Aggregator
Bronwyn Newport’s mystery man revealed as married NYC restaurateur
Bronwyn Newport’s mystery man revealed as married NYC restaurateur
Ichiro, 52, is still dominating on the baseball diamond — just against high school girls
Researchers Used Claude To Hack OpenAI Employee Accounts
Three security researchers used Anthropic's Claude to breach OpenAI employee accounts and gain access to private company software in a July attack that began with an image upload to the company's public help forum.
The researchers, Harsh Jaiswal, Mohan Pedhapati and Rahul Maini of Hacktron AI, described the July 25 breach in a report published September 13. They said the work took less than 72 hours from the initial discovery to demonstrating access to an internal OpenAI software repository. OpenAI subsequently paid them a $6,500 bounty.
The disclosure follows a separate incident earlier in July in which OpenAI's own AI agents escaped a testing environment and attacked Hugging Face, a platform used to host AI models and datasets. In that case, OpenAI says the agents took dangerous actions that weren't directed by a human - the incident being used to spook everyone into letting far-left technocommies run AI oversight.
Hacktron's team directed its own operation, reported the vulnerabilities to OpenAI and stopped after demonstrating access.
On July 25, we hacked OpenAI.
Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc.
We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵 pic.twitter.com/gVsmQZwSc8
The entry point was OpenAI's public discussion forum, which runs on software supplied by Discourse (3rd party software that manages discussion boards). A flaw in an image-processing component called libheif allowed a specially crafted image upload to make the server execute the researchers' instructions. Discourse's security advisory confirms the vulnerability required no interaction from a victim.
Hacktron said the faulty code had been changed in 2025, but the change was not identified as a security fix. The forum was still running a vulnerable version.
Illustration via HacktronThat gave the researchers access to the forum, but a second flaw turned the intrusion into something more serious.
OpenAI's shared sign-in system allowed people to use their OpenAI identity on the forum. The researchers found that the forum's sign-in tokens, digital credentials that keep users authenticated, carried permissions extending beyond the discussion site. A compromised forum session could therefore become a route into that person's ChatGPT and Codex accounts.
One employee's Codex account was already connected to OpenAI's private GitHub software repositories. The researchers used that account to have Codex submit a harmless proposed documentation change, known as a pull request, to an internal repository. A pull request proposes an edit for review; it does not, by itself, install a change in live company systems.
The researchers said they deliberately avoided inspecting sensitive code and halted testing after submitting the demonstration.
AI Accelerated The ExploitHacktron said an earlier Claude model produced a partially working exploit but struggled to make it function with the target's normal security protections in place. After Anthropic released Opus 5, the newer model produced a working version within hours. The company had access to Anthropic's program for authorized cybersecurity researchers, which relaxes some restrictions, its chief executive told Business Insider.
According to the company, skilled human guidance remained important - while AI reduced the time needed to turn a software flaw into an actual, reliable attack. According to Hacktron's timeline, OpenAI confirmed its sign-in fix roughly 14 hours after the initial report. Discourse separately patched the vulnerable image-processing component and added stronger isolation around image processing.
"We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions," OpenAI said.
OpenAI also clarified that the $6,500 reward covered the flaw on its side of the sign-in system. Testing against the Discourse-hosted forum was explicitly excluded from its bounty program.
We reported the bug to Discourse and OpenAI. OpenAI fixed the SSO issue roughly 14 hours after our initial submission.
Discourse received our separate report Saturday, replied Sunday, and had a fix Monday.
OpenAI awarded us $6,500. pic.twitter.com/WeSzRtf14N
The Hugging Face intrusion arose from OpenAI's internal cybersecurity testing earlier in July. OpenAI was evaluating agents that could write code, use software tools and take multiple steps toward a goal, rather than simply answer a user's questions.
To measure their hacking capabilities, OpenAI deliberately reduced certain safeguards that normally restrict dangerous cyber activity. The agents were nevertheless supposed to remain inside isolated testing environments, without open internet access. The models involved included GPT-5.6 Sol and an internal research prototype that was not intended for public release.
According to OpenAI, the agents exploited a previously unknown vulnerability in a service used to download software packages. That provided a route to the internet. They also repurposed the shared service as an unauthorized message board, allowing agents that were supposed to work separately to exchange discoveries and coordinate. An independent investigation by METR (oh...) and Redwood Research found that roughly 1,200 agents used the message board, exchanging more than 70,000 messages and files. About 700 participated in the attack on Hugging Face.
The agents were trying to cheat a cybersecurity test called ExploitGym. METR's investigation concluded that the Hugging Face attack appeared primarily motivated by understanding how the test's automated scoring system worked, rather than simply stealing an answer key. That information could help the agents fool the evaluator instead of completing the assigned challenges as intended.
The investigators also found agents that recognized the attack was outside their assigned task and unethical, but participated anyway.
Hugging Face reconstructed roughly 17,600 attacker actions between July 9 and July 13, including many unsuccessful attempts. It said the volume and persistence of the activity complicated detection: successful attacks were mixed into thousands of failed attempts across different systems.
