That is 0 articles you have read today.
The Aporia is free and carries no advertising, so readers are the only
thing paying for it. If you are getting this much out of it, a small
donation is what keeps it independent.
Daily limit reached
You have read 0 articles today.
That is more than the 15 a day The Aporia gives away,
and well past what it can carry on nothing. Your allowance resets at
midnight.
There is no advertising here and nothing about you is sold, so readers
are the only thing paying for it. If the site is worth this much of
your day, it is worth a few dollars.
Everything else stays open: the
maps, the
directory and
search do
not count against this, and neither does re-opening something you have
already read today.
Security researchers from Hacktron used Anthropic’s language model Claude to exploit a flaw in OpenAI’s public help forum, which they reported on Friday after gaining control within about three hours using the updated Claude Opus 5 model. The vulnerability was fixed by OpenAI within 14 hours and the company paid Hacktron a $6,500 reward for their discovery. This incident highlights how rapidly evolving AI technology can be leveraged to conduct sophisticated cyberattacks efficiently, raising concerns among security experts about the broader implications of such tools.
Written locally by qwen2.5:14b on 2026-09-18,
using this article's own text rather than the other coverage of the
same event (that is the story summary below).
Story summary
In September, cybersecurity researchers at Hacktron AI used Anthropic’s Claude chatbot to breach OpenAI’s internal systems, gaining access to employee accounts and an internal GitHub repository. The researchers discovered a flaw in OpenAI's public help forum hosted by Discourse, which they exploited within 72 hours. They reported the issue immediately, and OpenAI fixed it within 14 hours while paying Hacktron a $6,500 bounty. The incident highlights how quickly AI can be repurposed for cyberattacks, despite efforts to ensure ethical use through bug-hunting programs like this one.
Written for “AI Breach Risks” on 2026-10-05,
grounded in this article and the 7 other(s) covering the same event.
A security research company said Friday it managed to break into OpenAI’s internal systems using the latest software from Anthropic, exposing how quickly the technology can carry out sophisticated cyberattacks.
asserted
technology → say → cyberattacks
The researchers from security firm Hacktron said they found a security flaw in OpenAI’s public help forum, run by the Discourse platform, that allowed them to take control of the site.
asserted
them → say → site
“We immediately reported the initial vulnerability to OpenAI and Discourse and worked with them to coordinate the patch,” Hacktron said in a blog post.
asserted
Hacktron → report → post
“We appreciate their attention to detail and fast resolution of this issue,” the post added.
asserted
post → appreciate → issue
OpenAI confirmed the flaw was fixed within about 14 hours of being notified and paid the researchers a $6,500 reward.
asserted
flaw → confirm → reward
“We thank the researchers for contacting us and sharing their findings.
asserted
We → thank → findings
We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions,” said Drew Pusateri, an OpenAI spokesperson.
asserted
Pusateri → narrow → tokens
The Hacktron researchers said they initially used Anthropic’s Claude Opus 4.8 to identify and exploit the software flaw, but struggled to make it work consistently.
asserted
it → say → flaw
After Anthropic released Claude Opus 5, the researchers said the newer model produced a working hack within about three hours.
asserted
model → release → hours
The hackers did not use Claude Mythos, a more capable Anthropic model that is restricted to a small group of vetted cyber-defence organisations.
asserted
that → use → organisations
Anthropic has described Mythos as having the strongest cybersecurity capabilities of any model it has built.
asserted
it → describe → model
Hacktron said the underlying software flaw is not unique to OpenAI and is used across many companies’ products, including those made by Slack and Meta.
asserted
flaw → say → Slack
The firm said it is continuing similar tests at other companies.
asserted
it → say → companies
The case adds to growing concern among security experts that AI tools are making it faster and cheaper to carry out sophisticated cyberattacks that once required specialised teams and months of work.
asserted
that → add → work