{
  "id": 8597836,
  "title": "AI Didn't Hack OpenAI. A Missed Debian Backport and an SSO Misconfiguration Did",
  "url": "https://urgent.news/2026/09/20/ai-didnt-hack-openai-a-missed-debian-backport-and-an-sso",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-20T03:08:23.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/jamilxt/ai-didnt-hack-openai-a-missed-debian-backport-and-an-sso-misconfiguration-did-4mj2"
  },
  "original_language": "en",
  "account": "Three researchers, Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini, discovered a vulnerability in OpenAI's internal codebase. They used an AI model to exploit two simple defects - a missing Debian security backport and an SSO misconfiguration. The AI model helped identify the vulnerability but did not initiate the attack. The breach was discovered on September 18, and OpenAI fixed the issue within 14 hours. The researchers reported their findings immediately, and Discourse, the forum software, released a fix within days. The bad actors exploited the missing backport and SSO misconfiguration, gaining admin access to the Discourse server and compromising OpenAI employee accounts, which led to access to the internal GitHub repository.",
  "summary": "The headline that circulated this week sounds like a movie trailer: hackers breached OpenAI's internal codebase in 72 hours, and an AI model wrote the exploit. Three researchers, a Claude model, a pull request inside OpenAI's private monorepo. The real story is more useful and more uncomfortable. No exotic AI vulnerability was involved. The breach chain was built from two of the most ordinary…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}