|
    Theme
    Tech Verified Story

    Anthropic's Claude helped cybersecurity researchers breach OpenAI: report

    Saba QamarSeptember 18, 2026 2 min read
    Text Size
    Anthropic's Claude helped cybersecurity researchers breach OpenAI: report
    Tech CoverageAman-e-Pakistan Digital Desk
    Key Story Executive Summary
    Quick Read

    A three-person cybersecurity research team used Anthropic’s. Claude Opus 5to exploit vulnerabilities in an OpenAI community forum, take control of employee accounts and demonstrate access to the company…

    The operation began on July 23 and was carried out by researchers from Hacktron AI, who disclosed the vulnerabilities to OpenAI and stopped testing without examining the company’s source code. The Wall Street Journal, which interviewed the researchers and first reported the incident, said OpenAI paid the team $6,500 for its discovery.

    The researchers reported the OpenAI-side vulnerability through the company’s bug-bounty programme. Testing of the third-party forum software itself, however, was outside the scope of OpenAI’s bounty programme. Read:OpenAI's rogue agents probed Hugging Face for weaknesses two months before major hack.

    The researchers, Harsh Jaiswal, Mohan Pedhapati and Rahul Maini, published a detailed technical account explaining how they combined a flaw in the software behind OpenAI’s community forum with a separate problem in the company’s sign-on system. The attack began atcommunity.openai.com, a help forum powered by the third-party discussion platform Discourse.

    Key Story Takeaway

    "Stay connected with Aman-e-Pakistan for ongoing live reporting and verified investigative updates."

    Hacktron found that certain uploaded image formats were processed through Image. Magick and a vulnerable version of the image-decoding library libheif. The vulnerability allowed specially prepared image data to trigger remote code execution, meaning an attacker could potentially run commands on the forum’s server.

    A separate identity-management flaw then allowed the researchers to move from a compromised forum session to ChatGPT and Codex accounts belonging to active forum members, including OpenAI employees. Because those accounts could be connected to other services, the potential reach extended to platforms including Git.

    Hub, Slack and Outlook,. Read more:OpenAI, Anthropic and Google are working to create an AI standards body. To demonstrate the impact without reading confidential material, the researchers instructed a compromised employee’s Codex account, which was connected to OpenAI’s Git.

    Hub organisation, to open a harmless pull request in the company’s private “openai/openai” monorepo, the central digital vault housing the core source code for all its AI systems. The team said it stopped testing immediately afterwards and updated its report to OpenAI.

    S

    Written by Saba Qamar

    Aman-e-Pakistan Senior Journalist & Bureau Reporter

    Fact Checked & Verified

    Continue Reading: More in Tech

    Swipe or click arrows to explore Tech desk coverage

    Founder of Chinese startup Spirit AI says robot brains set for 2027 breakthroughTech

    Founder of Chinese startup Spirit AI says robot brains set for 2027 breakthrough

    Read Story
    Archaeologist claims secret 'code' hidden in Great Pyramid may reveal ancient wonder's true purposeTech

    Archaeologist claims secret 'code' hidden in Great Pyramid may reveal ancient wonder's true purpose

    Read Story
    Prince Harry makes first public appearances since return to UKTech

    Prince Harry makes first public appearances since return to UK

    Read Story
    Anthropic says Claude now leads a quarter of work building its next AI modelsTech

    Anthropic says Claude now leads a quarter of work building its next AI models

    Read Story
    Regulated exchanges to boost freelancer inflowsTech

    Regulated exchanges to boost freelancer inflows

    Read Story
    King Charles warns AI leaders of 'existential dangers'Tech

    King Charles warns AI leaders of 'existential dangers'

    Read Story