AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts. The post AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code appeared first on SecurityWeek.
Researchers at security firm Hacktron used Claude to build a working exploit for a vulnerability in an image-processing library, then chained it with a flaw in OpenAI’s sign-in system to take over employee ChatGPT and Codex accounts, and ultimately gained access to internal code repositories.
The entry point was OpenAI’s community forum, community.openai.com, which runs on Discourse. Discourse’s built-in image checks didn’t support the HEIC/HEIF photo format, so uploads in that format were passed to ImageMagick, exposing an unpatched flaw in the libheif library it relies on for decoding.
Hacktron says the underlying bug had been fixed upstream a year earlier without ever being flagged as a security issue, so it was never assigned a CVE and missed the usual patching cycle.
Source: https://www.securityweek.com/ai-built-exploit-and-sign-in-flaw-opened-path-to-internal-openai-code/
Related breach coverage
- Critical Orkes Conductor Vulnerability Exploited in Attacks2026-09-18
CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions. The post Critical Orkes Conductor Vulnerability Exploited in Attacks appeared first on SecurityWeek.
- In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw2026-09-18
Noteworthy stories that might have slipped under the radar: Mandiant's 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited. The post In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw appeared first on SecurityWeek.
- 23 Million User Records Compromised in Gyazo Data Breach 2026-09-18
Gyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access. The post 23 Million User Records Compromised in Gyazo Data Breach appeared first on SecurityWeek.
- Check Point, Kaspersky, Tanium Patch Product Vulnerabilities2026-09-18
Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges. The post Check Point, Kaspersky, Tanium Patch Product Vulnerabilities appeared first on SecurityWeek.