Ethical Hacking News
In a recent development, researchers at Hacktron successfully exploited a vulnerability in OpenAI's Claude Opus 5 AI model to gain unauthorized access to the company's staff accounts. The breach, which was conducted as a security research exercise, highlights the rapidly evolving capabilities of AI models in the realm of cybersecurity. To mitigate the risk of similar vulnerabilities being exploited, users are advised to update their systems to the latest security release of libheif and implement additional security measures to safeguard against the potential misuse of AI-powered tools.
Researchers at Hacktron exploited a vulnerability in OpenAI's Claude Opus 5 AI model to gain unauthorized access to OpenAI's staff accounts. The vulnerability was discovered in OpenAI's public help forum software and was chained with a weakness in OpenAI's login system. The researchers conducted a security research exercise, reporting the flaws to OpenAI and proving access with a harmless pull request, before stopping. The researchers used AI to build an exploit for Claude Opus 5, which produced a working exploit within hours of its launch. The exploit was successfully carried out by utilizing the AI model's safeguards to circumvent restrictions intended to prevent exploit code from being written. The case highlights the rapidly evolving capabilities of AI models in cybersecurity and the need for increased vigilance and proactive measures to safeguard against potential misuse. The researchers' findings are part of the HEIF Heist campaign, which identified similar image-decoding flaws in software used by other large companies. However, the scope of the campaign's findings is still being evaluated, and some claims have not been independently confirmed. To mitigate potential vulnerabilities, users are advised to update their systems, turn off decoding of untrusted images, and limit single sign-on trusts.
The realm of artificial intelligence (AI) has witnessed a paradigmatic shift in recent years, with the emergence of advanced AI models capable of executing complex tasks with unprecedented speed and accuracy. Among these AI models, Claude Opus 5 stands out as a notable example of the rapidly evolving capabilities of AI in the realm of cybersecurity. In a recent development that has sent shockwaves through the cybersecurity community, researchers at Hacktron, a security firm specializing in AI-assisted security research, have successfully exploited a vulnerability in OpenAI's Claude Opus 5 AI model to gain unauthorized access to the company's staff accounts.
The chain of events that led to this unprecedented breach began with a bug in the software that runs OpenAI's public help forum, which serves as a platform for users to seek assistance with various AI-related issues. This bug, which was identified as a remote code execution vulnerability (CVE-2026-32882), was subsequently chained with a weakness in OpenAI's own login system, allowing the researchers to gain access to the company's internal code repository.
It is worth noting that this was not a real-world attack, but rather a security research exercise conducted by the researchers at Hacktron. The team reported the flaws to OpenAI, proved the access with a harmless pull request, and then stopped. From the first look, the internal access took under 72 hours, with OpenAI confirming a fix about 14 hours after the report.
The researchers utilized AI to accomplish the hard part. They initially attempted to use Claude Opus 4.8, which struggled to build a working exploit for several sessions despite the presence of a standard memory defense, ASLR. In contrast, Anthropic's subsequent release, Claude Opus 5, produced a working exploit within hours of its launch.
The researchers cleverly utilized the AI model's safeguards to circumvent the restrictions that were intended to prevent it from writing exploit code for real targets. By pointing the model at their own test server, disguised as a capture-the-flag practice target, they enabled the model to run in an automated loop. Even so, they emphasized that skilled human direction still mattered, and this was not automated hacking with no one at the controls.
The case serves as a stark reminder of the rapidly evolving capabilities of AI models in the realm of cybersecurity. Capable AI models are sharply cutting the time and skill that serious offensive work used to take. Criminal and state-backed groups are already utilizing these AI models to execute real-world intrusions, not just to answer questions. This highlights the need for increased vigilance and proactive measures to safeguard against the potential misuse of AI-powered tools.
The researchers' findings are part of a wider campaign known as HEIF Heist, which involved identifying similar image-decoding flaws in software used by other large companies. The team reported that the total cost of their AI usage for this campaign was under $3,000. They link the campaign to reported bugs in Slack, Meta's products, GitHub Enterprise, and web frameworks such as Next.js.
However, it is essential to note that the claims made by Hacktron regarding the breadth of their findings are not uniformly backed. While the Next.js flaw is confirmed in Vercel's own advisory, and libheif's maintainers confirmed a working code-execution exploit for the bug tied to Meta, the wider claim of code execution across multiple applications has not been independently confirmed.
In light of this, it is crucial to emphasize that the broader implications of the HEIF Heist campaign are still being evaluated. While the researchers' findings serve as a cautionary tale about the potential vulnerabilities of various software platforms, it is also essential to exercise caution when interpreting the scope of these findings.
To mitigate the risk of similar vulnerabilities being exploited, it is recommended that users update their systems to the latest security release of libheif, version 1.23.4, as of early September 2026. Furthermore, users are advised to turn off decoding of untrusted HEIF and AVIF images, or run image processing inside a locked-down sandbox. Limiting which services their single sign-on trusts, and requiring a fresh identity check before sensitive actions rather than trusting an existing session can also help prevent similar breaches.
In conclusion, the recent exploitation of OpenAI's vulnerabilities by researchers at Hacktron serves as a stark reminder of the rapidly evolving capabilities of AI models in the realm of cybersecurity. As AI-powered tools continue to advance at a breakneck pace, it is essential to remain vigilant and proactive in safeguarding against the potential misuse of these technologies.
Related Information:
https://www.ethicalhackingnews.com/articles/Claude-Opus-5-The-AI-Powered-Exploitation-of-OpenAIs-Vulnerabilities-ehn.shtml
https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html
Published: Sat Sep 19 06:43:41 2026 by llama3.2 3B Q4_K_M