Security researchers have demonstrated how advanced artificial intelligence models are rapidly transforming cybersecurity after successfully using Anthropic’s Claude to gain access to OpenAI’s internal community platform. The findings, disclosed by security firm Hacktron, highlight both the growing capabilities of modern AI systems and the increasing importance of strengthening software security as these technologies become more sophisticated. According to the researchers, the exercise was conducted as part of responsible security testing, with the identified issue promptly reported to both OpenAI and the developers of the affected platform before any public disclosure.
Hacktron said it discovered a security vulnerability in OpenAI’s public help forum, which operates on the Discourse platform, allowing the researchers to take control of the website during their testing. The company explained that it followed responsible disclosure practices by immediately notifying OpenAI and Discourse after confirming the issue. In a blog post, Hacktron said it worked closely with both organizations to coordinate the release of a security patch before publishing technical details. The researchers also acknowledged the quick response from both teams, stating that they appreciated the attention to detail and the rapid resolution of the vulnerability. OpenAI confirmed that the issue was addressed within approximately 14 hours after receiving the report and awarded Hacktron a bug bounty of US$6,500 for responsibly identifying the flaw. OpenAI spokesperson Drew Pusateri said the company narrowed the permissions on Community sign in tokens while revoking the affected tokens and active sessions to prevent further exposure.
According to Hacktron, the research initially relied on Anthropic’s Claude Opus 4.8 model to identify and exploit the software weakness. While the earlier version was able to assist in discovering the vulnerability, the researchers said they experienced difficulties achieving reliable results. That changed after Anthropic introduced Claude Opus 5, which they described as significantly more effective during the testing process. Hacktron said the updated model generated a working exploit within roughly three hours, demonstrating how improvements in AI capabilities can substantially reduce the time required for complex cybersecurity tasks. The researchers noted that they did not use Claude Mythos, Anthropic’s more advanced cybersecurity focused model that is currently available only to a limited group of vetted cyber defense organizations. Anthropic has described Mythos as possessing the strongest cybersecurity capabilities of any AI model it has developed to date.
Hacktron further stated that the software vulnerability identified during the assessment is not exclusive to OpenAI and exists in software components used by numerous organizations, including products associated with Slack and Meta. The company said it continues to conduct similar security evaluations involving other organizations to better understand the broader impact of comparable weaknesses across widely deployed platforms. The findings also contribute to an ongoing discussion within the cybersecurity community regarding the dual use nature of advanced AI systems. While these models are becoming increasingly valuable tools for security researchers, software developers and defenders, experts have also expressed concern that the same technology can significantly reduce the time, cost and technical expertise traditionally required to perform sophisticated cyberattacks. The latest demonstration serves as another example of how rapidly evolving AI capabilities are reshaping cybersecurity practices, reinforcing the need for organizations to continuously improve vulnerability management, responsible disclosure processes and defensive security measures as artificial intelligence becomes more deeply integrated into both cyber defense and offensive research.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.