ZeroHour
Product

Discourse Cloud

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Security researchers used Claude to help them hack into OpenAI

Three Hacktron researchers used Claude Opus to breach OpenAI employee accounts through a Discourse HEIF flaw, reaching the Monorepo within 72 hours.

A three-person team at Hacktron used Anthropic's Claude Opus 4.8 and 5 to exploit a HEIF image-processing flaw in Discourse, achieving RCE on Discourse Cloud and access to OpenAI's community forum instance within roughly a day of Claude Opus 5's July 24 launch. They reached OpenAI's GitHub Monorepo through employee accounts and proved access with a pull request from an employee's Codex account. Their HEIF Heist tooling adapted to targets including OpenAI, Slack, Meta, and GitHub Enterprise for under $3,000 in tokens, and was detected by only one target, Shopify. Discourse and OpenAI have since fixed the reported vulnerabilities, and OpenAI paid a $6,500 bounty.

The Verge · AIupdated · 56m agofirst · 2h agoAI safety & security in the wild 9 sources