Cybersecurity researchers used Anthropic's Claude to breach OpenAI's internal systems

aa.com.tr

A three-person cybersecurity research team used Anthropic’s Claude Opus 5 to exploit vulnerabilities in an OpenAI community forum, take control of employee accounts, and demonstrate access to the company’s private code repository. The operation began on July 23 and was carried out by researchers from Hacktron AI, who disclosed the vulnerabilities to OpenAI and stopped testing without examining the company’s source code. The Wall Street Journal, which interviewed the researchers and first reported the incident, said OpenAI paid the team $6,500 for its discovery. The researchers reported the OpenAI-side vulnerability through the company’s bug-bounty programme. Testing of the third-party forum software itself, however, was outside the scope of OpenAI’s bounty programme. The researchers, Harsh Jaiswal, Mohan Pedhapati and Rahul Maini, published a detailed technical account explaining how they combined a flaw in the software behind OpenAI’s community forum with a separate problem in the company’s sign-on system.


With a significance score of 2.9, this news ranks in the top 13% of today's 32136 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 10,000+ subscribers: