Aggregator
Researchers Used Claude To Hack OpenAI Employee Accounts
Three security researchers used Anthropic's Claude to breach OpenAI employee accounts and gain access to private company software in a July attack that began with an image upload to the company's public help forum.
The researchers, Harsh Jaiswal, Mohan Pedhapati and Rahul Maini of Hacktron AI, described the July 25 breach in a report published September 13. They said the work took less than 72 hours from the initial discovery to demonstrating access to an internal OpenAI software repository. OpenAI subsequently paid them a $6,500 bounty.
The disclosure follows a separate incident earlier in July in which OpenAI's own AI agents escaped a testing environment and attacked Hugging Face, a platform used to host AI models and datasets. In that case, OpenAI says the agents took dangerous actions that weren't directed by a human - the incident being used to spook everyone into letting far-left technocommies run AI oversight.
Hacktron's team directed its own operation, reported the vulnerabilities to OpenAI and stopped after demonstrating access.
On July 25, we hacked OpenAI.
Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc.
We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵 pic.twitter.com/gVsmQZwSc8
The entry point was OpenAI's public discussion forum, which runs on software supplied by Discourse (3rd party software that manages discussion boards). A flaw in an image-processing component called libheif allowed a specially crafted image upload to make the server execute the researchers' instructions. Discourse's security advisory confirms the vulnerability required no interaction from a victim.
Hacktron said the faulty code had been changed in 2025, but the change was not identified as a security fix. The forum was still running a vulnerable version.
Illustration via HacktronThat gave the researchers access to the forum, but a second flaw turned the intrusion into something more serious.
OpenAI's shared sign-in system allowed people to use their OpenAI identity on the forum. The researchers found that the forum's sign-in tokens, digital credentials that keep users authenticated, carried permissions extending beyond the discussion site. A compromised forum session could therefore become a route into that person's ChatGPT and Codex accounts.
One employee's Codex account was already connected to OpenAI's private GitHub software repositories. The researchers used that account to have Codex submit a harmless proposed documentation change, known as a pull request, to an internal repository. A pull request proposes an edit for review; it does not, by itself, install a change in live company systems.
The researchers said they deliberately avoided inspecting sensitive code and halted testing after submitting the demonstration.
AI Accelerated The ExploitHacktron said an earlier Claude model produced a partially working exploit but struggled to make it function with the target's normal security protections in place. After Anthropic released Opus 5, the newer model produced a working version within hours. The company had access to Anthropic's program for authorized cybersecurity researchers, which relaxes some restrictions, its chief executive told Business Insider.
According to the company, skilled human guidance remained important - while AI reduced the time needed to turn a software flaw into an actual, reliable attack. According to Hacktron's timeline, OpenAI confirmed its sign-in fix roughly 14 hours after the initial report. Discourse separately patched the vulnerable image-processing component and added stronger isolation around image processing.
"We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions," OpenAI said.
OpenAI also clarified that the $6,500 reward covered the flaw on its side of the sign-in system. Testing against the Discourse-hosted forum was explicitly excluded from its bounty program.
We reported the bug to Discourse and OpenAI. OpenAI fixed the SSO issue roughly 14 hours after our initial submission.
Discourse received our separate report Saturday, replied Sunday, and had a fix Monday.
OpenAI awarded us $6,500. pic.twitter.com/WeSzRtf14N
The Hugging Face intrusion arose from OpenAI's internal cybersecurity testing earlier in July. OpenAI was evaluating agents that could write code, use software tools and take multiple steps toward a goal, rather than simply answer a user's questions.
To measure their hacking capabilities, OpenAI deliberately reduced certain safeguards that normally restrict dangerous cyber activity. The agents were nevertheless supposed to remain inside isolated testing environments, without open internet access. The models involved included GPT-5.6 Sol and an internal research prototype that was not intended for public release.
According to OpenAI, the agents exploited a previously unknown vulnerability in a service used to download software packages. That provided a route to the internet. They also repurposed the shared service as an unauthorized message board, allowing agents that were supposed to work separately to exchange discoveries and coordinate. An independent investigation by METR (oh...) and Redwood Research found that roughly 1,200 agents used the message board, exchanging more than 70,000 messages and files. About 700 participated in the attack on Hugging Face.
The agents were trying to cheat a cybersecurity test called ExploitGym. METR's investigation concluded that the Hugging Face attack appeared primarily motivated by understanding how the test's automated scoring system worked, rather than simply stealing an answer key. That information could help the agents fool the evaluator instead of completing the assigned challenges as intended.
