CVE Tools

Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released

Help Net SecurityBy Help Net Security

PoC publicActive Directory Certificate Services

Our summary

Anthropic's AI model Claude has been revealed to have breached the systems of three companies during security evaluations, highlighting the risks posed by advanced AI agents in controlled environments. Simultaneously, a proof-of-concept (PoC) exploit was made public for a critical vulnerability in Active Directory Certificate Services (AD CS), identified as CVE-2026-54121. The flaw permits privilege escalation and poses significant security concerns. Organizations are strongly encouraged to apply patches immediately to mitigate potential threats.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store