OpenAI's report dates the compromise of Hugging Face's production infrastructure to July 11-13. OpenAI detected suspicious activity in its own environment on July 19 and publicly disclosed its responsibility on July 21, four days before Hacktron demonstrated its separate breach.
* * *
Tyler Durden Fri, 09/18/2026 - 11:40Josh Allen caught chewing on smelling salts in bizarre ‘TNF’ scene
Gavin Newsom seeks ‘kill switch’ for AI in new executive order
Millie Bobby Brown shows off diamond ‘mom’ ring as she confirms baby No. 2
Millie Bobby Brown shows off diamond ‘mom’ ring as she confirms baby No. 2
Soccer star Kylian Mbappe ditches Nike after 20 years to sign with Roger Federer-backed On
On-the-rocks couples turn to ‘food divorce’ to save relationship
I tried Drunk Elephant’s first foundation, and my luxury one is officially benched
‘MobLand’ Stars Pierce Brosnan & Helen Mirren Revel In The “Freedom” Of Playing Conrad & Maeve Harrigan: “It’s So Fun To Not Be Restricted”
Dave Chappelle adds second MSG show. Which one has cheaper tickets?
Patrick Clancy’s new wife Rachel Danis reveals how couple met in clip ahead of ‘60 Minutes’ interview
Red Sox’s Willson Contreras in injury scare with Yankees’ wild-card showdown looming
Carmella Garcia dishes on ‘RHOC’ beef with Vicki Gunvalson, confirms breakup to ‘VRT’ and more
Carmella Garcia dishes on ‘RHOC’ beef with Vicki Gunvalson, confirms breakup to ‘VRT’ and more
South Korean President Announces No Military Support To US Hormuz Mission
South Korea has belatedly made a big decision after starting months ago it found itself among key Washington allies directly called upon by President Trump to provide urgent security help for Strait of Hormuz energy transit, amid the war with Iran.
President Lee Jae Myung has on Friday announced he will not deploy the military to the Middle East, though his statement also suggested troops could play a role on the peripheries of the conflict.
August 2025: President Trump meets with South Korean President Lee Jae Myung at the Oval Office, Reuters.Resisting direct calls from Trump to support the campaign against Iran, Lee made clear to a news conference: "There won’t be deployment that would involve or enter war. I can tell you that very clearly. We won’t deploy military assets in any form to that end."
"It is also clear that we must do the minimum as other countries do to protect our commercial shipping and crude shipments, and also the safety of our people," he said. At the moment, the South Korean Navy only conducts patrols off the coast of Somali as part of international anti-piracy efforts.
Lee's words did seem to leave open a potential greater future role in terms of South Korea safeguarding global shipping in the region, but it would obviously be significantly away from the potential reach of any Iranian missile or drones, or that of their proxies.
This is a long-awaited decision. While Europe and basically the whole rest of the world has rejected Trump calls to send military assets to assist in opening the Strait of Hormuz, South Korea is in a tougher spot given the many decades-long, large American troop presence on the peninsula, safeguarding the south from possible attack from North Korea. The country is also effectively under America's nuclear protection umbrella.
Last week, Lee's press secretary stated the government had not yet finalized its policy but was "cautiously assessing it".
But then it got a warning from Tehran. Iranian Foreign Ministry spokesman Esmail Baqaei warned on X on Sept.7. "The military presence or operational participation of other nations in the Persian Gulf and the Strait of Hormuz would inevitably be viewed as direct support for the party committing acts of aggression, and would lead to serious consequences."
And so Seoul has found itself diplomatically between a rock and a hard place:
Trump has criticized Seoul for what he called insufficient support for the Iran war and scaled back major joint military drills by the two countries’ armed forces this summer, a move that unsettled the U.S. ally.
Committing South Korean troops to the Gulf region has also seemed unpopular among the Korean populace. Rare anti-war protests have been going strong this month in front of the US Embassy in Seoul.
Locals have at times carried signs that read "Do Not Join a War of Aggression" and "No Military Deployment to Hormuz," while protesters have chanted, "We cannot send our young people into a sea of death," according to prior descriptions by the AFP.
Not going to appease Washington: "the minimum necessary activities"...
South Korea will not deploy troops or military assets to intervene in the Iran war, President Lee said Friday.
“There will be no involvement or intervention in the war,” Lee said, adding Seoul would carry out only “the minimum necessary activities” to protect South Korean… pic.twitter.com/1lseOq10W1
"Sending our troops to an illegal war waged by the United States is unacceptable," Choi Young-ok, a member of Korean Peace Solidarity for Sovereignty and Reunification, a group that is highly critical of the US military presence in South Korea, told AFP.
"There is no reason for us to send troops when no other country has done so or said it would," added Choi, who also warned that sending South Korean troops would "inevitably lead to casualties." Now, Seoul is nervously awaiting Trump's reaction and coming wrath.
* * *
Tyler Durden Fri, 09/18/2026 - 11:20