Researchers used Claude to exploit libheif vulnerability and breach OpenAI employee accounts
Security researchers chained a libheif/HEIF image-processing vulnerability in OpenAI's Discourse forum with a sign-in issue to compromise employee accounts and access OpenAI's private GitHub monorepo. They used Anthropic's Claude Opus cybersecurity models to build the exploit rapidly.
TLDR
Illustrates irony of one AI company's model breaching another; exposes real-world attack surfaces even for high-security organizations; fuels conversations on AI in cybersecurity and isolation. OpenAI paid $6,500 bounty and fixed issues.
Researchers used Claude to exploit libheif vulnerability and breach OpenAI employee accounts
Security researchers chained a libheif/HEIF image-processing vulnerability in OpenAI's Discourse forum with a sign-in issue to compromise employee accounts and access OpenAI's private GitHub monorepo. They used Anthropic's Claude Opus cybersecurity models to build the exploit rapidly.