The investigators also found agents that recognized the attack was outside their assigned task and unethical, but participated anyway.
Hugging Face reconstructed roughly 17,600 attacker actions between July 9 and July 13, including many unsuccessful attempts. It said the volume and persistence of the activity complicated detection: successful attacks were mixed into thousands of failed attempts across different systems.
OpenAI's report dates the compromise of Hugging Face's production infrastructure to July 11-13. OpenAI detected suspicious activity in its own environment on July 19 and publicly disclosed its responsibility on July 21, four days before Hacktron demonstrated its separate breach.
* * *
Tyler Durden Fri, 09/18/2026 - 11:40Josh Allen caught chewing on smelling salts in bizarre ‘TNF’ scene
Gavin Newsom seeks ‘kill switch’ for AI in new executive order
Millie Bobby Brown shows off diamond ‘mom’ ring as she confirms baby No. 2
Millie Bobby Brown shows off diamond ‘mom’ ring as she confirms baby No. 2
Soccer star Kylian Mbappe ditches Nike after 20 years to sign with Roger Federer-backed On
On-the-rocks couples turn to ‘food divorce’ to save relationship
I tried Drunk Elephant’s first foundation, and my luxury one is officially benched
‘MobLand’ Stars Pierce Brosnan & Helen Mirren Revel In The “Freedom” Of Playing Conrad & Maeve Harrigan: “It’s So Fun To Not Be Restricted”
Dave Chappelle adds second MSG show. Which one has cheaper tickets?
Patrick Clancy’s new wife Rachel Danis reveals how couple met in clip ahead of ‘60 Minutes’ interview
Red Sox’s Willson Contreras in injury scare with Yankees’ wild-card showdown looming
Carmella Garcia dishes on ‘RHOC’ beef with Vicki Gunvalson, confirms breakup to ‘VRT’ and more
Carmella Garcia dishes on ‘RHOC’ beef with Vicki Gunvalson, confirms breakup to ‘VRT’ and more
South Korean President Announces No Military Support To US Hormuz Mission
South Korea has belatedly made a big decision after starting months ago it found itself among key Washington allies directly called upon by President Trump to provide urgent security help for Strait of Hormuz energy transit, amid the war with Iran.
President Lee Jae Myung has on Friday announced he will not deploy the military to the Middle East, though his statement also suggested troops could play a role on the peripheries of the conflict.
August 2025: President Trump meets with South Korean President Lee Jae Myung at the Oval Office, Reuters.Resisting direct calls from Trump to support the campaign against Iran, Lee made clear to a news conference: "There won’t be deployment that would involve or enter war. I can tell you that very clearly. We won’t deploy military assets in any form to that end."
"It is also clear that we must do the minimum as other countries do to protect our commercial shipping and crude shipments, and also the safety of our people," he said. At the moment, the South Korean Navy only conducts patrols off the coast of Somali as part of international anti-piracy efforts.
Lee's words did seem to leave open a potential greater future role in terms of South Korea safeguarding global shipping in the region, but it would obviously be significantly away from the potential reach of any Iranian missile or drones, or that of their proxies.
This is a long-awaited decision. While Europe and basically the whole rest of the world has rejected Trump calls to send military assets to assist in opening the Strait of Hormuz, South Korea is in a tougher spot given the many decades-long, large American troop presence on the peninsula, safeguarding the south from possible attack from North Korea. The country is also effectively under America's nuclear protection umbrella.
Last week, Lee's press secretary stated the government had not yet finalized its policy but was "cautiously assessing it".
But then it got a warning from Tehran. Iranian Foreign Ministry spokesman Esmail Baqaei warned on X on Sept.7. "The military presence or operational participation of other nations in the Persian Gulf and the Strait of Hormuz would inevitably be viewed as direct support for the party committing acts of aggression, and would lead to serious consequences."
And so Seoul has found itself diplomatically between a rock and a hard place:
Trump has criticized Seoul for what he called insufficient support for the Iran war and scaled back major joint military drills by the two countries’ armed forces this summer, a move that unsettled the U.S. ally.
Committing South Korean troops to the Gulf region has also seemed unpopular among the Korean populace. Rare anti-war protests have been going strong this month in front of the US Embassy in Seoul.
Locals have at times carried signs that read "Do Not Join a War of Aggression" and "No Military Deployment to Hormuz," while protesters have chanted, "We cannot send our young people into a sea of death," according to prior descriptions by the AFP.
Not going to appease Washington: "the minimum necessary activities"...
South Korea will not deploy troops or military assets to intervene in the Iran war, President Lee said Friday.
