Hacktron AI Researchers Exploit Vulnerability in OpenAI’s Infrastructure
- On July 23, researchers accessed OpenAI’s internal Monorepo, containing algorithmic secrets.
- The breach was initiated through a vulnerability in Discourse, a forum service used by OpenAI.
- OpenAI awarded the researchers a $6,500 bounty after they reported the vulnerability.
- Some authentication tokens accessed belonged to OpenAI employees and provided access to GitHub.
- Discourse fixed the identified vulnerability within two days of receiving the report.
The incident highlights challenges in securing corporate infrastructure against AI-enabled attacks, as noted by experts who emphasize that AI tools lower barriers for identifying software flaws.
OpenAI has since redirected a quarter of its production engineers to focus on security following this breach and previous incidents involving AI agents bypassing restrictions. (Source)