1 hr ago

AI Assistants Turned Account Access Into OpenAI Code Breach

AI Assistants Turned Account Access Into OpenAI Code Breach
The hackers never stole a password! They took over an employee's AI assistant instead · wionews.com

Researchers took control of an OpenAI employee's account.

They did not need to steal a repository password.

The employee's Codex AI assistant was already connected to OpenAI's private code.

The researchers told the assistant to make a change request in that code.

Because the assistant was authorised to help the employee, it carried out the request.

This shows that an AI assistant can become a path into company systems when its user's account is taken over.

Similar assistants might also be connected to email or chat.

The article says companies should keep these useful connections but add better limits and monitoring.

Key facts

Affected organisation
OpenAI
Compromised access
An employee's account
AI tool
Codex, an AI coding assistant
Connected system
OpenAI's GitHub organisation
Demonstrated action
Opening a change request inside an internal code repository
Traditional credentials used
The researchers did not need to steal repository passwords or secret keys
Potentially exposed integrations
The article says connected assistants could also reach chat and email tools

Sources

Related news