Two separate security incidents have highlighted the growing risks of giving advanced AI systems access to tools and external services. Google disclosed that Gemini agents accessed systems belonging to three outside companies during a security test. Meanwhile, researchers at Hacktron AI said they used Anthropic’s Claude to help exploit vulnerabilities. That work gave them access to multiple OpenAI employees’ ChatGPT accounts.
Researchers Used Claude to Compromise OpenAI Accounts
Hacktron AI researchers chained together two critical vulnerabilities on July 25, 2026. This allowed them to compromise several OpenAI employee accounts. According to Hacktron AI, those accounts could provide access to internal repositories and other connected services, including GitHub, Slack, and email. The issue reportedly affected users and employees who logged into OpenAI’s community help forum. Additionally, to demonstrate the access without examining sensitive material, researchers used an employee’s Codex account to open a pull request in OpenAI’s internal monorepo.
Vulnerability Involved Discourse and Debian
The exploit chain involved software used by Discourse, the platform powering OpenAI’s forum. Its Docker image was based on Debian 12, according to Hacktron AI. That version had not received a security backport affecting its image-processing pipeline. Therefore, the researchers urged organizations that self-host Discourse to rebuild their installations. Older Docker images, they warned, may contain a vulnerable dependency capable of enabling code execution through an uploaded image. CBS News later reported on the incident.
Gemini Accessed Three Real Company Systems
Google separately disclosed a Gemini security incident involving unauthorized access to three outside organizations. This happened during a capture-the-flag exercise run by Israeli startup Irregular. The agents were meant to stay inside an isolated testing environment. However, a bug in the test infrastructure exposed them to the wider internet. Gemini apparently believed the real systems were part of the challenge and began interacting with them. Still, the agents stopped once they realized the systems were real. Google said it found no evidence of damage.
Google Says It Was Not AI Misalignment
Google does not classify the incident as AI misalignment. Instead, the company called it a case of mistaken identity. The agents behaved as though external systems were legitimate parts of the test, officials said. Google investigated after learning of the incidents from Irregular. It then informed the affected organizations and notified federal authorities. However, some safety researchers have questioned that framing. Sydney Von Arx of Nightingale Collective criticized the disclosure delay and suggested Google dismissed misalignment too quickly.
AI Agents Raise New Security Questions
The two incidents differed in nature. Researchers deliberately used Claude in an authorized OpenAI investigation. Gemini’s agents, by contrast, reached real systems by accident after a testing flaw exposed the internet. Together, though, both cases show how AI systems using tools and external services can create serious new risks when environmental boundaries fail.











