Исследователи использовали Claude, чтобы взломать сотрудников OpenAI
PoC publiccommunity.openai.comImageMagickOur summary
Hacktron researchers used Claude Opus 5 to build an exploit chain targeting community.openai.com, an OpenAI forum running Discourse, and gained access to several employees' ChatGPT and Codex accounts. The public PoC combined CVE-2026-32882 in libheif with an OpenAI SSO issue; the server used libheif 1.19.7 despite a fix in 1.22.0, enabling forum RCE and potential access to connected internal services. OpenAI remediated the issue after disclosure, while Discourse added image-processing sandboxing.
Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.