Anthropic’s Claude helped cybersecurity researchers breach OpenAI: report | The Express Tribune

Anthropic's Claude helped cybersecurity researchers breach OpenAI: report | The Express Tribune

Anthropic’s Claude helped cybersecurity researchers breach OpenAI: report

Hacktron team says it accessed OpenAI’s internal code repository before reporting vulnerabilities to company

Jacob Coxon leaves the AI industry after working on pretraining AI models at Anthropic. AFP

A three-person cybersecurity research team used Anthropic’s Claude Opus 5 to exploit vulnerabilities in an OpenAI community forum, take control of employee accounts and demonstrate access to the company’s private code repository

The operation began on July 23 and was carried out by researchers from Hacktron AI, who disclosed the vulnerabilities to OpenAI and stopped testing without examining the company’s

The Wall Street Journal, which interviewed the researchers and first reported the incident, said OpenAI paid the team $6,500 for its discovery

The researchers reported the OpenAI-side vulnerability through the company’s bug-bounty programme. Testing of the third-party forum software itself, however, was outside the scope of OpenAI’s bounty programme

Read: OpenAI’s rogue agents probed Hugging Face for weaknesses two months before major hack

The researchers, Harsh Jaiswal, Mohan Pedhapati and Rahul Maini, published a detailed technical account explaining how they combined a flaw in the software behind OpenAI’s community forum with a separate problem in the company’s sign-on system

The attack began at community.openai.com, a help forum powered by the third-party discussion platform Discourse

Hacktron found that certain uploaded image formats were processed through ImageMagick and a vulnerable version of the image-decoding library libheif. The vulnerability allowed specially prepared image data to trigger remote code execution, meaning an attacker could potentially run commands on the forum’s server

A separate identity-management flaw then allowed the researchers to move from a compromised forum session to ChatGPT and Codex accounts belonging to active forum members, including OpenAI employees

Because those accounts could be connected to other services, the potential reach extended to platforms including GitHub, Slack and Outlook

To demonstrate the impact without reading confidential material, the researchers instructed a compromised employee’s Codex account, which was connected to OpenAI’s GitHub organisation, to open a harmless pull request in the company’s private “openai/openai” monorepo, the central digital vault housing the core

The team said it stopped testing immediately afterwards and updated its report to OpenAI

LATEST

Anthropic’s Claude helped cybersecurity researchers breach OpenAI: report

King Charles warns AI leaders of ‘existential dangers’

Former Rockstar developer’s studio reportedly shutting down after MindsEye struggles

Chinese AI not powerful enough to see rogue-AI risks, says Huawei

German court rules Meta liable for fake ads on Instagram, Facebook

US Senate blocks AI ‘kill switch’ bill amid debate over superintelligence risks

MOST READ

Khuhro regrets ‘unintentional’ remarks about Field Marshal Asim Munir

Makkah defence pact has reached point of implementation: Defence Minister Khawaja Asif

Islamabad ATC sends Imaan, Hadi on judicial remand after SC orders release on bail

‘Four-day working week’ notification circulating online is fake: MoIB

Full time VCs appointed for single term

Cantt building scam exposed

OPINION

Stories from another time

Pakistan Art Chronicles: new chapter in art documentation

Generosity is not a substitute for justice

Transformation in the global order

AI – the story of greed and capitalism

New currency of respect

Related:
<a href="https://yoursite.com/automation-training-benin/" title="Digital Automation Training Benin: 5 Winning Skills Employers Demand in 2026“>
Digital Automation Training Benin: 5 Winning Skills Employers Demand in 2026

<a href="https://yoursite.com/automation-africa/" title="WhatsApp Marketing Automation Africa: 6 Dangerous Mistakes Brands Make in Nigeria”>
WhatsApp Marketing Automation Africa: 6 Dangerous Mistakes Brands Make in Nigeria

Want to learn this practically?

Join Justfine Infotech and build real digital skills in AI, automation, web development, digital marketing, office productivity, e-commerce, freelancing and cybersecurity.

Available Programmes:
6 Weeks Certificate • 3 Months Professional Certificate • 6 Months Diploma • Full Professional Diploma

WhatsApp:
+229 01 57 57 99 15
+229 01 66 68 11 60

Enroll Now

Source: tribune.com.pk

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top