Tools
After billions on security: researchers with Claude reached OpenAI employee accounts
CSO Online wraps two separate OpenAI security disclosures: Hacktron’s team (aided by Anthropic Claude models, per their blog) reported a chain that led to OpenAI employees’ ChatGPT accounts and internal reach under coordinated disclosure — fixed, with a bounty; separately, Accomplish researchers reported two Codex sandbox-escape paths fixed within days. High-level only from the sources: identity/access and agent-control gaps, with no attack recipes or payloads. This is CSO’s gaps piece / Hacktron’s employee-account writeup plus Codex sandbox escapes, not Plugin4Shell, not Unit 42’s enterprise intrusion, and not RoboHarm.