Hook

Their other posts in the index, biggest breakout first.
A security researcher used Claude to exploit a bug in the platform that operates all the ticketing for all US music festivals, including Lollapalooza, EDC, south by southwest, and ACL. The vulnerability that he found would have allowed him to issue to himself or anybody any number of tickets of any kind, GA, VIP, whatever absolutely for free and have access to a ton of private user data, the ability to change people's passwords, and the ability to change the passwords of the admins. Frontgate Tickets is a subsidiary of Live Nation, just like Ticketmaster, and they operate all the ticketing for all the festivals in the US except for Coachella. This researcher, Ian Carroll, is supposedly part of a program that Anthropic runs called Cyber Verification Program. The researcher noticed that all of the ticketing for a bunch of festivals he was looking into were all being operated by the same provider, Front Gate. Not just for online ticketing, but also their physical box office was operated by the same place. When combing through their API, he noticed there were parameters in their code missing and there was a SQL injection vulnerability. All he had to do to get around the app's firewall was prompt Claude. Claude helped him get full access into the database with staff credentials, customer information and login credentials. A ton of the sites live tokens. You would have been able to take over any of those accounts or fulfill any orders for any number of tickets for any of the festivals at any level of ticket. He reported it right away, probably because he's part of this cyber verification program. And also, you probably don't wanna get charged for fraud for stealing tickets to something like Lollapalooza. But he said when he reached out to Front Gate and Live Nation, he found no security contact to tell this information to and no bug bounty program. Front Gate and Live Nation claimed they did know something about this before it was brought to their attention by this researcher. He did uncover this in April. It's only being disclosed to the public in July. So I imagine they had some work to do on their end. On the surface, it's just a developer finding a bug in public software. But what's interesting is the disparity between companies and their allotment of resources to cyber security while the technology for cyber crime is advancing by the day. If he didn't have access to Claude, this wouldn't have been so easy for him to do. And sure, Claude might not allow a regular user to hack into any website, but they are just one of a dozen models, both based in the US and China, that probably would do this. If you asked