< Back to all clusters
[TECHNOLOGY] · United States · 6 sources

started · updated

OpenAI internal systems breached by researchers using Claude AI

Cybersecurity researchers from the startup Hacktron successfully breached OpenAI’s internal systems by chaining two vulnerabilities. The researchers utilized Anthropic’s Claude models to facilitate the attack, which was completed in less than 72 hours.

The exploit began with a vulnerability in the libheif image processing library used by OpenAI’s Discourse-powered community forum. By uploading a manipulated image file, the researchers were able to execute remote code. They then leveraged a misconfiguration in OpenAI’s Single Sign-On (SSO) system to impersonate forum members and gain access to employee ChatGPT and Codex accounts.

Through these compromised accounts, the researchers accessed OpenAI’s internal GitHub repository. As a proof of concept, they created a harmless pull request within the internal monorepo without accessing sensitive data. OpenAI responded to the report by patching the vulnerabilities within 14 hours and awarded the researchers $6,500 through its bug bounty program.

Entities

Anthropic · ChatGPT · Claude · GitHub · Hacktron · Hacktron AI Inc. · OpenAI

Claims

What the coverage asserts, and how many sources carry each claim.

  • [● 3 SOURCES] Researchers gained access to OpenAI’s internal GitHub code repository and created a harmless pull request as proof of concept. the-decoder.de · siliconangle.com
  • [● 3 SOURCES] OpenAI has patched the exploited vulnerabilities and provided a reward through its bug bounty program. siliconangle.com · www.nbcnews.com
  • [● 2 SOURCES] The cyberattack was completed in less than 72 hours. the-decoder.de · www.nbcnews.com
  • [● 3 SOURCES] The security group Hacktron used Anthropic’s Claude models to infiltrate OpenAI’s internal systems. the-decoder.de · siliconangle.com
  • [● 3 SOURCES] A misconfiguration in OpenAI’s Single Sign-On (SSO) system allowed attackers to impersonate forum members and take over ChatGPT and Codex accounts. the-decoder.de · siliconangle.com · www.nbcnews.com
  • [● 2 SOURCES] A vulnerability in the libheif image processing library used by OpenAI’s community forum allowed for remote code execution via manipulated image files. the-decoder.de · siliconangle.com
  • [○ 1 SOURCE] OpenAI paid the researchers $6,500 through its bug bounty program. www.nbcnews.com