The Jerusalem PostMural of rapper Macklemore painted in Gaza after Sheeran tour furorESPN DeportesLamine Yamal reclama el Balón de Oro y cuenta por qué tiene que ganarloESPNHow and why Missouri is claiming a college football title 66 years laterוואלהנקבע מותו של ילד כבן 7 בעקבות תאונת דרכים ברהטInquirerPalace to Pia Cayetano on fear for her liberty: Is this paranoia? Don’t panicRTP DesportoUEFA e CONCACAF pedem dados à FIFA sobre projeto de privatizar MundiaisDaily MaverickAGE OF ACCOUNTABILITY: Five criminal cases later, Ekurhuleni fires Julius MkhwanaziDeadlineBrad Pitt Reunites With His ‘Riders’ Director Edward Berger On Paramount’s ‘World War Z’ SequelTechCrunchJoby Aviation’s 3,100-mile autonomous flight signals its push beyond electric air taxisسكاي نيوز عربيةمحمد بن زايد ومودي يبحثان العلاقات والتطورات الإقليميةCBS SportsCollege football schedule, games 2026: What to watch in Week 3, TV channels, streaming, kickoff timesIl Sole 24 OreLe immagini come chiave di lettura dell’attualità: al via nuovo programma di Radio24
The Daily Newsstand · Free, Always
Friday, September 18, 2026

Researchers used Claude to breach OpenAI's internal systems

Translate

WASHINGTON: A security research company said on Friday (Sep 18) it managed to break into OpenAI's internal systems using the latest software from Anthropic, exposing how quickly the technology can carry out sophisticated cyberattacks.

The researchers from security firm Hacktron said they found a security flaw in OpenAI's public help forum, run by the Discourse platform, that allowed them to take control of the site.

"We immediately reported the initial vulnerability to OpenAI and Discourse and worked with them to coordinate the patch," Hacktron said in a blog post.

"We appreciate their attention to detail and fast resolution of this issue," the post added.

OpenAI confirmed the flaw was fixed within about 14 hours of being notified and paid the researchers a US$6,500 reward.

"We thank the researchers for contacting us and sharing their findings. We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions," said Drew Pusateri, an OpenAI spokesperson.

The Hacktron researchers said they initially used Anthropic's Claude Opus 4.8 to identify and exploit the software flaw, but struggled to make it work consistently.

After Anthropic released Claude Opus 5, the researchers said the newer model produced a working hack within about three hours.

The hackers did not use Claude Mythos, a more capable Anthropic model that is restricted to a small group of vetted cyber-defense organisations.

Anthropic has described Mythos as having the strongest cybersecurity capabilities of any model it has built.

Hacktron said the underlying software flaw is not unique to OpenAI and is used across many companies' products, including those made by Slack and Meta.

The firm said it is continuing similar tests at other companies.

The case adds to growing concern among security experts that AI tools are making it faster and cheaper to carry out sophisticated cyberattacks that once required specialised teams and months of work.

View the original on Channel News Asia

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.