研究人员用Anthropic的Claude攻破OpenAI
原标题:Researchers used Anthropic’s Claude to hack into OpenAI
AI 摘要
独立安全研究团队 Hacktron AI 利用 Anthropic 的 Claude 模型,通过 OpenAI 社区论坛所用 Discourse 软件中 libheif 库的一个内存漏洞,串联两个关键漏洞入侵 OpenAI 内部系统,并接管了多名员工的 ChatGPT 和 Codex 账户。该攻击属于 OpenAI 漏洞赏金项目,Hacktron 获得 6500 美元奖励,OpenAI 表示已修复相关问题。事件凸显了现成 AI 工具降低漏洞利用门槛,以及前沿模型在网络安全攻防中的双刃剑效应。
正文节选
In a twist that captures the strange new state of AI security, independent security researchers have used Anthropic’s Claude to break into OpenAI, exposing cracks in the ChatGPT-maker’s defenses, The Wall Street Journal reported on Thursday evening. A three-person security team at startup Hacktron AI carried out the attack as part of an OpenAI bug-bounty program. Hacktron reported its findings to OpenAI, which gave the startup a $6,500 award. The team managed to chain together two critical vulne