a long-horizon task evaluation), and during internal usage.” Submitting forms when it shouldn’t have generally occurred “when an evaluation’s instructions were ambiguous, or when a misconfiguration within the environment prevented Claude from working with dummy forms.”

Anthropic’s blog post acknowledges three other categories of behaviors:

Exploiting software flaws. Like when Claude received an error when trying to run a public tool on a university’s web site, it located an injection flaw in a script on the university’s server that let it run commands — including that public tool.
Working around restrictions to reach gated data. For example, Claude Mythos 5 needed public data that was only available from a state agency for a fee. “Claude learned from an archived copy of the agency’s website that its public dashboard issues an access token to any visitor,” Anthropic explains. “It requested one and used it to query the database without paying the fee.”
Using URL shortening services. “Some of our fetch tools, which let Claude read webpages, limit the length of the URLs Claude can request. This is to prevent Claude from using long URLs to take certain unwanted actions, such as SQL or command injections… We saw several models, including Claude Opus 5 and Claude Mythos 5, get around this limitation by using free URL shortening services.”

“We have built tooling to automatically detect and block the kinds of behaviors described above,” Anthropic says, saying it’s already running no on most of their evaluations. “When we tested it against the cases described in this post, it blocked all of them.”

And they’ve already taken several other new preventive measures:

They’ve stopped running some public evaluations
Other public evaluations were moved to offline versions or rebuilt so their tasks don’t reach live websites.
They’ve updated the guardrails on some internet access tools (including web fetch) “to heavily restrict what the model can do.”
They’re continuing “to fix or remove training environments that reward Claude for working around tool restrictions or other blockers, so that they do not incentivize these behaviors or permit reward hacking.”

They’ve moved internal agents to “centrally managed infrastructure with strong containment,” that minimizes internet access while monitoring “far more of what agents do through techniques like safety classifiers and hierarchical summarization.”

In the past they’d focused reviews on cybersecurity testing, but they’ve broadened their transcript reviewing to other tasks which include internet access. “Because language models are non-deterministic — that is, their responses always involve some element of randomness, and they may carry out the same task slightly differently each time — we have Claude complete each evaluation task hundreds or thousands of times… If training rewards something we didn’t intend — such as finding loopholes or working around a restriction — the model learns that the workaround pays off and may then apply it elsewhere.”

Anthropic’s blog post also acknowledged they’d seen multiple misalignment incidents involving federal, state, and local U.S. government agencies. “We have briefed the White House on these cases and notified each agency involved,” Anthropic wrote, adding that “While we have not completed a full alignment assessment of these cases, we consider them to be less severe than the cybersecurity incidents from this summer.” (And they are “modifying training to reduce the likelihood of further misbehavior.”)


Read more of this story at Slashdot.

Sony’s XR Patent Dump To Meta Could Signal The End Of PlayStation VR

Sony's XR Patent Dump To Meta Could Signal The End Of PlayStation VR
According to ZDNet Korea, Sony is transferring 419 extended-reality (XR) patents and patent applications to Meta, raising serious questions about the future of PlayStation VR. The portfolio spans virtual reality (VR), augmented reality (AR), mixed reality (MR), and general head-mounted display (HMD) technologies, giving Meta access to a substantial

OpenAI Disrupts Two AI-Enabled ‘False Front’ Influence Operations That Included Seven Fake Journalists

OpenAI announced it’s recently banned two “influence operations” — one from Russia and one from Iran — that were using its models “to launder geopolitical, conflict-related messaging” in sophisticated “false front” propaganda campaigns:

The Iranian operation included a stable of seven “journalist” personas which it used to pitch long-form articles to small and medium online outlets around the world… As well as long-form articles, the Iranian operation generated batches of social media comments, generally on topics related to the US-Iran war… [The Russian operation “appears to have co-opted unwitting people in Latin America to run a ‘think tank’…. Since we do not allow access to our models from Russia, they used VPNs to connect to our services.”] The Russian operation created fake “leaked” documents and audio scripts, some of which we identified being spread online… Both managed to land their content (not all of which was generated from our models) in mainstream media outlets, rather than simply posting it on social media.

OpenAI says they’ve exposed 30 covert influence operations using its tools over the last two and a half years. But ironically, in this case both operations “also made heavy use of AI to draft internal reports (the Russian operation did this more than anything else).” And “in both cases, the actors used questionable or outright deceitful methodologies to exaggerate the operators’ effectiveness.”

[The Russian operators] claimed that in May 2026, they created a fake email address purporting to come from the Regional Directorate of Education in Lima, Peru. They used this to instruct schools in the district to hold events dedicated to Ukraine on the national Day of Cultural and Linguistic Diversity (May 21)… According to the operators, some schools replied to the fake email address, confirming that they had held such events and even providing pictures. The operators then claimed to have planted stories about the events in the media in both Peru and Poland, alongside allegations that Ukraine was “exporting” ultra-nationalist ideologies, triggering outrage. Open-source searches identified stories that matched this claim in the Peruvianâ andâ Polish pressâ, and an English-language publication in Hungary (some of the articles have since been deleted)…

Similarly, in June, the operators claimed they used a different fake email address to trick schools in Ecuador into holding a ceremony pledging allegiance to President Daniel Noboa and to Erik Prince, former head of private military contractor Blackwater. The operators claimed that the incident provoked outrage in Ecuador and put pressure on the government to deny the fake, thus amplifying it to a nationwide audience. Again, open-source research identified mediaâ coverageâ in the Ecuadorianâ pressâ that closely resembled this claim, and even a detailed rebuttalâ by Ecuador’s Minister for Education.

