{"id":9412,"date":"2026-09-18T13:52:19","date_gmt":"2026-09-18T13:52:19","guid":{"rendered":"https:\/\/justfineinfotech.com\/anthropics-claude-helped-cybersecurity-researchers-breach-openai-report-the-express-tribune\/"},"modified":"2026-09-18T13:52:20","modified_gmt":"2026-09-18T13:52:20","slug":"anthropics-claude-helped-cybersecurity-researchers-breach-openai-report-the-express-tribune","status":"publish","type":"post","link":"https:\/\/justfineinfotech.com\/fr\/anthropics-claude-helped-cybersecurity-researchers-breach-openai-report-the-express-tribune\/","title":{"rendered":"Anthropic&#8217;s Claude helped cybersecurity researchers breach OpenAI: report | The Express Tribune"},"content":{"rendered":"<p>Anthropic&#8217;s Claude helped cybersecurity researchers breach OpenAI: report<\/p>\n<p>Hacktron team says it accessed OpenAI\u2019s internal code repository before reporting vulnerabilities to company<\/p>\n<p>Jacob Coxon leaves the AI industry after working on pretraining AI models at Anthropic. AFP<\/p>\n<p>A three-person cybersecurity research team used Anthropic\u2019s Claude Opus 5 to exploit vulnerabilities in an OpenAI community forum, take control of employee accounts and demonstrate access to the company\u2019s private code repository<\/p>\n<p>The operation began on July 23 and was carried out by researchers from Hacktron AI, who disclosed the vulnerabilities to OpenAI and stopped testing without examining the company\u2019s<\/p>\n<p>The Wall Street Journal, which interviewed the researchers and first reported the incident, said OpenAI paid the team $6,500 for its discovery<\/p>\n<p>The researchers reported the OpenAI-side vulnerability through the company\u2019s bug-bounty programme. Testing of the third-party forum software itself, however, was outside the scope of OpenAI\u2019s bounty programme<\/p>\n<p><strong>Read:\u00a0<\/strong>OpenAI&#8217;s rogue agents probed Hugging Face for weaknesses two months before major hack<\/p>\n<p>The researchers, Harsh Jaiswal, Mohan Pedhapati and Rahul Maini, published a detailed technical account explaining how they combined a flaw in the software behind OpenAI\u2019s community forum with a separate problem in the company\u2019s sign-on system<\/p>\n<p>The attack began at community.openai.com, a help forum powered by the third-party discussion platform Discourse<\/p>\n<p>Hacktron found that certain uploaded image formats were processed through ImageMagick and a vulnerable version of the image-de<a href=\"https:\/\/justfineinfotech.com\/fr\/vibe-coding-is-not-going-away-aws-darko-mesaros-on-ai-and-the-future-of-coding\/\" title=\"\u2018Vibe coding is not going away\u2019: AWS\u2019 Darko Mesaro\u0161 on AI and the future of coding\">coding<\/a> library libheif. The vulnerability allowed specially prepared image data to trigger remote code execution, meaning an attacker could potentially run commands on the forum\u2019s server<\/p>\n<p>A separate identity-management flaw then allowed the researchers to move from a compromised forum session to ChatGPT and Codex accounts belonging to active forum members, including OpenAI employees<\/p>\n<p>Because those accounts could be connected to other services, the potential reach extended to platforms including GitHub, Slack and Outlook<\/p>\n<p>To demonstrate the impact without reading confidential material, the researchers instructed a compromised employee\u2019s Codex account, which was connected to OpenAI\u2019s GitHub organisation, to open a harmless pull request in the company\u2019s private \u201copenai\/openai\u201d monorepo, the central digital vault housing the core<\/p>\n<p>The team said it stopped testing immediately afterwards and updated its report to OpenAI<\/p>\n<h2>LATEST<\/h2>\n<h3>Anthropic&#8217;s Claude helped cybersecurity researchers breach OpenAI: report<\/h3>\n<h3>King Charles warns AI leaders of &#8216;existential dangers&#8217;<\/h3>\n<h3>Former Rockstar developer\u2019s studio reportedly shutting down after MindsEye struggles<\/h3>\n<h3>Chinese AI not powerful enough to see rogue-AI risks, says Huawei<\/h3>\n<h3>German court rules Meta liable for fake ads on Instagram, Facebook<\/h3>\n<h3>US Senate blocks AI \u2018kill