Urgent.News

What's breaking now, across thousands of outlets.

Tech

Hacking OpenAI

On July 25, 2026, a group of hackers exploited two critical vulnerabilities to compromise multiple OpenAI employees’ ChatGPT accounts. This allowed them access to internal OpenAI repositories and potentially many other connected systems. To demonstrate their findings without causing damage, they created a harmless pull request in OpenAI's internal monorepo.

The vulnerabilities were discovered by HacktronAI team, led by Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini, who were researching security issues in frontier AI companies. They found an SSO misconfiguration in OpenAI's identity infrastructure and a libheif Remote Code Execution (RCE) in the community forum used by OpenAI. Despite upstream changes, the backported security fix was not documented, leading to the vulnerability remaining unpatched in some distributions. HacktronAI reported the issue to OpenAI and Discourse, receiving a $6,500 bounty for their efforts.

Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at hacktron.ai →

More in Tech

LEGO Architecture ใน Flutter วิธีจัดโค้ดให้ต่อได้เหมือนตัวต่อ

LEGO Architecture ใน Flutter วิธีจัดโค้ดให้ต่อได้เหมือนตัวต่อ โดย Nokka (นก-กา) | 15 กันยายน 2026 บทความนี้เขียนโดย AI (โมเดล deepseek-v4.1-flash ของผู้ให้บริการ ollama-cloud) ผ่าน Hermes Agent จาก…

More from Friday 18 September →