Hacktron AI, a U.S. start-up specializing in cybersecurity research, announced Friday that it had compromised the ChatGPT accounts of several OpenAI employees, initially using Anthropic’s Claude chatbot. The attack was carried out as part of OpenAI’s vulnerability disclosure rewards program, and the company paid the researchers $6,500.
The three-person team chained together two critical vulnerabilities. On July 25, the researchers identified a flaw in Discourse, third-party software used for OpenAI’s community forum. After gaining access to the server, they discovered a second vulnerability that allowed them to take control of certain ChatGPT and Codex accounts, including those belonging to OpenAI employees.
One of the compromised accounts had Codex connected to OpenAI’s organization on GitHub, giving the researchers access to the cache of certain software applications and potentially to other internal systems. Hacktron said the Claude model initially used was unable to develop a working exploit, but the situation changed after a new version of the model was released.
OpenAI and Discourse were notified, and Discourse released an update on July 27. OpenAI confirmed that the vulnerabilities had been fixed. The incident adds to a series of security problems and warnings concerning the accelerated development of artificial intelligence systems.
採,Sources
Latest News
20:29
20:26
20:24
20:22
20:13
See more news