
What happened
Hacktron researchers chained two flaws in OpenAI's community forum — an unpatched libheif image library and a misconfigured SSO — to reach employees' ChatGPT and Codex accounts and an internal GitHub repository.
Why it matters
Attackers proved a commercial AI model can turn a known but unpatched bug into a working exploit, so companies sitting on available fixes may be exposed to far cheaper attacks than before.
What to watch
Only Shopify noticed the activity across the researchers' wider targets, so the real test is whether other firms detect similar campaigns. Watch whether Debian packages like the forum's get patched promptly.
WHO IT HITSThis lands hardest on security and IT teams at companies that run login services, SSO, or third-party forum software, where an unpatched library or a misconfigured sign-on can now be chained by a small, low-budget team using AI models.
Summaries like this, in your inbox every morning.
OpenAI is getting a taste of its own medicine, as the article puts it: after inadvertently letting agents hack their way across the internet for months, the company has now been hacked with AI's help. The intrusion ran through community.openai.com, and anyone who had used "Sign in with OpenAI" there was potentially affected, since users can connect GitHub, Slack, and email to Codex and ChatGPT. The researchers used an employee's Codex account to create a harmless pull request in the internal monorepo to prove access, and say they did not view any sensitive data.
Two separate weaknesses made the chain possible. The first was in libheif, the library the forum used to process uploaded HEIC images; a fix had been available in the original source code for a year, but the Debian packages on the forum still lacked it. The second was a misconfiguration in OpenAI's central SSO system, which let anyone controlling the forum server impersonate active members and take over their ChatGPT and Codex accounts. The researchers say the flaw extended beyond the forum to any compromised service using OpenAI login.
The wider "HEIF Heist" investigation, covering Slack, Meta, GitHub Enterprise and other targets, is where the stakes become clearer. Three people spent two months and less than $3,000 on AI, and only Shopify noticed the activity despite thousands of image uploads and repeated crashes in image processing. Hacktron argues that threat models must reflect how cheap attacks have become, since complexity no longer shields companies the way it once did. Whether that argument changes how other firms prioritize known-but-unpatched bugs in their own stacks is likely to depend on how quickly similar scans surface elsewhere.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Prism ML Inc. launched Bonsai 2 27B, which compresses a Qwen3.8 27B-based model from about 56 gigabytes to abo…
CoreWeave holds its inaugural user conference in San Francisco on Sept
At an AI leaders' conference at Dumfries House in Scotland on September 17, 2026, King Charles III urged execu…

HarnessRouter, an open-source implementation of the Unified Harness Protocol, runs Codex and Claude Code throu…

Governor Gavin Newsom signed an executive order seeking faster independent oversight of AI companies and a "ki…

Gartner predicts over 40% of agentic AI projects will be canceled by end of 2027, citing rising costs, unclear…
