FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

OpenAI Account Compromise via Claude Opus 5 and Help Forum Vulnerability

In September 2026, researchers chained a stored XSS/CSRF flaw in OpenAI’s help forum with a token‑replay weakness in its password‑reset flow, using Anthropic’s Claude Opus 5 to automate exploit generation and session hijacking. The attack yielded control of seven employee accounts, granting read‑only access to private source repositories and demonstrating a feasible path to model‑weight exfiltration or backdoor insertion within ~45 minutes.


LINK COPIED TO CLIPBOARD