Hackers breach OpenAI, exposing vulnerabilities in security systems

1 day ago 1



A group of security researchers managed to breach OpenAI’s internal systems in July 2026, gaining access to employee ChatGPT and Codex accounts as well as the company’s private GitHub repositories. The kicker: they used a rival AI company’s model to do it. The Hacktron AI research team, composed of Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini, publicly disclosed the breach on September 18, roughly two months after exploiting the vulnerabilities. OpenAI confirmed the incident but said no sensitive user data or production systems were compromised. How a rival’s AI helped crack OpenAI’s defenses The attack exploited two distinct weaknesses. The first was a heap buffer overflow in the libheif library, a third-party image processing tool integrated into OpenAI’s stack. The second was an overly permissive single sign-on (SSO) token that gave the researchers far more access than any external party should have had. The Hacktron team used a specialized version of Anthropic’s Claude Opus model to develop their exploits. The researchers executed their full attack chain within 72 hours of starting work. OpenAI responded quickly once notified, patching the reported vulnerabilities within app...

Read Entire Article