安全研究员用Claude在72小时内攻破OpenAI内部系统
原标题:Security researchers used Anthropic's Claude to hack OpenAI's internal systems in under 72 hours
AI 摘要
安全研究团队Hacktron利用Anthropic的Claude模型,在72小时内通过OpenAI社区论坛的漏洞链入侵了OpenAI内部系统,获取了员工ChatGPT和Codex账户权限,并进入其GitHub内部代码仓库。攻击利用了论坛图像处理库libheif的未修复漏洞和OpenAI中央SSO配置错误。研究称Claude Opus 5发布后数小时内即生成可用漏洞利用,而前代Opus 4.8未能做到。该事件表明AI正大幅降低复杂网络攻击的时间与技能门槛。
正文节选
Security researchers used Anthropic's Claude to hack OpenAI's internal systems in under 72 hours Key Points - Security researchers used Anthropic's Claude to break into OpenAI's internal systems and code repositories. - The attack ran through OpenAI's community forum, where chained vulnerabilities gave the researchers access to employee ChatGPT and Codex accounts. - The entire exploit took just 72 hours to develop, showing how drastically AI models are cutting the time and skill needed for sophi