A group of security researchers utilized Anthropic's generative AI, "Claude," as an auxiliary tool for attacks, conducting a cyber attack simulation against OpenAI's internal systems. In this investigation, the researchers reported identifying system vulnerabilities and confirming the process leading to a compromise in a remarkably short period of just 72 hours.
This case was not tied to a specific product launch or vulnerability disclosure, but rather served as a proof-of-concept experiment for a security investigation process using Large Language Models (LLMs). The researchers leveraged Claude as an attack support tool, accelerating the entire workflow from target system reconnaissance to vulnerability exploitation.
This investigation demonstrated that state-of-the-art LLMs possess high capabilities in complex code analysis and the identification of security flaws. Attackers are now able to gather information more efficiently than with conventional tools, rapidly formulating scripts and strategies that exploit gaps in system environments.
With the advancement of generative AI, the cybersecurity threat landscape is changing rapidly. This case highlights the dual-sided risks of AI—enhancing not only defensive capabilities but offensive ones as well. Moving forward, alongside leveraging AI for defense, building monitoring and defensive measures against new attack methodologies that abuse LLMs has become an urgent priority.