Three researchers at the security firmΒ HacktronΒ used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository.
The chain began with a bug in the software that runs OpenAI's public help forum and moved through a weakness in OpenAI's own login system.
This was security research,
An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSecΒ said on September 18.
The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May'sΒ supply chain attack on TanStack, in which malicious versions of TanStack's npm packages stole credentials from