switch\u2019 bill amid debate over superintelligence risks<\/h3>\n<h2>MOST READ<\/h2>\n<h3>Khuhro regrets \u2018unintentional\u2019 remarks about Field Marshal Asim Munir<\/h3>\n<h3>Makkah defence pact has reached point of implementation: Defence Minister Khawaja Asif<\/h3>\n<h3>Islamabad ATC sends Imaan, Hadi on judicial remand after SC orders release on bail<\/h3>\n<h3>&#8216;Four-day working week&#8217; notification circulating online is fake: MoIB<\/h3>\n<h3>Full time VCs appointed for single term<\/h3>\n<h3>Cantt building scam exposed<\/h3>\n<h2>OPINION<\/h2>\n<h3>Stories from another time<\/h3>\n<h3>Pakistan Art Chronicles: new chapter in art documentation<\/h3>\n<h3>Generosity is not a substitute for justice<\/h3>\n<h3>Transformation in the global order<\/h3>\n<h3>AI &#8211; the story of greed and capitalism<\/h3>\n<h3>New currency of respect<\/h3>\n<div style=\"clear:both;margin:30px 0 15px 0\">\n<p>\n    <strong>Related:<\/strong><br \/>\n    &lt;a href=&quot;https:\/\/yoursite.com\/automation-training-benin\/&quot; title=&quot;Digital Automation Training Benin: 5 Winning Skills Employers Demand in <a href=\"https:\/\/justfineinfotech.com\/fr\/5-supply-chain-certifications-to-know-in-2026\/\" title=\"5 Supply Chain Certifications to Know in 2026\">2026<\/a>&#8220;&gt;<br \/>\n      Digital Automation Training Benin: 5 Winning Skills Employers Demand in 2026<br \/>\n    <\/a>\n  <\/p>\n<p>\n    &lt;a href=&quot;https:\/\/yoursite.com\/automation-africa\/&quot; title=&quot;WhatsApp <a href=\"https:\/\/justfineinfotech.com\/fr\/fsu-marketing-expert-explains-how-viral-tiktok-trends-are-shifting-consumer-habits\/\" title=\"FSU marketing expert explains how viral TikTok trends are shifting consumer habits\">Marketing<\/a> Automation Africa: 6 Dangerous Mistakes Brands Make in Nigeria&#8221;&gt;<br \/>\n      WhatsApp Marketing Automation Africa: 6 Dangerous Mistakes Brands Make in Nigeria<br \/>\n    <\/a>\n  <\/p>\n<\/div>\n<div style=\"clear:both;margin:30px 0;padding:25px;background:#f8f9fc;border:1px solid #ddd;border-radius:8px;text-align:center\">\n<h3>Want to learn this practically?<\/h3>\n<p>Join <strong>Justfine Infotech<\/strong> and build real digital skills in AI, automation, web development, digital marketing, office productivity, e-commerce, freelancing and cybersecurity.<\/p>\n<p><strong>Available Programmes:<\/strong><br \/>\n  6 Weeks Certificate \u2022 3 Months Professional Certificate \u2022 6 Months Diploma \u2022 Full Professional Diploma<\/p>\n<p><strong>WhatsApp:<\/strong><br \/>\n  +229 01 57 57 99 15<br \/>\n  +229 01 66 68 11 60<\/p>\n<p><a href=\"https:\/\/api.whatsapp.com\/send?phone=2348132690270&amp;text=Hello\" target=\"_blank\" rel=\"noopener\">Enroll Now<\/a><\/p>\n<\/div>\n<p class=\"ani-source\">Source: <a href=\"https:\/\/tribune.com.pk\/story\/2630048\/anthropics-claude-helped-cybersecurity-researchers-breach-openai-report\" target=\"_blank\" rel=\"nofollow noopener\">tribune.com.pk<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>Hacktron team says it accessed OpenAI\u2019s internal code repository before reporting vulnerabilities to company<\/p>","protected":false},"author":1,"featured_media":9414,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[71],"tags":[937,78,795,1019,841],"class_list":["post-9412","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-online-scam-alerts","tag-anthropics","tag-claude","tag-cybersecurity","tag-helped","tag-researchers"],"_links":{"self":[{"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/posts\/9412","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/comments?post=9412"}],"version-history":[{"count":1,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/posts\/9412\/revisions"}],"predecessor-version":[{"id":9413,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/posts\/9412\/revisions\/9413"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/media\/9414"}],"wp:attachment":[{"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/media?parent=9412"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/categories?post=9412"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/tags?post=9412"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}