Hackers breach OpenAI using Claude tools, gaining access to employee accounts (www.tomshardware.com)

🤖 AI Summary
A team of white-hat hackers from Hackron AI successfully breached OpenAI using Claude tools, gaining access to employee accounts and the organization's internal codebase. Announcing the hack on September 18, the hackers disclosed that they exploited vulnerabilities in OpenAI's community discussion forum, including a single sign-on (SSO) misconfiguration and a Remote Code Execution (RCE) flaw in the Discourse platform. The attack chain involved uploading a malicious HEIF image to trigger a heap overflow, which enabled remote code execution and allowed them to impersonate an OpenAI employee. Their access resulted in a pull request to OpenAI’s private repository, serving as proof of the breach. This incident underscores the growing concerns regarding AI-assisted cyberattacks, particularly as tech companies increasingly integrate unified authentication systems. The Hackron researchers used Anthropic’s Claude Opus 5 model to generate a weaponized exploit based on the vulnerabilities they discovered. Despite their unauthorized access, they responsibly halted further testing and reported the vulnerabilities to OpenAI and Discourse, leading to swift resolution and a $6,500 bounty from OpenAI. The breach serves as a cautionary tale for the AI/ML community, highlighting the critical need for robust cybersecurity measures, especially when leveraging AI in developing tools and technologies.
Loading comments...
loading comments...