Skip to content

Sam's News β€” anthropic β€” 2026-09-18

Security

7.5 Hacktron Demonstrates Account Takeover Flaw in OpenAI Via AI-Generated Exploit

Hacktron researchers used Claude to develop an exploit for an unpatched libheif vulnerability in OpenAI's Discourse forum, chaining it with excessive sign-in token permissions to take over employee accounts and access internal repositories. The exploit demonstrated remote code execution and full API compromise.

  • Used Claude (Opus 4.8 and 5) to build working exploit for libheif vulnerability
  • Libheif bug fixed upstream a year earlier but never assigned CVE or security flag
  • Sign-in tokens for community forum carried excessive permissions to ChatGPT, Codex, GitHub, Slack, email
  • Researchers demonstrated account takeover by accessing OpenAI's GitHub organization
  • Three-person Hacktron AI team exploited an ImageMagick/libheif vulnerability via HEIC image uploads
  • Sign-in tokens for OpenAI's community forum carried excessive permissions to ChatGPT and Codex accounts
  • Libheif bug had been fixed upstream but never formally assigned a CVE number
  • OpenAI awarded $6,500 bug bounty; vulnerabilities resolved

Sources: SecurityWeek AI Web Searched, TechCrunch AI Web Searched, Daily Sabah RSS

7.5 Security researchers used Claude to access OpenAI internal code in under 72 hours

White hat security researchers reportedly used Anthropic's Claude to gain access to OpenAI's internal code within 72 hours.

Sources: Yellow.com RSS

7.5 Researchers used Claude to hack OpenAI employee accounts

Researchers hacked OpenAI employee ChatGPT accounts using Anthropic's Claude.

Sources: The Register RSS, theregister.com RSS, the-decoder.com RSS, Yahoo Tech RSS, ForkLog RSS Update to: Security researchers used Claude to access OpenAI internal code in under 72 hours

7.5 Hackers breached OpenAI amid surge in AI security and safety concerns

OpenAI disclosed that Hacktron, a cybersecurity firm, breached its systems in July 2026 via chained vulnerabilities in third-party software and employee validation processes. The authorized white-hat test exposed employee ChatGPT accounts over 72 hours with no harm; vulnerabilities were patched and the firm paid $6,500 through bug bounty.

  • Breach occurred July 2026 over 72-hour period
  • Exploited Discourse software and OpenAI employee validation vulnerabilities
  • Authorized security test with no unauthorized access confirmed
  • $6,500 bug bounty paid to Hacktron
  • All vulnerabilities patched; no evidence of other exploitation

Sources: NBC News AI Web Searched, news.sbs.co.kr RSS, The Coin Republic RSS

7 Researchers earned $6,500 breaching OpenAI using Claude in bug bounty

Security researchers earned a $6,500 bounty by successfully exploiting OpenAI's systems using Anthropic's Claude.

Sources: BeInCrypto RSS, Central Oregon Daily RSS

AI

7 Anthropic's Claude AI taking over development of its own successor models

Claude is now handling a quarter of the development work for Anthropic's next-generation AI system.

Sources: The Washington Post RSS, DevOps.com RSS, varindia.com RSS, Mezha RSS, Yahoo RSS, Straight Arrow RSS

7 Anthropic Reports Claude Leads 26% of Its AI Research Work

Claude accounts for 26% of Anthropic's research and development efforts according to the company.

Sources: the-decoder.com RSS, qz.com RSS, CEO Today RSS, Dataconomy RSS, findarticles.com RSS, VOI.id RSS Update to: Anthropic reports Claude drives 26% of internal R&D

7 Novo Nordisk Partners with Anthropic to Accelerate Drug Discovery Using AI

Pharmaceutical company Novo Nordisk is utilizing Anthropic's Claude AI model to accelerate drug discovery processes.

Sources: Drug Discovery News RSS, finance.biggo.com RSS Update to: Anthropic partners with Novo Nordisk to apply Claude AI for drug discovery

7 Anthropic Developing AI Access to Bank Accounts

Anthropic is developing capabilities to allow its Claude AI to access customer banking accounts directly.

Sources: Yahoo Finance UK RSS, The Independent RSS, allaboutcookies.org RSS Update to: Anthropic Testing 'Claude Money' for Bank Account Connectivity and Financial Analysis

7 Anthropic Quietly Sets Up Biology Lab for AI Drug Development

Anthropic set up a new biology laboratory as it accelerates its artificial intelligence drug discovery initiative.

Sources: Reuters RSS, TradingKey RSS