Ars Technica · September 18, 2026 · 1Cifer
Claude Helped Researchers Hack OpenAI's Systems
Security researchers demonstrated that an AI agent built on Claude can be turned into an attack tool. Using it, they reached an OpenAI employee's account and got into private data stored in the company's GitHub repositories.
The issue isn't a flaw in Claude itself — it's that AI agents can carry out whole chains of actions on their own: gathering information, guessing credentials, bypassing defenses. They do this the way a person would, just faster and without getting tired. The same tool that saves hours of routine work can turn against a company if access is set up loosely.
Check what permissions your AI agents, service accounts, and integrations actually hold. Do those permissions match the real task each one is meant to perform? Access tied to role and company structure is a basic security principle: in 1Cifer, each employee's agent only sees what their position allows.


