~/CYBERSECURIT/white-hat-hackers-use-anthropic-s-claude-to-breach-openai-internal-account

White-Hat Hackers Use Anthropic's Claude to Breach OpenAI Internal Account Systems

Security researchers from Hacktron AI used Anthropic's Claude model to discover and exploit a vulnerability in Discourse (CVE-2026-45788), allowing them to obtain session tokens that unlocked OpenAI employee ChatGPT accounts and internal documentation. After responsibly disclosing the flaw, the researchers were awarded a $6,500 bug bounty by OpenAI. This incident highlights how modern AI tools can significantly lower the technical barrier for discovering vulnerabilities and automated cyber exploitation. It also demonstrates the systemic security risks that arise when third-party software authentication tokens are over-privileged across high-value enterprise infrastructure. The initial entry point was an unauthenticated Discourse file-upload flaw that leaked user tokens, which surprisingly held authentication privileges for OpenAI's ChatGPT services and internal GitHub repository metadata. OpenAI subsequently revoked the compromised tokens, restricted Discourse token scopes, and reassigned approximately 25% of its production engineers to reinforce security infrastructure.

## BACKGROUND

Bug bounty programs provide a legal safe harbor and financial incentives for ethical hackers to disclose vulnerabilities securely rather than exploiting them maliciously. Software companies often use Single Sign-On (SSO) systems to manage access across third-party platforms like Discourse forums, but improper token scoping can accidentally expose internal production systems.

## REFERENCES

## KEYWORDS

#Cybersecurity#AI Security#OpenAI#Anthropic#Bug Bounty

$ subscribe --daily

White-Hat Hackers Use Anthropic's Claude to Breach OpenAI Internal Account Systems | Daily News