thehackernews.com • 57m
OpenAI Account Compromise via Claude Opus 5 and Help Forum Vulnerability
In September 2026, researchers chained a stored XSS/CSRF flaw in OpenAI’s help forum with a token‑replay weakness in its password‑reset flow, using Anthropic’s Claude Opus 5 to automate exploit generation and session hijacking. The attack yielded control of seven employee accounts, granting read‑only access to private source repositories and demonstrating a feasible path to model‑weight exfiltration or backdoor insertion within ~45 minutes.
Links:thehackernews.com, Nlcyber, Ground, Xcademia, Uphillsecurity, Trendingtopics, Newsnow, Migma •