FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
    Filters
      Symbols
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      Security Researchers Use Anthropic’s Claude to Penetrate OpenAI’s Private Software Cache

      Independent security researchers participating in an OpenAI bug-hunting program used Anthropic’s Claude to gain access to OpenAI’s private cache of software, the Wall Street Journal reported Friday (Sept. 18).

      The researchers from Hacktron AI reached the software by using Claude to gain access to an OpenAI employee’s ChatGPT account. Once they saw that they could reach OpenAI’s GitHub service, a software repository, the researchers stopped and reported their findings to OpenAI, because they didn’t want to access sensitive data, according to the report.

      In a Sunday (Sept. 13) blog post, Hacktron AI said: “Until two months ago, any user or OpenAI employee logging into OpenAI’s own help forum … could have had their ChatGPT and Codex accounts taken over. Since people can connect various services to Codex and ChatGPT, the scope of what we could theoretically access was huge, including GitHub, Slack and emails.”

      According to the WSJ report, OpenAI paid the team a $6,500 bounty as part of the AI startup’s bug-hunting program, which invites researchers to try to break into its corporate systems to stress-test its digital infrastructure.

      The researchers began their hack on July 23, per the report.

      Hacktron AI Chief Technology Officer Mohan Pedhapati told the WSJ: “I don’t think we are as strong as Chinese threat actors. We’re just three guys with Claude and Codex subscriptions.”

      An OpenAI spokesperson said in the report that the issues discovered by the researchers have been resolved.

      “We thank the researchers for contacting us and sharing their findings,” the OpenAI spokesperson said in the report. “We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions.”

      In Hacktron AI’s blog post, the researchers said AI has changed the software environment in which complexity used to provide a form of security, because exploiting vulnerabilities required expertise, time and knowledge of the target.

      “This was never a real security boundary, but it protected ordinary companies in practice from software vulnerabilities,” the researchers said in the post. “AI is removing that protection by turning more of this scareexpertise into compute. Work that required a well-resourced team and months of effort can now be compressed into days.”

      It was reported in August that after a series of cyberattacks by AI models from companies like Anthropic, Meta and OpenAI, cyber insurance firms are rethinking their policies.

      PYMNTS reported Thursday (Sept. 17) that several prominent figures in frontier AI have commented on a proposed slowdown in the technology’s development over the past week after some high-profile incidents in which AI agents went rogue on the open internet.


      Source: PYMNTS.com
      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud