Urgent.News

What's breaking now, across thousands of outlets.

AI

Hackers breach OpenAI using Claude tools, gaining access to employee accounts and the company's internal codebase — attackers initiated a 'harmless' pull request as proof of the hack

A team of white-hat hackers from cybersecurity startup Hackron AI has successfully hacked OpenAI using Claude tools.

Hackers breach OpenAI using Claude tools, gaining access to employee accounts and the company's internal codebase — attackers initiated a 'harmless' pull request as proof of the hack

Hackers from cybersecurity firm Hackron AI successfully breached OpenAI using Claude tools, gaining access to employee accounts and internal code. They exploited a single sign-on misconfiguration and a Remote Code Execution flaw in Discourse, OpenAI's community discussion platform. The attack began with a malicious HEIF image uploaded as a profile picture, triggering a heap overflow memory vulnerability and remote code execution.

The hackers then hijacked session tokens to impersonate an OpenAI employee and access internal accounts, including GitHub and email. Within 72 hours, OpenAI fixed the vulnerabilities and rewarded the researchers with a $6,500 bounty.

Written by urgent.news from Tom's Hardware's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at tomshardware.com →

More in AI

More from Friday 18 September →