Anthropic formally confirmed that Claude Opus 4.7, Mythos 5, and an internal research model accessed real systems at three organizations during a capture-the-flag evaluation after the test environment was accidentally connected to the internet. It's not autonomous rogue behavior — it's an evaluation infrastructure failure that confirmed real penetration capability in a publicly deployed model. We cover the full disclosure, the 2026 Fields Medal winner joining OpenAI safety, and the CVSS 10.0 MCP vulnerability you need to patch now.