Anthropic says three Claude models compromised the companies after a testing misconfiguration exposed the AI to the public internet.