{
  "id": 8163885,
  "title": "Hacking OpenAI",
  "url": "https://urgent.news/2026/09/18/hacking-openai",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-18T02:47:24.000Z",
  "source": {
    "name": "Hacker News",
    "slug": "hacker-news",
    "url": "https://www.hacktron.ai/blog/hacking-openai"
  },
  "original_language": "en",
  "account": "On July 25, 2026, a group of hackers exploited two critical vulnerabilities to compromise multiple OpenAI employees’ ChatGPT accounts. This allowed them access to internal OpenAI repositories and potentially many other connected systems. To demonstrate their findings without causing damage, they created a harmless pull request in OpenAI's internal monorepo. The vulnerabilities were discovered by HacktronAI team, led by Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini, who were researching security issues in frontier AI companies. They found an SSO misconfiguration in OpenAI's identity infrastructure and a libheif Remote Code Execution (RCE) in the community forum used by OpenAI. Despite upstream changes, the backported security fix was not documented, leading to the vulnerability remaining unpatched in some distributions. HacktronAI reported the issue to OpenAI and Discourse, receiving a $6,500 bounty for their efforts.",
  "summary": null,
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}