Researchers used Anthropic’s Claude to hack into OpenAI
Scored daily by a customisable AI persona to surface the most relevant engineering leadership news.
Novel use of AI agents for cybersecurity, highly relevant to AI/ML and security.
Security researchers at Hacktron AI used Anthropic's Claude Opus 5 to chain two vulnerabilities—a libheif memory bug in Discourse forum software and a subsequent account takeover—to access OpenAI employee ChatGPT and Codex accounts, earning a $6,500 bug bounty. The exploit succeeded only after Opus 5 was released, as Opus 4.8 failed to produce a working exploit, highlighting how rapidly improving AI models can lower the barrier for sophisticated attacks. The libheif bug had been patched months earlier but lacked a CVE identifier, leaving Discourse running the vulnerable version.