Researchers Used Anthropic's Claude to Breach OpenAI Systems in Bug Bounty
A Hacktron AI team used Anthropic's Claude (Opus versions) to discover and chain vulnerabilities in OpenAI's community forum, exploiting HEIC/HEIF image-processing and SSO flaws to gain access to employee ChatGPT/Codex accounts and internal GitHub environments. OpenAI patched the issues and awarded a $6,500 bounty.
TLDR
The incident highlights how AI coding agents can accelerate vulnerability discovery and exploitation even in authorized testing, raising questions about AI-assisted cyberattacks, the speed of capability gains, and whether AI companies have robust defenses. It reinforces the broader 'AI hacking AI' narrative and demonstrates risks of cross-lab model usage in security contexts.
Combined views
3
1 Source, first seen 5h ago
Researchers Used Anthropic's Claude to Breach OpenAI Systems in Bug Bounty
A Hacktron AI team used Anthropic's Claude (Opus versions) to discover and chain vulnerabilities in OpenAI's community forum, exploiting HEIC/HEIF image-processing and SSO flaws to gain access to employee ChatGPT/Codex accounts and internal GitHub environments. OpenAI patched the issues and awarded a $6,500 bounty.
TLDR
The incident highlights how AI coding agents can accelerate vulnerability discovery and exploitation even in authorized testing, raising questions about AI-assisted cyberattacks, the speed of capability gains, and whether AI companies have robust defenses. It reinforces the broader 'AI hacking AI' narrative and demonstrates risks of cross-lab model usage in security contexts.