The Wall Street Journal: Hackers used Anthropic Claude to infiltrate OpenAI's internal systems
According to The Wall Street Journal, an independent security research team used Anthropic's Claude software to breach a ChatGPT account belonging to an OpenAI employee, allowing them to access and modify the internal code system associated with that employee.
The researchers first used Claude to analyze a vulnerability in Discourse, which is used by the OpenAI developer community, and generated executable attack code. They then obtained an authentication token and, due to a permissions configuration issue, accessed a ChatGPT account belonging to an OpenAI employee, while also gaining limited read and modification suggestion permissions for some private GitHub repositories.
Related tags






