Anthropic’s Claude helped 3 researchers breach OpenAI in under 72 hours

Share

Three security researchers from startup Hacktron used Anthropic’s Claude to discover and chain two vulnerabilities in OpenAI, gaining access to ChatGPT and Codex accounts as well as the company’s internal code repository in under 72 hours in July. The Opus 5 model overcame a technical hurdle that its predecessor Opus 4.8 could not solve, compressing exploit development from months to days, although guidance from experienced human researchers remained essential. A compromised Codex account was connected to OpenAI’s GitHub organization, providing a path into the company’s internal software environment. OpenAI fixed the identity flaw approximately 14 hours after notification and paid Hacktron a $6,500 bounty. The incident highlights how AI coding agents concentrate permissions around a single compromised account, multiplying risks for companies integrating them into their development workflows.

Source: Read the original article

Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Lire la Suite

Articles