Search
Close this search box.

Anthropic’s Claude Aids Cybersecurity Breach in OpenAI Forum: Report

Anthropic's claude opus 5 has been instrumental in a cybersecurity breach that targeted an openai community forum. a three-person team from hacktron ai exploited vulnerabilities:erson team from Hacktron AI exploited vulnerabilities, gaining control over employee accounts and accessing OpenAI's private code repository. The operation, initiated on July 23, was halted after the vulnerabilities were disclosed to OpenAI, with no examination of the company's source code.

According to Anadolu Agency, the incident was first reported by The Wall Street Journal, which interviewed the researchers involved. OpenAI acknowledged the breach by compensating the team with $6,500 for uncovering the security lapse. The Hacktron AI researchers, Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini, reported the vulnerabilities through OpenAI's bug-bounty programme. However, the scope of the programme did not cover the third-party forum software that was tested.

The researchers detailed their method, which involved exploiting a flaw in the software behind OpenAI's community forum, coupled with a problem in the company's sign-on system. The breach began at community.openai.com, a forum using the Discourse platform. Hacktron AI discovered that certain image formats were being processed through ImageMagick and a vulnerable version of the libheif library. This vulnerability allowed remote code execution, permitting attackers to run commands on the forum's server.

Further investigation revealed an identity-management flaw that enabled the researchers to transition from a compromised forum session to ChatGPT and Codex accounts of active forum members, including OpenAI employees. These accounts had the potential to connect to other services such as GitHub, Slack, and Outlook.

To illustrate the scope of the breach without accessing confidential information, the team used a compromised employee's Codex account to open a harmless pull request in OpenAI's private 'openai/openai' monorepo on GitHub. The testing was concluded immediately thereafter, and the team updated OpenAI with their findings.

Source: Anadolu Agency