

An interesting development has emerged in the field of artificial intelligence and cybersecurity. Three Indian origin researchers from cybersecurity startup Hacktron AI Harsh Jaiswal, Mohan Pedhapati and Rahul Maini used Anthropic’s Claude models to identify and demonstrate security vulnerabilities affecting OpenAI’s systems. The researchers exploited a vulnerability linked to OpenAI’s community forum and demonstrated that the issue could be chained to access OpenAI employee ChatGPT and Codex accounts, eventually reaching the company’s private GitHub environment.
The research was conducted as part of OpenAI’s vulnerability disclosure and bug bounty process. The researchers said the complete chain, from identifying the initial weakness to demonstrating access to the internal repository, took less than 72 hours. They did not read or download internal source code and instead demonstrated the potential impact by using an employee’s Codex account to open a pull request in OpenAI’s internal repository before stopping further testing. OpenAI subsequently fixed the issues and revoked affected authentication tokens and sessions. The company awarded the researchers a $6,500 bug bounty for the OpenAI-side security finding.
One of the three researchers, Mohan Pedhapati, is from Rajahmundry in Andhra Pradesh and currently serves as CTO and co founder of Hacktron AI. He specialises in web exploitation and security research. Pedhapati studied at ZPPHS Sampathnagar High School before completing his computer science degree at Rajiv Gandhi University of Knowledge Technologies, Nuzvid. His participation in the research has drawn attention to the growing role of Indian cybersecurity researchers in the rapidly evolving field of AI security.













Comments (0)
No comments yet
Be the first to comment!