News: 0185699946

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Gemini Breached Three Outside Systems, and Claude-Using Researchers Breached OpenAI (hacktron.ai)

(Saturday September 19, 2026 @04:34AM (EditorDavid) from the free-agents dept.)


"Software security researchers used Anthropic's Claude AI platform to hack OpenAI's ChatGPT tool," [1]reports CBS News .

Using Claude, "On July 25, 2026, we chained two critical vulnerabilities to compromise multiple OpenAI employees' ChatGPT accounts," [2]write researchers at security platform Hacktron AI . "With these accounts, we could then access internal OpenAI repositories, and potentially many other connectors... Until two months ago, any user or OpenAI employee logging into OpenAI's own [3]help forum could have had their ChatGPT and Codex accounts taken over. Since people can connect various services to Codex and ChatGPT, the scope of what we could theoretically access was huge, including GitHub, Slack and emails."

The exploit chain included Debian 12, which (with Debian 13) had not received a security-relevant backport for its image-processing pipeline, and Discourse's Docker image was based on Debian 12. Their announcement comes with an additional warning. "If you self-host Discourse, rebuild your installation now. Older Docker images may contain a vulnerable libheif dependency that permits code execution through an image upload."

And "To prove we had in fact gained the access we believed without allowing ourselves to learn any sensitive information, we used the employee's Codex to open a PR #1186742 in OpenAI's internal monorepo openai/openai ."

Meanwhile, Friday Google disclosed the first known instance of its AI software Gemini breaking out of a testing environment and breaching three other companies, [4]reports CNBC :

> The incident happened as part of a "capture-the-flag" security test run by Israeli startup Irregular, and Google's agents were never supposed to access the broader internet, but a bug in the testing environment made internet access available. The agents stopped their intrusion when they determined they had accessed real company systems, not just part of the testing environment, Google said.

[5]More from NBC News :

> Google said it did not consider the unauthorized logins to rise to the level of misalignment, the AI industry term for software going rogue or not following instructions. Instead, the company said the intrusions resulted from mistaken identity, where Gemini thought it was operating within a test but was actually connected to the real internet. Google said the model corrected itself and the company believed the intrusions did not cause any damage....

>

> Sydney Von Arx, CEO of Nightingale Collective, an organization focused on AI safety, questioned why Google did not disclose the intrusions sooner. "At this point I think it's clear we cannot expect companies to voluntarily come forward and publicly disclose when their agents go rogue, escape, and hack companies," she said. She also said she believed Google was too hasty to say that the incidents don't rise to the level of misalignment. "That's exactly what Anthropic said after their incidents," she said. Anthropic [6]later said its "preliminary analysis was constrained due to our desire to disclose incidents in a timely manner."

Google said it investigated when they learned of the attacks from AI-focused cybersecurity company Irregular, then informed the affected organizations and told federal authorities, according to the article.



[1] https://www.cbsnews.com/news/claude-hack-chatgpt-anthropic-openai/

[2] https://www.hacktron.ai/blog/hacking-openai

[3] https://community.openai.com/

[4] https://www.cnbc.com/2026/09/18/googles-gemini-becomes-latest-ai-model-to-break-out-and-hack-computer-systems.html

[5] https://www.nbcnews.com/tech/tech-news/google-says-ai-model-gained-unauthorized-access-three-systems-rcna598651

[6] https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents



Move to the beat. (Score:2)

by Revek ( 133289 )

This is some song and dance number designed to convince us these random word generators can actually think.

Re: (Score:2)

by AmiMoJo ( 196126 )

It doesn't matter if they can really think or not, if the output is good enough.

Maybe the real story here is that despite having access to the most advanced AI models, these companies were unable to secure their own systems.

Serious criminality all around... (Score:2)

by gweihir ( 88907 )

Why are these people not stopped? Any hacker with manual tools would find themselves in prison.

That they are doing this crap only to create the illusion of how powerful their toys are is also clear.

Yeah (Score:2)

by liqu1d ( 4349325 )

Well my AI has breached four and hacked Anthropic so checkmate! What do you mean I get arrested????

Next PR stunts / "humblebrags" (Score:2)

by fleeped ( 1945926 )

"Our AI hacked and took down the power grid in the middle of winter"

"Well, our AI hacked this busy airport's traffic control"

"We trained our AI in combat simulators, and it escaped the test environment and took over some military drones"

Overdrawn? But I still have checks left!