Independent security researchers used Claude from Anthropic to explore vulnerabilities in OpenAI systems. The case involved employee accounts, access to Codex, and entry into an internal code repository. Despite the seriousness, the team carried out the action within the company’s bug bounty program.

The Hacktron AI startup assembled three experts to run the tests. After identifying and combining two critical vulnerabilities, the group reported the details to OpenAI and received a reward of US$6,500. The company says it has already patched the gaps found during the research.

The first step by Claude in an attack on OpenAI occurred on July 25. Researchers found a vulnerability in Discourse, third-party software that powers the OpenAI community forum. Interestingly, an image in HEIF or HEIC format paved the way for the incursion.

When a user sends this kind of file to the forum, Discourse uses different tools to convert the image into JPEG. First, the system forwards the content to ImageMagick, an open-source program used to resize and process images. Since the tool does not directly handle Apple’s format, it relies on the libheif library.

#Tecnologia #ArtificialIntelligence