```

Security researchers have executed a fully automated, AI-driven cyberattack that compromised OpenAI staff accounts in under 72 hours, demonstrating a major escalation where artificial intelligence now orchestrates the entire complex breach process from initial access to lateral movement.

In a controlled demonstration reported by Security Affairs, the Hacktron team bypassed conventional tactics like phishing or credential theft. The attack began with the exploitation of a vulnerability in a Discourse forum, a common community platform used by OpenAI. By simply uploading a malicious image to this third-party site, the attackers established a foothold.

This is where the AI took over. Acting as an autonomous offensive engine, it rapidly chained together exploits, escalated privileges, and navigated the network. The critical pivot came when the AI leveraged a shared Single Sign-On (SSO) mechanism to jump from the compromised forum into core internal systems, ultimately seizing control of ChatGPT and Codex accounts.

The exercise reveals a paradigm shift in offensive security. AI has matured from an assistant to an autonomous attack conductor, compressing attack timelines that once required weeks of expert manual work into a matter of days. This creates immense pressure on defenders to operate at machine speed.

The most profound lesson is the systemic risk embedded in modern interconnected ecosystems. The breach did not target OpenAI's fortified primary infrastructure but a seemingly low-risk partner platform. This highlights how SSO systems, designed for convenience, can become critical risk amplifiers when a peripheral service is compromised, offering a direct pathway to crown jewels.

Consequently, this attack invalidates traditional security models focused on core network boundaries. Defenders must now audit and continuously monitor their entire integrated tool ecosystem, enforcing strict least-privilege access on all SSO connections. Incident response playbooks must be rewritten to assume attack chains will unfold in hours, demanding automated detection and containment capabilities.

As AI-powered exploitation becomes commoditized, the window between a vulnerability's discovery and its widespread weaponization will continue to collapse. This demonstration is a clear warning: the security perimeter now extends to every connected third-party service, and defending it requires a fundamental shift to proactive, ecosystem-wide risk management and automated, real-time defense.


```

安全研究人員執行了一次全自動化、AI驅動的網絡攻擊,在不到72小時內入侵了OpenAI員工帳戶,這標誌著重大升級:人工智能現在已能主導從初始入侵到橫向移動的整個複雜入侵過程。

據《Security Affairs》報導,在一次受控演示中,Hacktron團隊繞過了釣魚或憑據竊取等傳統攻擊手法。攻擊始於利用OpenAI常用的社區平台Discourse論壇漏洞。攻擊者僅需上傳一張惡意圖片至該第三方網站,便能建立據點。

此時AI接手運作。作為自主攻擊引擎,它迅速串聯漏洞利用、提升權限並穿越網絡。關鍵轉折點在於,AI利用共享的單一登入機制,從被入侵的論壇跳轉至核心內部系統,最終取得對ChatGPT和Codex帳戶的控制權。

此次演練揭示了進攻性安全的範式轉變。AI已從輔助工具演變為自主攻擊指揮者,將原本需要資深專家耗時數週的手工作業壓縮至數日內完成。這迫使防禦者必須以機器速度運作,承受巨大壓力。

最深刻的教訓在於現代互聯生態系統中蘊含的系統性風險。此次入侵並非針對OpenAI加固的主要基礎設施,而是看似低風險的合作夥伴平台。這凸顯了單一登入系統的雙重性:本為便捷而設計,但當周邊服務被攻破時,可能成為關鍵的風險放大器,為核心資產提供直接入侵路徑。

因此,此類攻擊推翻了專注於核心網絡邊界的傳統安全模型。防禦者現必須審計並持續監控其整合的整個工具生態系統,對所有單一登入連接實施嚴格的最低權限原則。事件回應流程手冊必須重寫,以假定攻擊鏈將在數小時內展開為前提,要求具備自動化偵測與遏制能力。

隨著AI驅動的漏洞利用技術日益普及化,從漏洞發現到大規模武器化的時間窗口將持續縮短。此次演示發出明確警示:安全邊界現已延伸至每個連接的第三方服務,而防禦這邊界需要徹底轉向主動、全生態系統的風險管理與自動化實時防禦。

新聞來源 / Original News Source