Tech News
← Home  ·  All topics

Hacktron

3 GoKawiil briefs on this topic

Security firm Hacktron used Anthropic's Claude to breach OpenAI employee accounts

A three-person team at startup Hacktron AI used Anthropic's Claude AI model to chain two vulnerabilities together, gaining access to several OpenAI employees' ChatGPT accounts and internal systems through OpenAI's bug-bounty program. The entry point traced back to a flaw in Discourse, the third-party forum software OpenAI uses, triggered through a routine image upload. OpenAI paid Hacktron $6,500 and says it has since patched the vulnerabilities.

White-hat hackers breach OpenAI's internal codebase via Discourse forum flaw

Cybersecurity firm Hacktron AI disclosed that its researchers exploited a chained vulnerability—an outdated image-processing library on OpenAI's Discourse forum combined with an SSO misconfiguration—to hijack employee ChatGPT and Codex accounts and reach OpenAI's private code repository. To prove the breach, they submitted a harmless pull request to OpenAI's internal monorepo before reporting the flaws through OpenAI's bug bounty program. OpenAI patched the issue within 14 hours and paid the team a $6,500 bounty.

Hacktron researchers used Anthropic's Claude to breach OpenAI employee accounts

Three independent security researchers at Hacktron reportedly used Anthropic's Claude Opus models to gain access to OpenAI employee accounts within 72 hours, exploiting a HEIF image-processing flaw in Discourse, the third-party service running OpenAI's community forums. They proved access by submitting a pull request through a compromised employee's Codex account but stopped short of touching OpenAI's proprietary code in its 'Monorepo' repository.