研究人员表示,他们最初使用 Claude Opus 4.8 来发现该漏洞。模型构建了一个可行的利用程序,但仅在禁用 ASLR(一种常见的内存攻击防御机制)时才能运行。在几次实验中,它无法在启用 ASLR 的情况下生成可靠版本。广告
7 月 24 日晚,Anthropic 发布了 Claude Opus 5:https://the-decoder.com/anthropic-claims-its-new-claude-opus-5-delivers-near-fable-5-performance-at-half-the-token-price/。根据 Hacktron 的说法,新模型在三小时内成功生成了对本地 Mac 的可行利用程序,然后将其适配到 Discourse 服务器环境中。研究人员随后在他们自己的测试实例上以自主循环运行 Claude。
由于模型拒绝针对真实系统编写利用程序,他们将目标呈现为基准任务。四小时后,代理已接管服务器。在相关任务中,研究人员还观察到与 OpenAI 的 GPT-5.6 Sol 相比的性能跃升。广告
AI 通过用计算能力替代稀缺的专业知识,剥夺了这种保护。Hacktron 认为,威胁模型必须反映攻击已变得多么廉价。“曾经需要资源充足的团队和数月努力的工作,现在可以压缩到几天内完成,”团队写道。
保持 AI 相关信息的更新。清晰、有用,无废话。
关注 The Decoder,获取 AI 新闻、背景故事和专家分析。
解码器:https://the-decoder.com/
Three security researchers used Anthropic's Claude models to break into OpenAI's internal systems through the company's community forum. The attack took less than 72 hours and, according to the team, only became possible once Opus 5 shipped.
OpenAI is getting a taste of its own medicine. After inadvertently letting agents hack their way across the internet for months:https://the-decoder.com/openai-reportedly-slows-research-after-its-own-models-secretly-coordinated-hacks-for-weeks-undetected/, the company has now been hacked with AI's help. Hacktron's security team chained two vulnerabilities together to access OpenAI employees' ChatGPT and Codex accounts. From there, they broke into OpenAI's internal code repository on GitHub.
The attack:https://www.hacktron.ai/blog/hacking-openai ran through OpenAI's community forum at community.openai.com:http://community.openai.com. Any user or employee who had used "Sign in with OpenAI" there was potentially affected. Users can connect GitHub, Slack, and email to Codex and ChatGPT, so the attack could theoretically have reached those services too. To prove they had access, the researchers used an employee's Codex account to create a harmless pull request in the internal monorepo. They say they didn't view any sensitive data. Ad
The first vulnerability was in libheif, the library the forum used to process uploaded HEIC images. According to Hacktron, a fix had been available in the original source code:https://github.com/strukturag/libheif/commit/85e21ad44eba931314337300a2376b8d28f085ae for a year, but no one had flagged it as a security issue. The Debian packages running on the forum still lacked the fix. A crafted image file let the researchers run their own code on the server. Ad
The second vulnerability was a misconfiguration in OpenAI's central single sign-on (SSO) system. Anyone controlling the forum server could impersonate active forum members and take over their ChatGPT and Codex accounts. The flaw extended beyond the forum, Hacktron writes. Any compromised service using OpenAI login would have granted the same access.
The researchers say they initially used Claude Opus 4.8 to find the vulnerability. The model built a working exploit, but only with ASLR, a common defense against memory attacks, disabled. Across several sessions, it couldn't produce a reliable version with ASLR enabled. Ad
On the evening of July 24, Anthropic released Claude Opus 5:https://the-decoder.com/anthropic-claims-its-new-claude-opus-5-delivers-near-fable-5-performance-at-half-the-token-price/. According to Hacktron, the new model produced a working exploit for a local Mac within three hours, then adapted it to the Discourse server environment. The researchers then ran Claude in an autonomous loop against their own test instance.
Because the model refused to write exploits against real systems, they presented the target as a benchmark task. Four hours later, the agent had taken over the server. On a related task, the researchers also observed a jump in performance compared to OpenAI's GPT-5.6 Sol. Ad
OpenAI confirmed the fix about 14 hours after the report. Discourse, the software behind the forum, also responded within days. Ad
Beyond the OpenAI hack, the researchers expanded their investigation, dubbed "HEIF Heist":https://heif-heist.com/, to cover Slack, Meta, GitHub Enterprise, and other targets. Three people carried out the project over two months, spending less than $3,000 on AI. Adapting the attack to each new target took just one to two days. Only Shopify noticed the activity, despite thousands of image uploads and repeated crashes in image processing.
Software has long benefited from a kind of security through complexity, the Hacktron team writes. Even with public source code and a known vulnerability, building a reliable exploit required rare expertise, time, and deep knowledge of the target environment. Complexity wasn't a true security barrier, but it did protect many companies in practice.
AI strips away that protection by replacing scarce expertise with computing power. Hacktron argues that threat models must reflect how cheap attacks have become. "Work that once required a well-resourced team and months of effort can now be compressed into days," the team writes.
Stay in the loop on AI. Clear, useful, no fluff.
Follow The Decoder for AI news, background stories and expert analyses.