Tech & AI News
The Next Web

Three researchers used Claude to reach OpenAI’s internal code. OpenAI paid $6,500 and closed the hole in 14 hours.

Three researchers at Hacktron AI used Anthropic’s Claude to chain two existing web-security weaknesses—an image-upload flaw in OpenAI’s forum software and a configuration error that let session tokens access employee services—reaching internal code repositories in under 72 hours. OpenAI patched the single-sign-on flaw in about 14 hours and paid the team $6,500. The incident highlights that the speed of exploitation has accelerated, but the vulnerabilities themselves are classic, decades-old web-security issues.