
OpenAI employee accounts breached with help from Anthropic's Claude
Proactive Investors
公開日時: Sep 18, 2026, 11:42 PM GMT+9
Tech Edited by: Angela Harmantas 10:40 Fri 18 Sep 2026 --> Disclaimer No investment advice About this content Editorial Standards & Policies Share article About this content × About Read more About the publisher Proactive financial news and online broadcast teams provide fast, accessible, informative and actionable business and finance news content to a global investment audience. All our content is produced independently by our experienced and qualified teams of news journalists. Proactive news team spans the world’s key finance and investing hubs with bureaus and studios in London, New York, Toronto, Vancouver, Sydney and Perth. We are experts in medium and small-cap markets, we also keep our community up to date with blue-chip companies, commodities and broader investment stories. This is content that excites and engages motivated private investors. The team delivers news and unique insights across the market including but not confined to: biotech and pharma, mining and natural resources, battery metals, oil and gas, crypto and emerging digital and EV technologies. Use of technology Proactive has always been a forward looking and enthusiastic technology adopter. Our human content creators are equipped with many decades of valuable expertise and experience. The team also has access to and use technologies to assist and enhance workflows. Proactive will on occasion use automation and software tools, including generative AI. Nevertheless, all content published by Proactive is edited and authored by humans, in line with best practice in regard to content production and search engine optimisation. OpenAI View Price & Profile OpenAI employee accounts breached with help from Anthropic's Claude Published: 10:40 18 Sep 2026 EDT OpenAI (Unlisted:OPAI) patched security flaws after Hacktron AI researchers used Anthropic (Unlisted (US):ANTHRO) Claude models to compromise employee accounts and access internal software repositories, the Wall Street Journal reported. The company paid the three researchers $6,500 for an OpenAI single sign-on vulnerability, while testing its Discourse-hosted forum fell outside the bounty program's scope. Hacktron said it used Claude Opus 4.8 and Opus 5 to help develop the exploit, which chained two vulnerabilities. First, a heap buffer overflow in the libheif image-processing library enabled remote code execution through a malicious image uploaded to the forum. An OpenAI single sign-on misconfiguration then allowed the researchers to obtain identity tokens and take over employee ChatGPT accounts. Those accounts provided a route to internal code through GitHub, demonstrating how the forum breach could extend into connected company systems. OpenAI thanked the researchers and said it had fixed the issues. Continue reading
Source: Proactive Investors
個別の投資に関する推奨やアドバイスを提供することを意図しておりません。ここで述べられている意見や見解は、あくまでも各記事の個人的見解です。