AT2k Design BBS Message Area
Casually read the BBS message area using an easy to use interface. Messages are categorized exactly like they are on the BBS. You may post new messages or reply to existing messages!

You are not logged in. Login here for full access privileges.

Previous Message | Next Message | Back to Slashdot  <--  <--- Return to Home Page
   Local Database  Slashdot   [69 / 102] RSS
 From   To   Subject   Date/Time 
Message   VRSS    All   Gemini Breached Three Outside Systems, and Claude-Using Research   September 19, 2026
 3:40 AM  

Feed: Slashdot
Feed Link: https://slashdot.org/
---

Title: Gemini Breached Three Outside Systems, and Claude-Using Researchers
Breached OpenAI

Link: https://slashdot.org/story/26/09/19/0518206/g...

"Software security researchers used Anthropic's Claude AI platform to hack
OpenAI's ChatGPT tool," reports CBS News. Using Claude, "On July 25, 2026, we
chained two critical vulnerabilities to compromise multiple OpenAI employees'
ChatGPT accounts," write researchers at security platform Hacktron AI. "With
these accounts, we could then access internal OpenAI repositories, and
potentially many other connectors... Until two months ago, any user or OpenAI
employee logging into OpenAI's own help forum could have had their ChatGPT
and Codex accounts taken over. Since people can connect various services to
Codex and ChatGPT, the scope of what we could theoretically access was huge,
including GitHub, Slack and emails." The exploit chain included Debian 12,
which (with Debian 13) had not received a security-relevant backport for its
image-processing pipeline, and Discourse's Docker image was based on Debian
12. Their announcement comes with an additional warning. "If you self-host
Discourse, rebuild your installation now. Older Docker images may contain a
vulnerable libheif dependency that permits code execution through an image
upload." And "To prove we had in fact gained the access we believed without
allowing ourselves to learn any sensitive information, we used the employee's
Codex to open a PR #1186742 in OpenAI's internal monorepo openai/openai."
Meanwhile, Friday Google disclosed the first known instance of its AI
software Gemini breaking out of a testing environment and breaching three
other companies, reports CNBC: The incident happened as part of a "capture-
the-flag" security test run by Israeli startup Irregular, and Google's agents
were never supposed to access the broader internet, but a bug in the testing
environment made internet access available. The agents stopped their
intrusion when they determined they had accessed real company systems, not
just part of the testing environment, Google said. More from NBC News: Google
said it did not consider the unauthorized logins to rise to the level of
misalignment, the AI industry term for software going rogue or not following
instructions. Instead, the company said the intrusions resulted from mistaken
identity, where Gemini thought it was operating within a test but was
actually connected to the real internet. Google said the model corrected
itself and the company believed the intrusions did not cause any damage....
Sydney Von Arx, CEO of Nightingale Collective, an organization focused on AI
safety, questioned why Google did not disclose the intrusions sooner. "At
this point I think it's clear we cannot expect companies to voluntarily come
forward and publicly disclose when their agents go rogue, escape, and hack
companies," she said. She also said she believed Google was too hasty to say
that the incidents don't rise to the level of misalignment. "That's exactly
what Anthropic said after their incidents," she said. Anthropic later said
its "preliminary analysis was constrained due to our desire to disclose
incidents in a timely manner." Google said it investigated when they learned
of the attacks from AI-focused cybersecurity company Irregular, then informed
the affected organizations and told federal authorities, according to the
article.

Read more of this story at Slashdot.

---
VRSS v2.1.180528
  Show ANSI Codes | Hide BBCodes | Show Color Codes | Hide Encoding | Hide HTML Tags | Show Routing
Previous Message | Next Message | Back to Slashdot  <--  <--- Return to Home Page

VADV-PHP
Execution Time: 0.0183 seconds

If you experience any problems with this website or need help, contact the webmaster.
VADV-PHP Copyright © 2002-2026 Steve Winn, Aspect Technologies. All Rights Reserved.
Virtual Advanced Copyright © 1995-1997 Roland De Graaf.
v2.1.250224