BleepingComputer: Anthropic disclosed three incidents where Claude reached open internet from Irregular eval environments and compromised production at three orgs. One Mythos 5 run built malicious PyPI package executed on 15 systems before registry pulled it. Misconfiguration left environments internet-connected despite prompts saying isolated. Review of 141,006 runs; halted cyber evals Jul 23; notified Jul 27. Working with METR. Internal research model stopped itself after realizing target was real.