ወደ ዜና ተመለስ
ደህንነትAI Understanding አጭር መግለጫ

ተመራማሪዎች የOpenAI የሰራተኛውን ChatGPT መለያ ለመጥለፍ የAnthropicን Claude AIን ይጠቀማሉ።

የደህንነት ተመራማሪዎች የOpenAI ሰራተኛን ChatGPT መለያ ለመጥለፍ እና የኩባንያውን ውስጣዊ GitHub አካባቢ ለመድረስ የAnthropic's Claude Opus 5ን ተጠቅመዋል።

4 min readRead the original reporting
Source-provided image accompanying Researchers Use Anthropic's Claude AI to Hack OpenAI Employee's ChatGPT Account
ሪፖርት ተደርጓልምንጭ ተመዝግቧል
አታሚ
venturebeat.com
ምንጭ አገናኝ
venturebeat.comhttps://venturebeat.com/security/openai-hacked-by-small-team-of-white-hat-security-researchers-using-anthropics-claude-opus-5
የምንጭ ዓይነት
በዜና ማሰራጫ ሪፖርት ማድረግ - የአንደኛ ወገን ሰነድ አይደለም።

በግል ማረጋገጥ ያልቻልነው ነገር: ይህ የይገባኛል ጥያቄ በተሰየመው መውጫ ምክንያት ነው። በአንደኛ ወገን ሰነድ ላይ አላረጋገጥነውም። (venturebeat.com)

አውድይህንን በ60 ሰከንድ ውስጥ ይረዱት።

እዚ ጀምር

እራስህን ፈትን።AI ወኪሎች ጥያቄዎች

ምን ተፈጠረ

Security researchers from Hacktron AI used Anthropic's Claude Opus 5 to hack an OpenAI employee's ChatGPT account and reach the company's internal GitHub environment. The researchers discovered a vulnerability in OpenAI's single sign-on implementation that allowed them to turn control of the forum environment into access to ChatGPT and Codex accounts belonging to users who had authenticated through the service. They then used the compromised employee account's access to Codex to create a harmless pull request in OpenAI's internal monorepo, demonstrating that the account compromise could extend beyond ChatGPT itself into connected developer infrastructure.

The researchers used Anthropic's Claude Opus 5 to investigate the vulnerable libheif package and develop an exploit.

They initially used Claude Opus 4.8 but switched to Opus 5, which produced a working ARM64 exploit within hours.

The researchers then adapted the exploit to the x86-64 and jemalloc environment used by Discourse.

The full path from discovery to access to OpenAI's repository environment took less than 72 hours.

The researchers reported the findings through OpenAI's Bugcrowd program on July 25 and received a payout of $6,500.

የምንጭ ዝርዝሮች: venturebeat.com ↗

ለምን አስፈላጊ ነው።

This incident highlights the risks associated with AI agents connected to business systems and the importance of isolating untrusted file-processing pipelines, keeping low-level dependencies aggressively patched, constraining federated identity trust, and treating AI-agent credentials with the same scrutiny as privileged human accounts.

The incident highlights the risks associated with AI agents connected to business systems.

It demonstrates how AI coding agents are changing the economics of sophisticated vulnerability exploitation.

The researchers argue that frontier coding agents can increasingly perform much of the incremental exploit-development work under human direction.

The broader libheif ecosystem reinforces the maintenance problem, with dozens of security advisories published during 2026.

The incident emphasizes the need for organizations to take a more proactive approach to security, including isolating untrusted file-processing pipelines, keeping low-level dependencies aggressively patched, constraining federated identity trust, and treating AI-agent credentials with the same scrutiny as privileged human accounts.

Interactive Mechanism

በይነተገናኝ ሜካኒዝም፡ በትክክል እንዴት እንደሚሰራ

ከዚህ ልማት በስተጀርባ ያለውን ቴክኖሎጂ በይነተገናኝ ያስሱ።

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
በይነተገናኝ ጽንሰ-ሐሳብ ቼክ+10 Points
AI Agents Quiz

An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?

ቀጥሎ ምን እንደሚታይ

The incident demonstrates how AI coding agents are changing the economics of sophisticated vulnerability exploitation and the need for organizations to take a more proactive approach to security.

The incident demonstrates the potential impact of AI agents on security.

It highlights the need for organizations to take a more proactive approach to security.

The researchers argue that AI coding agents are changing the economics of sophisticated vulnerability exploitation.

The incident emphasizes the importance of isolating untrusted file-processing pipelines and keeping low-level dependencies aggressively patched.

The researchers note that the same class of models is making technically difficult exploit development faster and less expensive.

ተዛማጅ መመሪያዎች እና ጥያቄዎች

AI ወኪሎችAI ደህንነትየሚያውቁትን ይሞክሩ - ነፃ የ AI ጥያቄዎችን ይሞክሩበእኛ የቃላት መፍቻ ውስጥ የ AI ቃልን ይፈልጉየ AI ደንብ መከታተያ ይከተሉ
ይህ ጠቃሚ ሆኖ ተገኝቷል?