Claude couldn't hack OpenAI. Then Anthropic shipped Opus 5 (thenewstack.io)

🤖 AI Summary
Hacktron AI's security researchers recently demonstrated a significant vulnerability in OpenAI's systems, exploiting a memory-corruption bug in the Discourse forum software due to inadequate image processing. Using Anthropic’s newly released Claude Opus 5 model, they adapted an exploit for a heap buffer overflow in an outdated version of the ImageMagick library. Within hours of deploying Opus 5, they achieved remote code execution on OpenAI's community forum, ultimately gaining access to an OpenAI employee’s Codex account, which was linked to the company’s private GitHub repositories. This incident underscores the growing capability of AI models in security research and exploitation, as the Hacktron team successfully executed the attacks with minimal human intervention. The ease with which Claude Opus 5 adapted to these challenges indicates a potential shift in the landscape of cybersecurity, allowing AI to take on more complex tasks traditionally reserved for human experts. OpenAI has since responded by tightening security measures, including revising the permissions on community sign-in tokens. The whole operation, dubbed "HEIF Heist," cost under $3,000 and highlights the urgent need for robust vulnerability disclosures in open-source software to prevent similar exploits in the future.
Loading comments...
loading comments...