跳到正文
@Yuchenj_UW· @Yuchenj_UW · X·· 21 天前AI 评分62
AI 导读

三名研究人员用 Claude Opus 5 把图片上传漏洞变成对 OpenAI 员工账号的接管,再让被攻陷员工的 Codex 在 OpenAI 内部 monorepo 提交了一个 PR。整个攻击的 token 成本不到 3000 美元,此前 Opus 4.8 未能完成该利用,Opus 5 发布后数小时内即攻破。作者认为 AI 驱动的网络攻击正变得常见且廉价,最好的防御是让防守方也用上最强的 AI。

正文

OK, this is a big deal:

3 researchers used Claude Opus 5 to turn an image upload bug into an OpenAI employee account takeover, then had the compromised employee’s Codex open a PR in OpenAI’s internal monorepo.

Their entire hacking cost less than $3000 in tokens.

Opus 4.8 struggled with the exploit. Then Opus 5 dropped and cracked it within hours.

AI-powered cyberattacks are becoming common and cheap. The best defense is to put the best AI in the hands of defenders too.

来源:@Yuchenj_UW · x.com