Skip to content

Enterprise software, read for what it costs and who signs for it.

Security

Anthropic's Claude helped researchers reach OpenAI staff accounts in three days.

Three security researchers at Hacktron used Anthropic's Claude models to develop exploit code against OpenAI and reached several OpenAI employee ChatGPT accounts, The Register reported.

ERP LEADERS news desk · · First reported by The Register · Edition no. 12

The researchers wrote that they went from the first finding to demonstrating they could reach an internal OpenAI repository "by opening a harmless pull request" in under 72 hours, and then "stopped any further testing". No internal code or sensitive data was taken.

OpenAI patched the flaw in about 14 hours and paid a $6,500 bounty. The company said: "Testing against the Discourse-hosted community.openai.com was explicitly excluded from our bug bounty program. The award recognizes the OpenAI-side finding, not the actions against Discourse."

Anthropic did not respond to The Register's requests for comment.

The models that helped write the exploit are generally available. OpenAI's own statement puts part of the work on a Discourse-hosted community site that its bounty programme did not cover.

If a researcher found the equivalent in your estate this morning, how many hours until it reached your security team, and how many until it was closed?

Sources

Spotted an error? Tell us. Every correction is logged on Standards.

Your reading room

Companies in this story

Our file on Anthropic

  1. 21 SeptFiled later

    Anthropic let Accenture safety-test its AI from inside. Both expect to invest $1 billion.

  2. 20 SeptFiled later

    OpenAI's agent platform was installed at 75 firms. 69% made it their main one.

  3. 20 SeptFiled later

    Anthropic's AI led none of its own research in February. Now it leads 26%.

  4. 19 Sept

    Anthropic ordered $44.6 billion of computing from a company earning $140 million.

  5. 17 Sept

    Anthropic prepared one unreleased feature linking its AI to personal bank accounts.

All 9 Anthropic stories

For your next steering committee

Questions for your own programme. They are not findings about any company in this story.

  1. 1Ask when systems of this kind in your landscape were last patched, and who confirms it.
  2. 2Ask which finance and ERP accounts can be reached from outside, and how each sign-in is protected.
  3. 3Ask how long a restore took the last time it was tested.

Issue 01 of the ERP LEADERS brief puts a timeline, the three-number review and six questions on one page. Read issue 01

Founding reader view is on in this browser. It is a reading view, not secure access. Print the working sheet

Founding reader

Welcome back. · Issue 01

1 comment under this story on LinkedIn. Read the discussion

Keep reading

The ERP LEADERS brief Get issue 01