AI Tool Helps Researchers Breach OpenAI Forum
OpenAI Patches Forum Vulnerability After Researchers Demonstrate AI-Powered Exploit
A security research firm has demonstrated how rapidly advanced artificial intelligence can be used to identify and exploit software vulnerabilities after researchers successfully breached an OpenAI-operated online forum using Anthropic’s latest AI tools.
Researchers at cybersecurity firm Hacktron said on Friday that they discovered a vulnerability in OpenAI’s public help forum, which runs on the Discourse platform, allowing them to gain control of the site.
Hacktron said it immediately informed both OpenAI and Discourse about the vulnerability and worked with the companies to ensure the issue was addressed.
OpenAI confirmed that the flaw was patched roughly 14 hours after the company was notified. The researchers were also awarded $6,500 for reporting the vulnerability.
“We thank the researchers for contacting us and sharing their findings,” OpenAI spokesperson Drew Pusateri said. He added that the company had tightened permissions on Community sign-in tokens and revoked affected tokens and sessions.
According to Hacktron, researchers initially used Anthropic’s Claude Opus 4.8 to identify and exploit the vulnerability. However, they faced difficulties getting the exploit to work reliably.

Following the release of Claude Opus 5, the researchers said the newer model was able to produce a functional exploit in around three hours.
Hacktron said the researchers did not use Claude Mythos, a more advanced Anthropic model that is currently restricted to a limited number of vetted cybersecurity organisations.
Anthropic has described Mythos as the company’s most capable model for cybersecurity tasks.
Hacktron also noted that the vulnerability was not specific to OpenAI. According to the security firm, the underlying software issue is present in products used by several other companies, including Slack and Meta.
The company said it is continuing to conduct similar security tests involving other organisations.
The incident highlights growing concerns within the cybersecurity community that increasingly capable AI systems could reduce the time, expertise and cost traditionally required to conduct sophisticated cyberattacks.

Comments are closed, but trackbacks and pingbacks are open.