Cybersecurity researchers gain access to OpenAI’s GitHub repository using Claude
Three cybersecurity researchers used Claude to breach OpenAI Group PBC’s GitHub repository. Sources told the Wall Street Journal today that the repository contains “OpenAI’s algorithmic secrets.” The files were accessible until June 24, the day the researchers reported their findings to the company. OpenAI released a patch within 14 hours of receiving the tip. The […] The post Cybersecurity…
Three cybersecurity researchers successfully breached OpenAI Group PBC's GitHub repository by utilizing the AI model Claude, according to sources cited by the Wall Street Journal. The compromised repository reportedly contained "OpenAI's algorithmic secrets." The breach was identified six days prior to June 24, when the researchers alerted the company.
OpenAI swiftly released a patch within 14 hours of receiving the alert. The researchers, affiliated with the venture-backed cybersecurity startup Hacktron AI Inc., discovered the issue due to two vulnerabilities in OpenAI's infrastructure. The first vulnerability affected OpenAI's user forum, which operates on an open-source discussion board platform called Discourse.
The second vulnerability was found in the single sign-on (SSO) system responsible for managing employee accounts, also powered by Discourse. Discourse processes images using an open-source tool called libheif, which contained the first vulnerability. This vulnerability allowed hackers to compromise certain versions of libheif by uploading a malicious image, leading to a buffer overflow bug that could edit program data and introduce malicious code.
Despite libheif patching the vulnerability about a year earlier, Discourse failed to implement the fix, leaving OpenAI's forum exposed. Hacktron's researchers employed Claude Opus 4.8 to develop the initial exploit on June 23. Their breakthrough came the next day, when Anthropic's Claude Opus 5 model found a way around OpenAI's Address Space Layout Randomization (ASLR) implementation.
After gaining access to the company's forum, the researchers identified a configuration issue in the SSO system that powers OpenAI employees' forum accounts. They promptly notified OpenAI, and subsequently gained access to an employee's account, enabling them to map the company's internal GitHub environment. The libheif vulnerability, part of a series known as HEIF Heist, had exposed OpenAI's code and was also present in the infrastructure of other major tech firms, including Slack and Meta Platforms Inc. Hacktron advises affected users to download the latest libheif versions and harden or disable their image processing pipelines.
Written by urgent.news from SiliconANGLE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.