It's been a busy week, with some big developments in the cybersecurity sphere. One that caught our attention is how assumptions around encryption are being challenged, and quantum isn't the culprit. RSA research raised fresh concerns over legacy cryptographic assumptions after researchers demonstrated that they could create valid digital signatures using an old 1024-bit RSA key without stealing or factoring the key itself.
Speaking of cyber breaches, researchers from Hacktron AI reportedly used Anthropic's Claude while chaining flaws involving OpenAI's third-party Discourse-hosted forum to gain access to an employee's ChatGPT account.
And if that wasn't enough to raise questions about where AI is heading, reports suggest OpenAI and Anthropic could delay sharing some new models with the UK AI Security Institute pending US review. The reports remain unconfirmed. If borne out, the move would put renewed focus on how and when independent national bodies can evaluate frontier models.
RSA Forgery Result Wobbles Trust in Encryption
A paper published on September 22 by researchers at UC San Diego and INRIA demonstrated a method for forging signatures against 1024-bit RSA without factoring the private key. The preprint reports that the researchers carried out the attack in 1,380 CPU core-years over five calendar months, making 232 oracle queries.
The research is notable because it presents a new way to break RSA signatures without factoring the key. The attack is practical against deprecated 1024-bit keys under the conditions examined, but the researchers said widely used RSA implementations remain safe. The researchers' central warning concerns the practical security of RSA where raw signing interfaces or equivalent oracle behavior are exposed.
That should still prompt a careful review. The authors estimate that, in their attack model, RSA parameters from 1024 to 4096 bits may offer 15 to 30 fewer bits of concrete security than factoring-based estimates suggest, and argue that this strengthens the case for moving away from RSA during the post-quantum transition. Organizations should identify legacy RSA uses and understand whether exposed APIs, hardware security modules, or blind-signature workflows create the conditions the research examines.
Claude-Assisted Hacked OpenAI in Test
Researchers from Hacktron AI reportedly used Anthropic's Claude during an authorized OpenAI bug-bounty exercise that led to access to OpenAI employees' ChatGPT and Codex accounts. According to the report, the researchers exploited a flaw in OpenAI's third-party Discourse-hosted community forum, then chained it with an OpenAI sign-on flaw to reach employee accounts and, through a connected Codex account, an internal GitHub repository.
OpenAI said it thanked the researchers for reporting the issue and had fixed the vulnerabilities. The researchers said they demonstrated the access by having an employee's Codex account open a harmless pull request in OpenAI's internal repository, rather than accessing or extracting internal code.




