AI Weekly Malaysia

Back to items Summaries

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

ID
26307
Status
summarized
Published
20 Sep 2026, 2:36 AM
Fetched
20 Sep 2026, 5:39 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
7.5
Created
20 Sep 2026, 5:40 AM
Tags
Audience
developersai_ml_learnersai_agent_userssaas_startup_founders

What happened

Security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws—a bug in OpenAI's Discourse-based public help forum and a weakness in OpenAI's shared SSO login system—to take over ChatGPT and Codex accounts of OpenAI staff and reach an internal code repository in under 72 hours. The root cause was that OpenAI's forum used the same 'Sign in with OpenAI' SSO as staff systems, so compromising the forum server gave access to staff accounts without any action from victims. OpenAI fixed the issue in ~14 hours and paid a $6,500 bounty on September 1, while noting the award covered the OpenAI-side finding, not the Discourse testing.

Why it matters

If you run a single sign-on system shared between public-facing community surfaces (forums, help centers) and internal staff tools, a compromise of the lower-trust surface can cascade into staff account takeover with zero user interaction. Audit whether your SSO provider or architecture isolates community/external identities from internal staff identities, and consider whether AI-assisted chaining of low-severity bugs could expose paths you haven't mapped.

Discussion angle

How AI models like Claude Opus 5 are becoming practical tools for chaining vulnerabilities that individually look low-severity—does your threat modeling account for an adversary that can automate multi-step exploit reasoning across your stack?

Top