ZeroHour
Threat actor

Hacktron

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Security researchers used Claude to help them hack into OpenAI

Three Hacktron researchers used Claude Opus to breach OpenAI employee accounts through a Discourse HEIF flaw, reaching the Monorepo within 72 hours.

A three-person team at Hacktron used Anthropic's Claude Opus 4.8 and 5 to exploit a HEIF image-processing flaw in Discourse, achieving RCE on Discourse Cloud and access to OpenAI's community forum instance within roughly a day of Claude Opus 5's July 24 launch. They reached OpenAI's GitHub Monorepo through employee accounts and proved access with a pull request from an employee's Codex account. Their HEIF Heist tooling adapted to targets including OpenAI, Slack, Meta, and GitHub Enterprise for under $3,000 in tokens, and was detected by only one target, Shopify. Discourse and OpenAI have since fixed the reported vulnerabilities, and OpenAI paid a $6,500 bounty.

The Verge · AI · 1h agoAI safety & security in the wild 2 sources

Researchers used Claude to hack OpenAI

Researchers exploited a Discourse misconfiguration on OpenAI's community forum to reach internal sign-ons and an employee ChatGPT account with GitHub code access; OpenAI fixed it.

Researchers, first reported by the Wall Street Journal, exploited a flaw in the third-party Discourse-hosted setup of OpenAI's community forum to gain access to internal sign-ons and eventually an OpenAI employee's ChatGPT account, which had access to internal code through GitHub. OpenAI thanked the researchers and said it had fixed the issues; Anthropic declined to comment and Hacktron did not immediately respond. The disclosure, which did not detail how Claude was used in the operation, coincided with Anthropic publishing data showing 26% of its R&D work was led by Claude, up from 1% in March.

Ars Technica · Securityupdated · 1h agofirst · 3h agoData breach in the wild 10 sources1