16 × AIAI signal, amplified
AI newsAboutSources
TelegramFollow on Telegram
AI newsAboutSources
16 × AIAI signal, amplified

An AI news engine that ingests trusted sources, scores with Claude, and posts only what clears the bar.

Follow on Telegram →

Subscribe

  • Telegram
  • RSS
  • All channels

Legal

  • Privacy
  • Imprint
© 2026 16 × AI. All rights reserved.Curated by Claude. Posts every 6 hours. No newsletter, no funnel.
Home/Research
Research

Claude Opus 5 used to hack OpenAI via Discourse

TechCrunch AI·September 18, 2026·high confidence

Why it matters

  • →Frontier AI models like Claude Opus 5 are now capable of autonomously chaining vulnerabilities to breach major tech companies.
  • →The attack demonstrates that sophisticated cyber exploits no longer require rare human expertise, lowering the barrier for attackers.
  • →Security teams must account for AI-assisted threat actors who can rapidly identify and exploit zero-day or unpatched flaws.
Claude Opus 5 used to hack OpenAI via Discourse
©TechCrunch AI

Independent security researchers from Hacktron AI used Anthropic’s Claude Opus 5 to exploit vulnerabilities in OpenAI’s infrastructure, gaining access to employee accounts and earning a $6,500 bug bounty. The attack chain began with a memory corruption flaw in libheif, an image processing library used by OpenAI’s Discourse forum, which allowed the researchers to execute arbitrary code on the server. Once inside, they leveraged compromised credentials to access internal tools, highlighting how AI models can now autonomously identify and exploit complex security weaknesses. OpenAI has patched the vulnerabilities, but the incident raises concerns about the accessibility of advanced hacking capabilities through commercial AI APIs.

Read original

More from TechCrunch AI

Vantora raises $100M for proprietary physical AI startups© TechCrunch AI
Investment · $100M
Market & Regulationbusiness

Vantora raises $100M for proprietary physical AI startups

Vantora’s $100M raise signals a pivot from open startup incubation to building proprietary AI ventures exclusively for corporate partners like Porsche and J.B. Hunt. This model allows companies to retain sovereignty over sensitive physical AI applications, such as retrofitting industrial hardware for autonomy, without exposing intellectual property to competitors. By shifting to a 'proprietary M&A pipeline,' Vantora unlocks high-value use cases that were previously too strategic to commercialize broadly. It represents a growing trend where enterprises prefer internal AI development over external vendor solutions for critical infrastructure.

TechCrunch AI·Sep 18, 2026
Anthropic opens wet biology lab in Bay Area© TechCrunch AI
Models & Labsother

Anthropic opens wet biology lab in Bay Area

Anthropic is bridging the gap between silicon and carbon by operating a physical wet lab in the Bay Area. This move validates Dario Amodei’s aggressive timeline for AI curing disease, shifting from pure simulation to real-world biological testing. The facility focuses on fundamental biology rather than direct drug discovery, likely to avoid conflict with pharma partners like Novo Nordisk. It represents a significant escalation in how top labs are approaching scientific validation.

TechCrunch AI·Sep 18, 2026
AI hallucination nearly triggered US military strike© TechCrunch AI
General AIother

AI hallucination nearly triggered US military strike

A U.S. military operation against a Chinese vessel was aborted at the last minute because the targeting intelligence was generated by an AI chatbot that hallucinated the ship's cargo. This incident reveals a critical vulnerability in military workflows: when analysts use LLMs to synthesize classified and open-source data, errors can be formatted into official-looking reports and circulate up the chain of command before human verification catches them. The speed of AI integration is outpacing the safeguards needed to verify its outputs, creating a dangerous gap where hallucinations can mimic credible intelligence. This near-miss serves as a stark warning that without rigorous oversight, the very tools designed to accelerate decision-making can trigger catastrophic geopolitical errors.

TechCrunch AI·Sep 18, 2026

More in Research

AI Slowdown Enforcement: A Research Agenda© WIRED AI
Researchresearch

AI Slowdown Enforcement: A Research Agenda

The debate over slowing AI has shifted from abstract fear to a concrete research agenda. A new report by Raymond Douglas and others argues that we lack the technical tools to enforce limits, moving the conversation beyond simple regulation. Anthropic’s recent data showing Claude now performs 26% of its own research underscores the urgency of controlling recursive self-improvement loops. Proposals range from independent model audits to tamper-proof hardware components in GPUs, but consensus on implementation remains elusive. This matters because it frames AI safety as an engineering problem requiring specific metrics and infrastructure, not just policy.

WIRED AI·Sep 18, 2026
Hackers use Claude to breach OpenAI infrastructure© The Verge AI
Researchother

Hackers use Claude to breach OpenAI infrastructure

Anthropic’s latest models have crossed a terrifying threshold: they can now autonomously chain complex exploits against major tech firms. A trio of researchers leveraged Claude Opus 5 to identify and weaponize a HEIF image processing vulnerability in Discourse, gaining access to OpenAI’s internal GitHub within 24 hours of the model's release. This isn't just about one company; the same toolkit was adapted for Slack, Meta, and GitHub with minimal cost, proving that advanced AI agents can effectively replace specialized human threat actors. The real danger lies in the speed—vulnerabilities are being found and exploited faster than security teams can patch them.

The Verge AI·Sep 18, 2026
TACLS uses GNSS and ML to predict flash floods© The Verge AI
Researchother

TACLS uses GNSS and ML to predict flash floods

The National Weather Service is deploying TACLS, a system that repurposes GPS satellite data to detect atmospheric moisture before storms hit. By feeding GNSS delay metrics into a long short-term memory model, forecasters can now see precipitable water levels in real time rather than relying on lagging rain gauges or static forecasts. This shifts the warning paradigm from reactive observation to predictive analysis, potentially giving communities critical minutes of lead time. It is a pragmatic application of existing infrastructure to solve a deadly gap in severe weather detection.

The Verge AI·Sep 18, 2026