LIVE · cybersecurity feed
Live wire
CVE-2026-58138 · Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildBrevo Supply-Chain Attack Infected Over 100,000 WebsitesPublic Exploits Released for Linux Kernel Root Privilege FlawsIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawCisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEs
phishing

AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum

AI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO. Three researchers at Hacktron just took over ChatGPT and Codex accounts belonging to OpenAI staff. The attack did not rely on phishing techniques or a leaked password. Through an image upload on OpenAI’s […]

zeroday.news ·

Three researchers from Hacktron successfully exploited a vulnerability in the Discourse forum used by OpenAI, gaining unauthorized access to staff accounts for ChatGPT and Codex. The attack, which took less than 72 hours from initial discovery to accessing an internal OpenAI code repository, highlighted risks associated with shared single sign-on (SSO) systems.

The method of attack did not involve phishing or stolen passwords. Instead, it leveraged a heap buffer overflow vulnerability within the `libheif` library, which Discourse uses to process HEIC and HEIF image uploads via ImageMagick. This memory corruption flaw allowed attackers to read or write data outside of intended memory regions. While the vulnerability had been fixed upstream in `libheif` the previous year, the patch lacked a CVE identifier and had not been backported to Debian, which Discourse utilized.

A notable aspect of the exploit development was the role of artificial intelligence. Initially, the researchers tasked Claude Opus 4.8 with creating an exploit, but it struggled with protections like Address Space Layout Randomization (ASLR). Upon the release of Anthropic's Opus 5, the same task was given to the new model, which successfully generated a working exploit against a local Mac system in just three hours. The researchers observed further improvements with GPT-5.6 Sol, which could exploit the vulnerability without prior knowledge of the target system.

After developing the exploit, the researchers adapted it to Discourse's server environment, which ran x86-64 with jemalloc. They achieved local code execution and then, using their cloud instance disguised as a capture-the-flag target to bypass Opus 5's refusal to attack live systems, gained root-level access. They confirmed this by reading the `/etc/hosts` file.

The same exploit was then used against OpenAI's Discourse instance. To demonstrate account takeover without causing harm, the researchers utilized a hijacked employee's Codex account to create a single, harmless pull request within an internal OpenAI code repository. No source code was accessed, no merges were performed, and no changes were shipped.

Following the demonstration, the researchers reported their findings to both OpenAI and Discourse. OpenAI confirmed a fix approximately 14 hours after the initial report and awarded a $6,500 bounty. OpenAI clarified that the bounty specifically recognized the "OpenAI-side finding" and not actions against the Discourse-hosted community forum, as testing against that platform was outside their bug bounty program's scope. Discourse, for its part, released a patch the following Monday and implemented additional sandboxing for its image processing to enhance security.

The Hacktron team emphasized that the underlying vulnerability allowing escalation was not specific to Discourse but rather an issue with OpenAI's SSO architecture. They stated that any first-party or third-party OpenAI service using the OpenAI SSO, if compromised, could lead to similar access. This points to an identity architecture problem rather than solely a forum or image library flaw.

This incident is part of a broader research initiative by Hacktron called "HEIF Heist," which has spent two months investigating the same `libheif` issue across various companies and frameworks, including Slack, Meta, GitHub Enterprise, and Next.js. The total cost for AI usage across three researchers for this extensive campaign was less than $3,000, illustrating a significant shift in the cost and accessibility of exploiting memory corruption bugs. Organizations are advised to verify the `libheif` version running if their products accept HEIC, HEIF, or AVIF uploads and to re-evaluate shared login systems between public-facing services and critical internal infrastructure.

phishingbreachvulnerabilityai
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

North Korean WaterPlum hackers infected 30,000 devices worldwide

A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. [...]

ransomware

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. [...]

CVE-2026-58138critical

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution. "Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote

ai

Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up

Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal. The incidents occurred in May 2026 as part of a test run conducted by Israeli company Irregular. The evaluation partner was also involved in similar hacks disclosed

nation-state

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18. The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May's supply chain attack on TanStack, in which malicious versions of TanStack's npm packages stole credentials from

security

Flock Offers Employees Buyouts as Customers Flee

As dozens of cities end contracts for its controversial license plate readers, Flock is rolling out a voluntary severance program, WIRED has learned.