Urgent.News

What's breaking now, across thousands of outlets.

AI

Hacking OpenAI

On July 25, 2026, a group of hackers exploited two critical vulnerabilities to compromise multiple OpenAI employees’ ChatGPT accounts. This allowed them access to internal OpenAI repositories and potentially many other connected systems. To demonstrate their findings without causing damage, they created a harmless pull request in OpenAI's internal monorepo.

The vulnerabilities were discovered by HacktronAI team, led by Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini, who were researching security issues in frontier AI companies. They found an SSO misconfiguration in OpenAI's identity infrastructure and a libheif Remote Code Execution (RCE) in the community forum used by OpenAI. Despite upstream changes, the backported security fix was not documented, leading to the vulnerability remaining unpatched in some distributions. HacktronAI reported the issue to OpenAI and Discourse, receiving a $6,500 bounty for their efforts.

Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at hacktron.ai →

More in AI

More from Friday 18 September →