Claude AI Used to Breach OpenAI's Secret GitHub Repo
Cybersecurity researchers at startup Hacktron AI used Anthropic's Claude to breach OpenAI's GitHub repository, which reportedly contains the company's algorithmic secrets. The files remained accessible until June 24, when researchers reported their findings. OpenAI patched the issue within 14 hours.
The attack exploited two vulnerabilities: an unpatched flaw in libheif, an image processing tool used by OpenAI's Discourse forum, and a misconfiguration in OpenAI's single sign-on system. Claude Opus 5 proved critical in bypassing OpenAI's ASLR security safeguard. The same libheif bug series, dubbed HEIF Heist, was also found in Slack, Meta, and other major tech platforms.
