
Pare che il mazzocchio ha sfondato la sicurezza di OpenAI, e la banda di hacker non ha usato solo la forza bruta. Un trio di ricercatori di sicurezza indipendenti di Hacktron ha riportato di aver potuto compromettere account dipendenti di OpenAI in un lampo, letteralmente in meno di tre giorni. Lo strumento che ha reso possibile questa impresa, secondo i dettagli emersi, è stato Claude Opus 4.8 e 5, l’avanzato modello di linguaggio di Anthropic. Il vero tesoro rubato non erano solo i dati personali, ma anche l’accesso al celebre repository GitHub denominato ‘Monorepo’. Fonti vicine a Wall Street Journal suggeriscono che questo ‘Monorepo’ sia la sorta di scatola nera dove OpenAI conserva i suoi ‘segreti algoritmici’. Insomma, tre ricercatori, armati di un AI potente come Claude, sono riusciti a sfogliare i segreti del codice di uno dei giganti della tecnologia, dimostrando che, nel campo della sicurezza, la genialità (e un prompt ben formulato) può essere un superpotere… molto pericoloso.
🇬🇧 Summary in English
It seems that the mighty have fallen, and the hackers didn’t need brute force to breach OpenAI’s defenses. A trio of independent security researchers from Hacktron managed to compromise OpenAI employee accounts in a matter of hours, according to reports. The key to this swift, sophisticated intrusion, the reports indicate, was Anthropic’s Claude Opus 4.8 and 5, an advanced large language model. But the real prize wasn’t just personal data; it was access to OpenAI’s highly guarded GitHub repository, known as ‘Monorepo.’ Sources suggest that this repository is the vault where OpenAI keeps its ‘algorithmic secrets.’ Essentially, three researchers, armed with a powerful AI like Claude, were able to peek at the codebase secrets of a tech behemoth. It’s a spicy reminder that in the world of cybersecurity, high intelligence (and a well-crafted prompt) can be a seriously potent—and frankly, worrisome—superpower.
Leggi l’articolo originale su The Verge →
Fonte: The Verge | Argomento: Cybersecurity
#tecnologia #innovazione #technews