MonitoringAI & TechSecurity incidentFirst tracked 2026-09-18Last changed 2026-09-19
Current outcome
Security researchers at Hacktron used Anthropic's Claude to chain an image-processing vulnerability with an OpenAI identity flaw, breaching employee ChatGPT and Codex accounts and reaching an internal OpenAI code repository within 72 hours.
Progress timeline
1 material updates- #01
A heap overflow and SSO misconfiguration to compromise OpenAI internal repos
Researchers chained a libheif heap overflow with an SSO misconfiguration to gain remote code execution and access OpenAI's internal repositories within 72 hours.
Source evidence: Handy-Man · CryptoSlate