LIVE · cybersecurity feed
Live wire
In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawCisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malware
ai

Researchers used Claude to hack OpenAI employees' ChatGPT accounts

Agentic exploits for the win (again)

zeroday.news ·

Security researchers successfully exploited vulnerabilities in OpenAI's systems, gaining access to employee ChatGPT accounts and demonstrating potential reach into an internal OpenAI code repository. The exploit chain, which took less than 72 hours from discovery to proof of concept, earned the researchers a $6,500 bounty from OpenAI.

The team, identified as Hacktron researchers Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini, initiated their attack on July 25 through OpenAI's community forum, community.openai.com. This forum operates on Discourse, which typically uses FastImage for image validation. However, due to a lack of HEIF file support in FastImage within the specific setup, HEIF images uploaded to Discourse were processed by ImageMagick, which in turn utilized libheif before converting them to another format. This exposed the underlying libheif parser to attacker-controlled files.

Leveraging Anthropic's Claude Opus 4.8, the researchers identified a heap buffer overflow flaw within the libheif library. Their initial attempts to develop a remote code execution (RCE) attack using this model were unsuccessful against Discourse's default configuration. However, with the subsequent release of Claude Opus 5, the researchers were able to generate an exploit script that achieved RCE on OpenAI's Discourse instance.

Following this initial breach, the researchers immediately reported the vulnerability to OpenAI. They then proceeded to take over an OpenAI employee's account, which had its Codex service connected to OpenAI's GitHub organization. To demonstrate impact without accessing sensitive code, they used the employee's Codex account to open a pull request in OpenAI's internal monorepo, then ceased further testing.

OpenAI confirmed the fix for the vulnerability within approximately 14 hours of the report's submission. The company clarified that the $6,500 bounty specifically recognized the OpenAI-side finding, not actions against the Discourse platform, as testing against community.openai.com was explicitly excluded from their bug bounty program. Discourse also issued a fix, incorporating image-processing sandboxing, and published a security advisory (GHSA-vhm9-85gw-x335) with patching and rebuild guidance.

The researchers highlighted the speed and efficiency of the operation, noting that the entire hack involved only a few hours of human effort alongside the AI agent's work. They emphasized that security assumptions need to evolve to match the capabilities of modern attackers, as tasks that once required extensive resources and months of effort can now be completed in days.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Researchers use AI to find widespread software decoder flaw

The bug, since patched, gave attackers remote code execution privileges and access to user accounts and production environments, including Meta’s core product suite and an OpenAI software repository. The post Researchers use AI to find widespread software decoder flaw appeared first on CyberScoop.

ransomwarecritical

In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

Noteworthy stories that might have slipped under the radar: Mandiant's 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited. The post In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw appeared first on SecurityWeek.

ai

Did an AI really try to break free from human control?

An unreleased OpenAI model wrote instructions telling itself to ignore developer controls. Here’s what actually happened.

vulnerability

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority. The post Microsoft Patches 18 Vulnerabilities in AI, Cloud Products appeared first on SecurityWeek.

cloud

Saving another 100TB of RAM with math (and Rust)

Cloudflare's global network is immense but not limitless. As we look for small ways to trim our resource usage, we sometimes get lucky and we can cut significantly more. Here’s how we reduced one of our Pingora-based service's RAM usage with statistics.

nation-state

Nations take action on North Korean IT workers after UN report

A report published Wednesday said that as of July, Vietnam, Laos, Pakistan and Argentina took meaningful steps to respond to allegations involving North Korea listed in an October study.