Anthropic’s Claude helped cybersecurity researchers breach OpenAI: report
Hacktron team says it accessed OpenAI’s internal code repository before reporting vulnerabilities to company
Jacob Coxon leaves the AI industry after working on pretraining AI models at Anthropic. AFP
A three-person cybersecurity research team used Anthropic’s Claude Opus 5 to exploit vulnerabilities in an OpenAI community forum, take control of employee accounts and demonstrate access to the company’s private code repository
The operation began on July 23 and was carried out by researchers from Hacktron AI, who disclosed the vulnerabilities to OpenAI and stopped testing without examining the company’s
The Wall Street Journal, which interviewed the researchers and first reported the incident, said OpenAI paid the team $6,500 for its discovery
The researchers reported the OpenAI-side vulnerability through the company’s bug-bounty programme. Testing of the third-party forum software itself, however, was outside the scope of OpenAI’s bounty programme
Read: OpenAI’s rogue agents probed Hugging Face for weaknesses two months before major hack
The researchers, Harsh Jaiswal, Mohan Pedhapati and Rahul Maini, published a detailed technical account explaining how they combined a flaw in the software behind OpenAI’s community forum with a separate problem in the company’s sign-on system
The attack began at community.openai.com, a help forum powered by the third-party discussion platform Discourse
Hacktron found that certain uploaded image formats were processed through ImageMagick and a vulnerable version of the image-decoding library libheif. The vulnerability allowed specially prepared image data to trigger remote code execution, meaning an attacker could potentially run commands on the forum’s server
A separate identity-management flaw then allowed the researchers to move from a compromised forum session to ChatGPT and Codex accounts belonging to active forum members, including OpenAI employees
Because those accounts could be connected to other services, the potential reach extended to platforms including GitHub, Slack and Outlook
To demonstrate the impact without reading confidential material, the researchers instructed a compromised employee’s Codex account, which was connected to OpenAI’s GitHub organisation, to open a harmless pull request in the company’s private “openai/openai” monorepo, the central digital vault housing the core
The team said it stopped testing immediately afterwards and updated its report to OpenAI
LATEST
Anthropic’s Claude helped cybersecurity researchers breach OpenAI: report
King Charles warns AI leaders of ‘existential dangers’
Former Rockstar developer’s studio reportedly shutting down after MindsEye struggles
Chinese AI not powerful enough to see rogue-AI risks, says Huawei
German court rules Meta liable for fake ads on Instagram, Facebook
US Senate blocks AI ‘kill switch’ bill amid debate over superintelligence risks
MOST READ
Khuhro regrets ‘unintentional’ remarks about Field Marshal Asim Munir
Makkah defence pact has reached point of implementation: Defence Minister Khawaja Asif
Islamabad ATC sends Imaan, Hadi on judicial remand after SC orders release on bail
‘Four-day working week’ notification circulating online is fake: MoIB
Full time VCs appointed for single term
Cantt building scam exposed
OPINION
Stories from another time
Pakistan Art Chronicles: new chapter in art documentation
Generosity is not a substitute for justice
Transformation in the global order
AI – the story of greed and capitalism
New currency of respect
Related:
<a href="https://yoursite.com/automation-training-benin/" title="Digital Automation Training Benin: 5 Winning Skills Employers Demand in 2026“>
Digital Automation Training Benin: 5 Winning Skills Employers Demand in 2026
<a href="https://yoursite.com/automation-africa/" title="WhatsApp Marketing Automation Africa: 6 Dangerous Mistakes Brands Make in Nigeria”>
WhatsApp Marketing Automation Africa: 6 Dangerous Mistakes Brands Make in Nigeria
Want to learn this practically?
Join Justfine Infotech and build real digital skills in AI, automation, web development, digital marketing, office productivity, e-commerce, freelancing and cybersecurity.
Available Programmes:
6 Weeks Certificate • 3 Months Professional Certificate • 6 Months Diploma • Full Professional Diploma
WhatsApp:
+229 01 57 57 99 15
+229 01 66 68 11 60
Source: tribune.com.pk



