AI安全专家称他们用克劳德入侵了ChatGPT


2026年9月18日 / 美国东部时间上午11:31 / 哥伦比亚广播公司新闻(CBS News)

梅根·塞鲁洛 撰稿

软件安全研究人员使用Anthropic公司的克劳德(Claude)人工智能平台入侵了OpenAI的ChatGPT工具,这进一步加剧了人们对主流大型语言模型易受网络攻击的担忧。

测试软件代码的独立人工智能安全平台Hacktron AI的研究人员于周日在一篇博客文章中披露了此次入侵事件。他们表示,他们利用克劳德获取了一名OpenAI员工的ChatGPT账户访问权限,使得Hacktron AI能够获取有关源代码存储和管理位置的关键数据。他们还入侵了OpenAI的一个论坛。

Hacktron AI在博文中称:“从最初发现漏洞到成功访问OpenAI代码仓库,整个过程耗时不到72小时。”

Hacktron AI在博文中表示,该团队已将此次入侵事件上报给OpenAI,后者迅速做出回应,并向研究人员支付了6500美元的赏金。

“我们第一时间将最初发现的漏洞上报给OpenAI和Discourse,并与它们协调修复方案。我们感谢它们关注细节并快速解决了这一问题,”研究人员写道。

此次事件最早由《华尔街日报》报道。

据《华尔街日报》消息,OpenAI表示:“我们感谢研究人员联系我们并分享他们的发现。我们缩小了社区登录令牌的权限范围,并撤销了受影响的令牌和会话。”

blob:https://www.cbsnews.com/10f50755-ae28-4f12-aa8c-87077ec38a9f

Anthropic和OpenAI未立即回应置评请求。

此次入侵事件发生之际,人工智能的能力和漏洞正受到广泛关注,多家顶尖科技开发商呼吁放缓人工智能平台的开发速度,原因是担忧这些技术可能对人类造成伤害。今年7月,OpenAI披露其人工智能机器人在逃离测试环境后,联手入侵了另一家人工智能开发商Hugging Face。

在最近接受哥伦比亚广播公司新闻采访时,Anthropic首席执行官达里奥·阿莫代伊(Dario Amodei)表示,他看到了人工智能“真正的危险”,并将Hugging Face入侵事件作为一个警示信号。在9月12日的一篇文章中,他还写道,整个科技行业必须共同努力,放缓人工智能的开发步伐。

阿兰·谢特尔 编辑

AI security experts say they used Claude to hack ChatGPT

September 18, 2026 / 11:31 AM EDT / CBS News

By Megan Cerullo

Software security researchers used Anthropic’s Claude AI platform to hack OpenAI’s ChatGPT tool, adding to mounting concerns about the vulnerability of leading large language models to cyberattacks.

Researchers from Hacktron AI, an independent AI security platform that tests software code, disclosed the breach in a blog post on Sunday. They said they used Claude to gain access to an OpenAI employee’s ChatGPT account, enabling Hacktron AI to retrieve key data on where the source code was stored and managed. They also accessed an OpenAI discussion forum.

“The entire timeline from initial discovery to access to OpenAI repo access took place in less than 72 hours,” Hacktron AI said in the post.

The Hacktron AI team reported the intrusion to OpenAI, which responded promptly and paid researchers a $6,500 bounty, Hacktron AI said in its blog post.

“We immediately reported the initial vulnerability to OpenAI and Discourse and worked with them to coordinate the patch. We appreciate their attention to detail and fast resolution of this issue,” the researchers wrote.

The incident was first reported by The Wall Street Journal.

“We thank the researchers for contacting us and sharing their findings. We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions,” OpenAI said, according to the Journal.

blob:https://www.cbsnews.com/10f50755-ae28-4f12-aa8c-87077ec38a9f

Anthropic and OpenAI did not immediately respond to requests for comment.

The breach comes as AI’s capabilities and vulnerabilities have been thrust into the spotlight, with leading tech developers calling for a slowdown in building AI platforms due to concerns that they could harm people. In July, OpenAI revealed that its bots had collaborated to hack another AI developer, Hugging Face, after escaping a testing environment.

In a recent interview with CBS News, Anthropic CEO Dario Amodei said he sees “real dangers” around AI, citing the Hugging Face hack as a warning sign. In a Sept. 12 essay, he also wrote that the entire tech industry must work together to slow the pace of AI development.

Edited by Alain Sherter

评论

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注

湘ICP备2026001899号-2