安全研究团队Hacktron AI利用Anthropic公司的Claude聊天机器人,成功突破OpenAI的防御系统23。研究人员通过Discourse社区论坛软件中的安全漏洞,获得了多个OpenAI员工ChatGPT账户的访问权限,进而能够查看私密软件信息234。这次入侵涉及用户上传HEIF/HEIC图像文件时的安全漏洞,其根源在于ImageMagick和libheif等开源工具中的内存错误3。入侵发生在7月25日3,Discourse于7月27日发布了修复程序3。
研究人员初期利用Claude Opus 4.8模型生成黑客代码,但该版本无法构建可工作的漏洞利用工具;在Opus 5发布后数小时内,他们成功开发出了有效的攻击代码3。随后,他们主要使用OpenAI自身的GPT-5.6 Sol模型执行大部分黑客操作,获得了连接到OpenAI Github组织的Codex账户访问权限2。这一安全测试是在OpenAI的漏洞赏金计划框架下进行的,旨在在恶意行为人利用之前发现漏洞4。Hacktron因此获得了6500美元的漏洞赏金23,OpenAI已确认并修复了这些漏洞2。
安全专家指出这一事件的严重性,表示"对于每月200美元,任何人都可以使用这些工具入侵OpenAI这样的公司"3。研究人员称,曾需要资源充足的团队花费数月才能完成的工作,如今可压缩至数天内完成2。
Security researchers at Hacktron AI have successfully penetrated OpenAI's defenses by leveraging Anthropic's Claude chatbot, gaining access to employee ChatGPT accounts and sensitive software information.23 The breach was conducted as part of OpenAI's ethical hacking program, designed to identify security vulnerabilities before malicious actors can exploit them.24 OpenAI awarded the research team a bug bounty of $6,500 for their findings and has since confirmed and patched the vulnerabilities.23
The attack exploited two critical security flaws in Discourse, the community forum software used by OpenAI.3 Specifically, the researchers discovered a vulnerability in the image file upload mechanism when users uploaded HEIF/HEIC format images, which involved memory errors in open-source tools including ImageMagick and libheif.3 On July 25, the team gained initial access through these Discourse vulnerabilities and subsequently obtained credentials for multiple OpenAI employee accounts, including access to a Codex account connected to OpenAI's GitHub organization.3 Discourse released a patch to address the issue on July 27.3
The research team initially used Anthropic's Claude Opus 4.8 model to generate exploit code, but the tool proved unable to create a functional exploit at that time.3 However, after Claude Opus 5 was released, the researchers were able to construct a working exploit within hours using the updated model.3 According to the security researchers, they submitted a harmless pull request to GitHub as a test while maintaining awareness that they possessed access privileges but deliberately refrained from downloading code from OpenAI's GitHub repositories.2 One AI security expert noted that the accessibility of such tools at a monthly subscription cost of $200 means that "any person could use these tools to breach a company like OpenAI."3
评论
还没有评论,欢迎留下第一条。