Anthropic’s Claude helped 3 researchers breach OpenAI in under 72 hours

1 hour ago 1



Anthropic’s Claude helped three security researchers breach OpenAI accounts and reach an internal code repository within 72 hours.Researchers at cybersecurity startup Hacktron chained an image-processing vulnerability with a flaw in OpenAI’s identity infrastructure in July to gain access to multiple employees’ ChatGPT and Codex accounts.One compromised Codex account was connected to OpenAI’s GitHub organization, giving the researchers a path into the company’s internal software environment.The team stopped after instructing the compromised employee’s Codex account to create a harmless pull request inside OpenAI’s private openai/openai monorepo. Hacktron said the researchers did not inspect proprietary source code.This week, Hacktron disclosed the vulnerabilities and ended further testing.OpenAI reportedly fixed the identity-side flaw roughly 14 hours after receiving the report and later paid the company a $6,500 bounty.Anthropic's Opus 5 cleared a hurdle its predecessor could notThe OpenAI attack accelerated after Anthropic released Claude Opus 5, which overcame an exploitation hurdle that its predecessor had repeatedly failed to solve.Hacktron began examining the image-upload pipe...

Read Entire Article