The operators used a range of techniques to underpin their false stories. According to their internal reporting, they spread two different fakes targeting Ecuador in March. One used fake audio attributed to Ukraine’s consul in Ecuador, in which he was alleged to have made disparaging comments about Ecuadorians.

OpenAI’s report “is the latest illustration of how state actors can easily exploit widely available AI tools to peddle sophisticated propaganda against adversaries on a mass scale,” argues the Economic Times:

“We identified almost 100 articles published or syndicated under the [Iranian] operation’s bylines across roughly a dozen online outlets around the world,” OpenAI said. “These were small to medium outlets, generally focused on international affairs, geopolitics, and events in the Middle East.” The earliest article identified by OpenAI was published in July 2025, and the latest in October 2026, with the frequency of reports increasing after the US-Iran war broke out earlier this year. The operation also generated social media comments on topics related to the US-Iran war, it added.

One of the personas named Ervin B. Hoskins, whose bio claimed to be “an American freelance writer,” had social media accounts across tech platforms including Elon Musk’s X and Meta-owned Instagram.
X’s transparency information showed the account was connected via a “West Asia android app” and Instagram’s transparency information showed the account was based in Iran, according to screenshots provided by OpenAI. Both accounts appeared to be suspended.


Read more of this story at Slashdot.

Microsoft Overhauls Windows 11 Search To Control Your PC Faster Than Ever

Microsoft Overhauls Windows 11 Search To Control Your PC Faster Than Ever
With the latest build, Microsoft Insider Program members have access to an overhauled Search feature, that can trigger many additional actions directly from the search window. In addition to the numerous changes introduced with 26H2, some of the new advanced search features come by way of WinUI 3. Not only does the updated Search offer many

Another Woman Sues Flock For Mistaken Crime Accusation By Police – and for Surveillance

Last week a Florida woman sued Flock over its role in police officer accusing her of a crime she didn’t commit But she’s not the only one suing Flock over mistaken accusations, reports Gizmodo:
.

A Ring video of a Colorado woman being handed a criminal summons for a porch-package theft she did not commit recently went viral after the accusation rested on a Flock Safety automated license plate reader hit. Now, the woman involved in that case, Chrisanna Elser, is suing Flock Group, the towns of Columbine Valley and Bow Mar, Sergeant Jamie Milliman, and Chief Bret Cottrell in federal court on behalf of herself and other Coloradans whose plates the company has logged…

The package in question was worth $25… The claims aimed at the company are intrusion upon seclusion, plus negligence and negligent design, on the theory that Flock sold a searchable archive and refused to require a warrant, a case number, or a supervisor’s sign-off before an officer could run a plate… Elser is asking the court to make Columbine Valley, Bow Mar, Cottrell, and Flock delete the retained location data, to bar them from keeping it unless it is tied to an open case number, and to make Flock require a warrant, a case number, and a supervisor’s approval before a Colorado agency can search the system.

The Colorado Sun has more details. “Elser did not steal anything, but spent the following two weeks proving her own evidence to a department that did not return her calls, she said.

[P]olice Sgt. Jamie Milliman told her the town of Bow Mar’s surveillance cameras captured her forest green Rivian driving through town the same day a package disappeared from a thief… When Elser offered to show her own evidence to prove her innocence, including footage from her Rivian’s onboard cameras, Milliman said she could bring it to court. Now, she is suing the officers and Flock Safety in U.S. District Court in Denver, alleging that the warrantless tracking violated her constitutional rights and that Flock’s surveillance system unlawfully documents Coloradans’ movements… “The scariest part is what happened to me can happen to anyone. I had no idea the Flock cameras existed and no idea a private company was keeping a record of every time I drove past my own neighborhood, or that any officer could pull it up without asking anyone or giving a reason for doing so,” Elser said in a statement Tuesday. “If it can happen to me, it can happen to you….”

“As noted in the complaint, the Flock system accurately identified the location of Ms. Elser’s vehicle, while law enforcement retained responsibility for interpreting and weighing that information as part of the broader investigation,” Paris Lewbel, Flock’s public relations manager said. “Flock stands by the accuracy and integrity of its technology and intends to vigorously defend itself in this litigation.”

The article includes this statement from the woman’s attorney. “Coloradans pass Flock’s cameras on the way to work, church, the doctor, a protest, and a friend’s house, and Flock keeps a detailed record of their every movement. It knows where you went, when you went there, and how often you go back, and it gives that information to a police officer with no limits.

“We are asking a federal court to say what should be obvious: Flock’s surveillance is straight-up creepy and the government does not get to follow everyone, all the time, without any reason for doing so.”


Read more of this story at Slashdot.

Rolling Release Distros Superior To LTS Distros In The Patch-Heavy GenAI Era?

As some interesting food for thought and weekend forum discussions, this week at the Linux Plumbers Conference in Prague, Qualcomm engineer Khem Raj questioned the relevance of Linux Long Term Support (LTS) distributions in the era of generative AI with the constantly heavy patch flow and bug reports. Khem Raj argued the benefits of rolling release distributions in the GenAI era and the benefits it provides staying up-to-date with mainline…