Urgent.News

What's breaking now, across thousands of outlets.

AI

Researchers penetrate OpenAI systems with Claude models

Security researchers participating in OpenAI’s bug bounty programme penetrated employee accounts and reached the company’s private GitHub monorepo after using Anthropic’s Claude models to develop an exploit chain. The July operation was carried out by three researchers at cybersecurity start-up Hacktron AI, who said they combined a vulnerability in software used by OpenAI’s community forum with a…

Three security researchers from cybersecurity firm Hacktron AI penetrated OpenAI systems using Anthropic's Claude models, according to new reporting. The July operation began with a memory-safety flaw in libheif, an image-decoding library used by OpenAI's Discourse forum. By exploiting this vulnerability through image uploads, the researchers gained remote-code execution and administrative access.

The researchers then used Claude Opus 5 to create a proof-of-concept pull request in OpenAI's private repository, which allowed them to demonstrate the level of access they had gained. OpenAI patched the issue and paid the researchers a $6,500 bounty. The researchers emphasized that human judgment was still necessary to determine the extent of testing, as Claude Opus 5 is designed with certain cybersecurity restrictions. The underlying Discourse vulnerability was rated 8.8 on the CVSS scale.

Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at thearabianpost.com →

More in AI

More from Sunday 20 September →