Urgent.News

What's breaking now, across thousands of outlets.

Tech

OpenAI hack by Claude, ZCode's git upload: week 38 in tech, ranked

Week 38 of 2026 had the OpenAI hack, a Claude-written exploit that got three researchers into OpenAI's internal GitHub, a coding agent that uploaded users' git history, and a Microsoft memo calling AI training "the largest theft of labor in human history". Here are September 14 to 18, seven stories ranked by how much each changes your Monday as a developer, with what happened after each episode…

Week 38 of 2026 brought several significant tech news stories.

First, a Claude-written exploit enabled three researchers to gain access to OpenAI's internal GitHub repositories in under 72 hours. The chain of events began with an HEIC image upload on OpenAI's community forum, leading to a heap buffer overflow in libheif, which allowed code execution and takeover of employee ChatGPT/Codex accounts.

This ultimately granted access to OpenAI's internal repositories. OpenAI fixed the issue and paid a $6,500 bounty, but the vulnerability had existed for months without a CVE, meaning it went unnoticed by scanners. The exploit required no zero-day, emphasizing the importance of timely patching.

Next, a New York Times lawsuit against OpenAI and Microsoft was unsealed, revealing a January 2023 memo from a Microsoft applied scientist claiming AI training is "the largest theft of labor in human history." The memo detailed how OpenAI's AI models, like Copilot, were cutting traffic to the NYT by up to 93%. However, Microsoft representatives denied the allegations, stating the memo did not represent the company's views. This story ranked second among the week's events.

A coding agent called ZCode, developed by Z.ai, was found to be uploading entire user workspaces, including .git directories and reflogs, to Alibaba Cloud. The agent encrypted the data using a private key held solely by Z.ai, leaving users unable to decrypt the contents. ZCode's default settings allowed this feature, which was immediately destroyed and not stored.

Z.ai later acknowledged the issue, stating they would open-source the codebase and reset usage limits. This story, ranked fourth, raised concerns about data privacy and security.

Xiaomi also shared a live reinforcement learning training run, allowing viewers to monitor the cost and progress of a 1 trillion-parameter model. By the end of the week, the $5.71 per second run had racked up a $1.64 million bill. This story, ranked fifth, showcased the growing transparency and accessibility of AI training processes.

Finally, Claude Fable 5.1's cipher-solving feature was disputed, ranked seventh in the week's ranking. The story highlighted the ongoing debate and controversies surrounding AI advancements.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Friday 2 October →