AI News: Anthropic’s Claude Reportedly Used in OpenAI Breach
SEGUIR EN Google News Agregar como fuente preferida en Google Top Stories

AI News: Anthropic’s Claude Reportedly Used in OpenAI Breach

Perspectivas clave:

  • In the latest AI news, Hacktron AI researchers reportedly used Anthropic’s Claude to exploit a vulnerability in a third-party forum and gain access to multiple OpenAI employees’ ChatGPT accounts.
  • The access ultimately provided a path into OpenAI’s internal GitHub codebase; the vulnerabilities were exploited in July but disclosed publicly only now.
  • OpenAI has since fixed the vulnerabilities and paid Hacktron AI a $6,500 bug bounty for the findings.

AI news broke Thursday when researchers used Anthropic’s Claude models to penetrate OpenAI systems, according to a Financial Times report. The three researchers from Hacktron AI, a small cybersecurity firm, gained access to an OpenAI employee’s ChatGPT account.

That account helped them view private software details and propose changes. OpenAI paid the team $6,500 under its bug bounty program.

The researchers received access to an Anthropic tool built for security professionals. They exploited a configuration flaw in OpenAI’s community forum, which runs on third-party Discourse software.

From there, they reached internal sign-on systems and eventually the employee ChatGPT account linked to private GitHub repositories.

OpenAI confirmed it fixed the issues after the researchers reported the findings through its Bugcrowd program in July. “We thank the researchers for contacting us and sharing their findings,” OpenAI said.

AI News: How the Access Unfolded

According to the FT report, Hacktron AI first used Claude to analyze the Discourse forum vulnerability and generate working exploit code.

The model helped adapt the exploit across different environments. Once inside the employee’s ChatGPT account, the team could read limited internal code and submit change suggestions.

The incident remained limited. No evidence emerged of broader system compromise or data exfiltration beyond the reported access.

AI News on Hacktron AI Hack Report | Source: X
AI News on Hacktron AI Hack Report | Source: X

The disclosure arrived the same day Anthropic released fresh internal metrics. The company said Claude now leads 26 percent of its research and development work, up from just 1 percent in March. In those cases, the model completed the majority of tasks under human instruction and supervision.

Rival Models in Security Testing

The episode adds to a string of recent disclosures involving frontier models in cybersecurity evaluations. Earlier this summer, OpenAI reported AI news that one of its unreleased models broke out of a test environment and accessed Hugging Face infrastructure.

Anthropic later reviewed more than 141,000 of its own evaluation runs and found three separate incidents in which Claude models reached real production systems of external organizations. Those cases stemmed from a misconfiguration that left internet access open during testing.

In the latest case, the researchers operated under authorized bug-bounty rules. OpenAI’s payment of $6,500 reflects standard industry practice for responsible disclosure.

The researchers worked with both OpenAI and Discourse to close the gaps. AI news of this type continues to surface as companies race to harden defenses while their models grow more capable at coding and agentic tasks.

The FT report underscores that even internal employee accounts and third-party hosted forums remain attack surfaces. OpenAI has not released further technical details on the exact scope of the ChatGPT account privileges involved.

El artículo AI News: Anthropic’s Claude Reportedly Used in OpenAI Breach apareció primero en The Coin Republic.

Esto no es asesoramiento de inversión El análisis publicado aquí es solo para información. Los activos digitales son volátiles y puedes perder todo el valor de tu posición. Investiga por tu cuenta antes de actuar.

Arnold Kirimi