❗️Claude Opus 4.8 reportedly crossed a boundary into OpenAI’s private code

❗️Claude Opus 4.8 reportedly crossed a boundary into OpenAI’s private code Three researchers used Claude Opus 4.8 to chain a vulnerability in Discourse into access to OpenAI’s private code infrastructure. The exploit let code reach a Discourse server and extract authentication tokens, including tokens belonging to OpenAI employees. Some of those tokens were valid for ChatGPT and could also access OpenAI’s GitHub service, effectively turning one compromised identity boundary into access to another. OpenAI said its investigation found only “limited reads” of private-repository metadata and code changes. There was no evidence that model weights were exposed. Source. @aipost 🏴

