Three researchers used Claude to reach OpenAI’s internal code. OpenAI paid $6,500 and closed the hole in 14 hours.
Three researchers at Hacktron AI used Anthropic’s Claude to chain two weaknesses and reach OpenAI employee accounts and an internal code repository, in under 72 hours. They disclosed privately, OpenAI patched the single sign-on flaw in about 14 hours, and the team was paid $6,500. Neither weakness was an AI vulnerability, and the research paper being cited to explain the week says its authors are no longer confident the industry is on track.
Security researchers at Hacktron AI chained two weaknesses to reach OpenAI employee accounts and an internal code repository, using Anthropic’s Claude to do it. The Wall Street Journal reported the work, and Prashant Rao gathered it for Semafor alongside the week’s other AI security news.
Harsh Jaiswal, Mohan Pedhapati and Rahul Maini went from first discovery to access in under 72 hours. They reported what they found, OpenAI fixed the single sign-on weakness about 14 hours...
Copyright of this story solely belongs to thenextweb.com. To see the full text click HERE