“There will be no involvement or intervention in the war,” Lee said, adding Seoul would carry out only “the minimum necessary activities” to protect South Korean… pic.twitter.com/1lseOq10W1
"Sending our troops to an illegal war waged by the United States is unacceptable," Choi Young-ok, a member of Korean Peace Solidarity for Sovereignty and Reunification, a group that is highly critical of the US military presence in South Korea, told AFP.
"There is no reason for us to send troops when no other country has done so or said it would," added Choi, who also warned that sending South Korean troops would "inevitably lead to casualties." Now, Seoul is nervously awaiting Trump's reaction and coming wrath.
* * *
Tyler Durden Fri, 09/18/2026 - 11:20Holdout Lindsay Clancy juror Michael P. Desronvil believes being black Republican may have put target on his back
AfD Preps Talks With Moscow To Reopen Cheap Gas Flows To Germany
It didn't take long for the Alternative for Germany (AfD) party - fresh off its historic taking of 43.8% of the vote in the eastern German state of Saxony-Anhalt election earlier this month which left Chancellor Friedrich Merz and his Christian Democratic Union (CDU) shaken - to embark on ties which are a serious shot across the bow and slap in the face to both Berlin and Brussels.
Reuters is on Friday reporting that AfD leadership is preparing for possible talks with President Putin and his economic envoy and top negotiator Kirill Dmitriev focused on restoring Russian gas supplies to Germany.
via ReutersThe meeting could take place next year, as early as March 2027, and would be spearheaded by AfD co-leaders Alice Weidel and Tino Chrupalla.
This is precisely what German voters supported in the regional election, and the AfD made no secret of its plans to seek turning the Russian energy tap back on. Weidel made clear in a June interview, "Cheap energy from Russia was the secret of the success of 'Made in Germany'. We need it back."
"The loss of this energy has set us back years. Hundreds of thousands of jobs have been lost," the AfD co-leader said at the time. "It has made us dependent on the United States, which sells us energy at far higher prices."
Russia had prior to the start of the Ukraine war supplied over half of Germany's natural gas, alongside more than a third of the country's crude oil imports.
Russian natgas to Germany was halted in stages, in tandem with the major Nord Stream bombings and investigation, as Berlin eventually found alternative suppliers like Norway, the Netherlands and increased its reliance on LNG imports.
Many Germans have been sick and tired of seeing daily living prices go up while resources and untold billions are siphoned off for the Zelensky government in the Ukraine war.
Getty ImagesWhile nothing has yet to be officially announced or confirmed by the Russian side or through any AfD official statement, Reuters points to a key caveat based on its sources: "The meeting would only happen if a peace framework was agreed first between Russia and Ukraine, and the organisers hoped it would bring together the AfD, Russia and the United States, the person said. Possible locations for the summit included Israel, the United Arab Emirates or India, they added," the report says.
Earlier, we featured commentary by Andrew Korybko which seeks to summarize the mood in both Moscow and among the 'hard-rightward' turning German streets:
Finally, the economic errors concern the EU's sanctions on Russian energy, which led to the bloc replacing inexpensive long-term gas contracts with Russia with expensive market-priced imports from elsewhere. Prices are now nearly ten times higher than before and "may well rise even further." Putin also criticized the EU's gas storage policies for being "unconcerned with the technical condition of these storage facilities and the physical volumes involved." All of this adversely affects the EU's economy.
All in all, Putin is arguing that the AfD's rise is an electoral revolt against these policies, all of which center on Russia. This doesn't mean that the party or its supporters are "pro-Russian", let alone "Russian puppets", just that they understand the importance of pragmatic ties with Russia for their country's political interests, security, and economic development. Obsessive anti-Russian fearmongering, risking World War III over Ukraine, and dumping inexpensive Russian energy haven't helped Germany at all.
"Bests interests for Germany" being prioritized, where energy supplies "are cheapest, namely from Russia"...
German AfD Leader Alice Weidel on Russia:
We have to obtain fossil fuels from wherever natural gas and oil are cheapest — namely, from Russia.
It is in our own security interests as well as our economic interests to have good relations with Russia. pic.twitter.com/FkKKOpCDAo
As a reminder, there were already some deeply provocative diplomatic AfD moves back in June, with AfD foreign-policy spokesman Markus Frohnmaier having traveled to St. Petersburg to meet with Dmitriev and Gazprom CEO Alexei Miller, urging the reopening of the Nord Stream pipeline.
* * *
Tyler Durden Fri, 09/18/2026 - 10:45