Tech News
← Home  ·  All topics

Hacktron Ai

2 GoKawiil briefs on this topic

Security firm Hacktron used Anthropic's Claude to breach OpenAI employee accounts

A three-person team at startup Hacktron AI used Anthropic's Claude AI model to chain two vulnerabilities together, gaining access to several OpenAI employees' ChatGPT accounts and internal systems through OpenAI's bug-bounty program. The entry point traced back to a flaw in Discourse, the third-party forum software OpenAI uses, triggered through a routine image upload. OpenAI paid Hacktron $6,500 and says it has since patched the vulnerabilities.

White-hat hackers breach OpenAI's internal codebase via Discourse forum flaw

Cybersecurity firm Hacktron AI disclosed that its researchers exploited a chained vulnerability—an outdated image-processing library on OpenAI's Discourse forum combined with an SSO misconfiguration—to hijack employee ChatGPT and Codex accounts and reach OpenAI's private code repository. To prove the breach, they submitted a harmless pull request to OpenAI's internal monorepo before reporting the flaws through OpenAI's bug bounty program. OpenAI patched the issue within 14 hours and paid the team a $6,500 bounty.