Show notes
In this episode, we discuss how security researchers at Hacktron used Anthropic's Claude Opus 5 to build an exploit chain that reached into OpenAI's private repo through a single sign on weakness and connected Codex accounts, earning a bug bounty after OpenAI patched the identity flaw in about fourteen hours. We also cover Anthropic's new internal data on how much Claude Code is contributing to its own AI research, including the jump in success on open ended research tasks and the caveats around vendor reported, model graded results. Finally, we break down California Governor Gavin Newsom's executive order pushing independent AI auditors, externally validated safety plans, and continuously tested emergency shutoff mechanisms for frontier models, plus why an AI kill switch is far easier to write into policy than to engineer. Along the way we look at what agent permissions, identity infrastructure, and private code repositories mean for your attack surface.
https://www.aiconvocast.com
Help support the podcast by using our affiliate links:
Eleven Labs: https://try.elevenlabs.io/ibl30sgkibkv
Disclaimer:
This podcast is an independent production and is not affiliated with, endorsed by, or sponsored by Anthropic, OpenAI, Hacktron, the State of California, or any other entities mentioned unless explicitly stated. The content provided is for informational and entertainment purposes only and does not constitute professional, security, legal, or financial advice. Some links above are affiliate links, and we may earn a commission if you make a purchase through them at no additional cost to you.