LIVE · cybersecurity feed
Live wire
CVE-2024-4405 · Malicious Extensions Hijack AI Browser Agents via Prompt ForcingCVE-2026-58138 · Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildCVE-2025-39682 · CISA Flags Three Linux Kernel Vulnerabilities Exploited in the WildBrevo Supply-Chain Attack Infected Over 100,000 WebsitesPublic Exploits Released for Linux Kernel Root Privilege FlawsIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawCisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
vulnerability

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the software that runs OpenAI's public help forum and moved through a weakness in OpenAI's own login system. This was security research,

zeroday.news ·

Security researchers have reportedly leveraged Anthropic's Claude Opus 5 to assist in chaining two distinct vulnerabilities, leading to the compromise of OpenAI staff accounts for ChatGPT and Codex, and subsequently gaining access to an internal OpenAI code repository. The incident was described as a security research effort conducted by three researchers at the firm Hacktron.

The reported attack chain initiated with a vulnerability discovered in the software powering OpenAI's public help forum. While the specific nature of this initial flaw was not detailed, forum software often presents a range of potential weaknesses, from cross-site scripting (XSS) to SQL injection or authentication bypasses, which can be exploited to gain initial access or information.

Following the compromise of the help forum, the researchers reportedly exploited a weakness within OpenAI's own login system. This suggests a potential flaw in the authentication or authorization mechanisms used by OpenAI for its internal and employee-facing applications. Such weaknesses could include session management issues, insecure direct object references, or other logical flaws that allow an attacker to bypass intended access controls or impersonate legitimate users.

The role of Claude Opus 5 in this research was highlighted, indicating its application as a tool to facilitate the chaining of these two vulnerabilities. Large language models (LLMs) like Claude Opus 5 can be used by security researchers to analyze code, identify potential attack paths, generate exploit payloads, or automate parts of the penetration testing process, thereby accelerating the discovery and exploitation of complex vulnerability chains.

The ultimate objective and reported outcome of this chain was the takeover of ChatGPT and Codex accounts belonging to several OpenAI employees, followed by access to an internal OpenAI code repository. Access to employee accounts can grant an attacker privileges within internal systems, while access to a code repository could expose proprietary source code, internal tools, sensitive configurations, or intellectual property.

Mitigation for such chained attacks typically involves a multi-layered security approach. Organizations are advised to conduct regular security audits and penetration tests on all public-facing applications, including forum software, and rigorously review the security of their authentication and authorization systems. Implementing strong access controls, multi-factor authentication (MFA), and continuous monitoring for anomalous activity are crucial steps to prevent and detect similar compromises.

This incident underscores the evolving landscape of cybersecurity research, where advanced AI tools are increasingly being integrated into the methodologies used to discover and exploit vulnerabilities. It also highlights the persistent challenge for organizations, even those at the forefront of AI development, to secure their own infrastructure against sophisticated attack chains that leverage multiple, seemingly disparate weaknesses.

vulnerabilityaicloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2024-4405high

Malicious Extensions Hijack AI Browser Agents via Prompt Forcing

A new proof-of-concept attack named BragJack demonstrates how malicious browser extensions can hijack AI assistants within browsers like Chrome and Edge. The attack utilizes a technique called Prompt Forcing to gain control of these AI agents, successfully earning significant bug bounties and two CVEs.

phishing

AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum

AI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO. Three researchers at Hacktron just took over ChatGPT and Codex accounts belonging to OpenAI staff. The attack did not rely on phishing techniques or a leaked password. Through an image upload on OpenAI’s […]

vulnerability

Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening

AI labs are toying with an industry-wide pact to slow development. Meanwhile, widely available AI chatbots are already helping uncover a tidal wave of security flaws.

security

TigerByte Cyber Emerges From Stealth With $3 Million in Funding

The company has secured over $7 million in contracts with US government agencies, including the US Space Force, the US Navy, and DARPA. The post TigerByte Cyber Emerges From Stealth With $3 Million in Funding appeared first on SecurityWeek.

security

North Korean WaterPlum hackers infected 30,000 devices worldwide

A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. [...]

ransomware

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. [...]