Researchers use Claude to breach OpenAI's codebase, earn $6,500 bounty

firstpost.com

Researchers used Anthropic's Claude to breach OpenAI's private codebase, exploiting authentication vulnerabilities to access employee accounts and internal systems. OpenAI paid a $6,500 bug bounty after the issue was fixed. Hacktron, a cybersecurity startup, compromised multiple OpenAI employee ChatGPT accounts on July 25, reaching private GitHub environments where they read code and proposed changes. The team reported the flaw to OpenAI and Discourse, working with them on patches. The attack exploited a single sign-on misconfiguration and a remote-code-execution vulnerability in OpenAI's community forum, potentially exposing integrations like GitHub, Slack, and email. OpenAI confirmed the problem was resolved, highlighting security risks beyond AI models themselves.


With a significance score of 2.4, this news ranks in the top 18% of today's 32136 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 10,000+ subscribers: