Bottom line: OpenAI's internal codebase has been compromised due to a previously unknown AI-built exploit.
What's happening: Hacktron researchers found an unpatched vulnerability in OpenAI's sign-in system that allowed them to access employee accounts. This vulnerability was found in OpenAI's internal codebase and was not disclosed to the company until June 2022.
What to do: Security leaders should conduct an immediate review of OpenAI's internal security controls to identify potential weaknesses and ensure compliance with industry standards.