Small Business AI

AI Is Making Hacking Faster. Small Businesses Should Fix the Basics First.

AI helped researchers chain two flaws into OpenAI's systems through its bug bounty. For small businesses, the answer is dull, reliable security basics.

September 18, 2026 · 3 min read

What changed

Details published September 18 describe how Hacktron AI, a small security startup, got into some of OpenAI's internal systems in July. According to TechCrunch and Hacktron's own write-up, the team used Anthropic's Claude models (Opus 4.8, then Opus 5) to help build an exploit for a bug in the image-handling code behind OpenAI's community forum, which runs on the Discourse software. They then chained it with a separate flaw in OpenAI's sign-in setup that let forum access lead to employee ChatGPT and Codex accounts. To prove the access was real without digging through anything sensitive, they had an employee's Codex account open a harmless pull request in OpenAI's internal code repository, then stopped. They reported it through OpenAI's bug bounty program on July 25. OpenAI confirmed a fix about 14 hours later and paid $6,500. Hacktron says the whole path, from first discovery to that proof, took under 72 hours.

The honest nuance

This was not an attack on OpenAI's customers, and it was not an AI acting alone. The researchers were authorized bug-bounty participants who stopped early and disclosed what they found. OpenAI said, as quoted by SecurityWeek, that it narrowed the permissions on its community sign-in tokens and revoked affected tokens and sessions. Its own review found limited reads of private-repository metadata and commits, plus a pull request that touched only a README file. None of the coverage we found reports customer data being exposed, though that is the absence of a report, not a guarantee. A few more caveats. Hacktron says the older Claude model got only partway, and a working exploit came after Opus 5 arrived, with the researchers steering throughout. Its write-up also says OpenAI's GPT-5.6 Sol was used later in its broader research, so this is not a clean story about one vendor's tool. And OpenAI said the bounty rewarded the OpenAI-side finding, not the testing against the Discourse software, which was reported separately and patched by Discourse.

Why it matters for your business

No one should read this as "a startup with an AI subscription is about to break into your shop." The more sober takeaway, based on Hacktron's account, is that turning a known kind of bug into a working exploit can take less time than it used to. The same tools that help defenders find flaws can help anyone probing ordinary businesses, and a smaller gap between "a flaw exists" and "someone tries it" leaves less room for slow updates. What made this chain work is familiar: a bug in third-party software on a side system, and a sign-in arrangement where access to one account reached further than it needed to. Small businesses have their own versions, such as a forgotten website plugin, a former contractor's login, or one email account that can reset everything else. You do not need expensive new security software to respond. You need the basics done consistently: multi-factor authentication (MFA), unique passwords in a password manager, prompt updates, and access that ends when a person's role does. MFA would not necessarily have stopped this specific chain, but it addresses the far more common problem of stolen or reused passwords.

What to actually do

Set aside 30 minutes this week. Write down the five accounts that would hurt most to lose, and do them in this order: your business email first (it can reset most other accounts), then your bank and payment processor, your website or ecommerce platform, your cloud storage or accounting tool, and your domain registrar. For each one, turn on MFA (an authenticator app or passkey where offered, text codes if that is all there is) and make sure the password is unique and saved in a password manager. Then, next to each account, list who has access. Remove anyone who has left, any contractor whose project ended, and any shared login you can replace with individual ones. While you are there, switch on automatic updates for your website software and plugins. That one page of notes will tell you more about your real exposure than another tool would.

From Kindloom Labs

If your team is also using AI tools day to day, the free Quick Read What Not to Paste Into AI covers keeping passwords, keys, and customer details out of chats, a good companion to the account cleanup above.

Stay in the loop

Get notified about new releases, content, and blog updates from Kindloom. No spam, unsubscribe anytime.

← Back to blogBrowse one-time paid kits