安全研究员用 Claude 入侵 OpenAI 并获赏金
原标题:Security researchers used Claude to help them hack into OpenAI
AI 摘要
三名独立安全研究员组成的 Hacktron 团队利用 Anthropic 的 Claude Opus 4.8 和 5,在不到 72 小时内入侵了 OpenAI 员工账户,并访问了 OpenAI 的 GitHub 仓库 Monorepo。他们通过 Discourse 论坛的 HEIF 图像处理漏洞实现远程代码执行,并从员工 Codex 账户提交拉取请求以证明访问权限。该漏洞已被修复,OpenAI 向 Hacktron 支付了 6500 美元赏金。
正文节选
A team of three independent security researchers at Hacktron says it took less than 72 hours for them to hack into OpenAI employee accounts using Anthropic’s Claude Opus 4.8 and 5, The Wall Street Journal reports. They were able to access OpenAI’s GitHub repository, called “Monorepo,” which reportedly contains “OpenAI’s algorithmic secrets,” according to The Wall Street Journal’s sources. Security researchers used Claude to help them hack into OpenAI A three-person team of researchers used a cor