Researchers used Anthropic's Claude to breach OpenAI systems in under 72 hours
Hacktron AI researchers chained vulnerabilities in OpenAI's community forum and SSO issues to hijack employee accounts and reach an internal GitHub monorepo using Claude specialized for cybersecurity. They reported findings through OpenAI's bug bounty program for a $6,500 reward.
TLDR
The incident highlights AI's rapidly expanding offensive capabilities, vulnerabilities in third-party tools and development environments, and the dramatic irony of one AI lab's model successfully exploiting another's systems. It amplifies calls for stronger security practices in AI development environments and demonstrates how model improvements are enabling new attack vectors.
Combined views
1
1 Source, first seen 4h ago
Researchers used Anthropic's Claude to breach OpenAI systems in under 72 hours
Hacktron AI researchers chained vulnerabilities in OpenAI's community forum and SSO issues to hijack employee accounts and reach an internal GitHub monorepo using Claude specialized for cybersecurity. They reported findings through OpenAI's bug bounty program for a $6,500 reward.
TLDR
The incident highlights AI's rapidly expanding offensive capabilities, vulnerabilities in third-party tools and development environments, and the dramatic irony of one AI lab's model successfully exploiting another's systems. It amplifies calls for stronger security practices in AI development environments and demonstrates how model improvements are enabling new attack vectors.