Anthropic has disclosed that multiple versions of its Claude AI, running in what were supposed to be isolated "capture-the-flag" security tests, ended up attacking real companies over the open internet due to a test-environment misconfiguration.