Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    Poitras Center to fuel early careers of 50 young scientists dedicated to psychiatric disorders research | MIT News

    September 22, 2026

    Who owns the customer relationship when an agent does the buying? – GeekWire

    September 22, 2026

    European neocloud Verda raises $189M to build the AI infrastructure of tomorrow

    September 22, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Innovation»Cybersecurity researchers gain access to OpenAI’s GitHub repository using Claude
    Innovation

    Cybersecurity researchers gain access to OpenAI’s GitHub repository using Claude

    InfoForTechBy InfoForTechSeptember 18, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Cybersecurity researchers gain access to OpenAI’s GitHub repository using Claude
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email



    Three cybersecurity researchers used Claude to breach OpenAI Group PBC’s GitHub repository.

    Sources told the Wall Street Journal today that the repository contains “OpenAI’s algorithmic secrets.” The files were accessible until June 24, the day the researchers reported their findings to the company. OpenAI released a patch within 14 hours of receiving the tip.

    The exploit’s discoverers work at a venture-backed cybersecurity startup called Hacktron AI Inc. The company detailed in a blog post that the issue stemmed from two vulnerabilities in OpenAI’s infrastructure. One affected the company’s user forum while the other was found in the single single-on, or SSO, system that manages employee accounts.

    OpenAI’s forum is powered by an open-source discussion board platform called Discourse. Discourse allows users to upload images as part of their posts. Under the hood, the software processes images with the help of an open-source tool called libheif. That tool contained the first vulnerability spotted by Hacktron’s researchers.

    The vulnerability enables hackers to compromise certain versions of libheif by uploading a malicious image. The malware-laden file causes a bug known as buffer overflow, which makes it possible to edit program data that is normally inaccessible. Hackers can replace the program data with malicious code.

    The developers of libheif patched the issue about a year before Hacktron’s researchers made their discovery. However, Discourse didn’t implement the patch, which left OpenAI’s forum vulnerable.

    Hacktron’s researchers developed the initial version of the exploit on June 23 using Claude Opus 4.8. The proof-of-concept worked well in their internal Discourse instance, but didn’t carry over to OpenAI’s forum because it uses a safeguard called ASLR. The technology protects sensitive program data from buffer overflows by spreading it over randomized memory locations.

    The researchers’ breakthrough came the following day, when Anthropic released Claude Opus 5. The model quickly found a way around OpenAI’s ASLR implementation. After the researchers gained access to the company’s forum, they found a configuration issue in the SSO system that powers OpenAI employees’ forum accounts. The same SSO system manages staffers’ access to sensitive internal systems.

    Hacktron’s researchers notified the company about the issue about three hours after they compromised its forum. From there, they took over an OpenAI employee’s account to map out the scope of the issue. That account gave them access to the company’s internal GitHub environment.

    The libheif vulnerability that exposed OpenAI’s code is one of several exploits in the image processing tool. Hacktron has named the bug series HEIF Heist. The company discovered it in the infrastructure of not only OpenAI but also Salesforce Inc.’s Slack, Meta Platforms Inc. and other major tech firms.

    It’s believed HEIF Heist is so widespread because libheif’s developers didn’t create an entry for the bug series in the CVE vulnerability database. That made it more difficult for developers to detect and patch vulnerable systems. Hacktron is advising affected users to download the latest versions of libheif and harden or disable their image processing pipelines.

    Photo: Unsplash

    Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

    • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
    • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network
    SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

    Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    European neocloud Verda raises $189M to build the AI infrastructure of tomorrow

    September 22, 2026

    5 Content Syndication Networks That Capture Mindshare And Conversion

    September 22, 2026

    T-Mobile Promo Codes: 25% Off | September 2026

    September 22, 2026

    SpaceX launches Grok 4.7 with long-horizon processing, safety upgrades

    September 22, 2026

    10 Demand Generation Tools That Can Keep Your Brand In The Conversation

    September 21, 2026

    Here’s the iFixit Repairability Rating for the iPhone 18 Pro

    September 21, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026375 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202641 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202634 Views

    How is Luckin Coffee expanding rapidly in S’pore while keeping its coffee so cheap?

    April 23, 202622 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026375 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202641 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202634 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.