Urgent.News

What's breaking now, across thousands of outlets.

AI

Researchers used Claude to breach OpenAI's internal systems

A security research company said Friday it managed to break into OpenAI’s internal systems using the latest software from Anthropic, exposing how quickly the technology can carry out sophisticated cyberattacks. The researchers from security firm Hacktron said they found a security flaw in OpenAI’s public help forum, run by the Discourse platform, that allowed them to take control of the site. “We…

Researchers used Claude to breach OpenAI's internal systems

A security research company, Hacktron, reported on Friday that they successfully infiltrated OpenAI's internal systems using Anthropic's Claude Opus 4.8 software. The breach began with identifying a security flaw on OpenAI's public help forum, which is powered by the Discourse platform. Hacktron immediately informed both OpenAI and Discourse of the vulnerability and collaborated with them to resolve the issue.

OpenAI confirmed the flaw was patched within around 14 hours of being notified, and rewarded Hacktron with a $6,500 payout. Drew Pusateri, an OpenAI spokesperson, stated that the company revised permissions for Community sign-in tokens and revoked affected tokens and sessions. Initially, Hacktron found it challenging to consistently exploit the software flaw using Claude Opus 4.8.

However, after Anthropic released Claude Opus 5, the researchers managed to execute a working hack within approximately three hours. The researchers did not utilize Claude Mythos, a more potent Anthropic model, which is reserved for a select group of cyber-defence organizations. Anthropic has noted that Mythos possesses the strongest cybersecurity capabilities among any models it has developed.

Hacktron mentioned that the underlying software flaw is not unique to OpenAI, as it is utilized across various companies' products, such as Slack and Meta. The firm plans to conduct similar tests on other companies. This incident heightens concerns among security experts that AI tools are accelerating and reducing the cost of carrying out sophisticated cyberattacks that previously demanded specialized teams and months of effort.

Written by urgent.news from Dawn's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at dawn.com →

More in AI

More from Friday 18 September →