Thursday, 24 Sep 2026
Subscribe to AIWatcher
AIWatcher
  • Home
  • News

    OpenAI slots two cheaper GPT-6 models beneath Astra

    By
    AIWadmin

    Researcher hijacks Meta’s Muse agent through a hidden setting

    By
    AIWadmin

    ChatGPT learns to take voice orders for office chores

    By
    AIWadmin

    YouTube hands creators an AI agent for titles and thumbnails

    By
    AIWadmin

    Listeners can now rewrite the Spotify algorithm in plain words

    By
    AIWadmin

    Anthropic’s Claude agents flag a new enzyme family in viral DNA

    By
    AIWadmin
  • Articles

    Data shop Snorkel AI banks $350M as labs stockpile training sets

    By
    AIWadmin

    Ema banks $77M to push AI employees into the back office

    By
    AIWadmin

    US military command randomises routes to outfox enemy models

    By
    AIWadmin

    Kyutai teaches a speech model to do arithmetic out loud

    By
    AIWadmin

    Nokia hands developers a no-training route to calibrated answers

    By
    AIWadmin

    An open model sorts eight overlapping speakers in real time

    By
    AIWadmin
  • Spotlight

    DeepMind keeps cloud memory encrypted behind device-held keys

    By
    AIWadmin

    Anthropic trims Opus costs and speeds output in a mid-cycle refresh

    By
    AIWadmin

    Cisco Talos builds a fingerprint library for AI-driven malware

    By
    AIWadmin

    Google parks idle agents in a new open source runtime

    By
    AIWadmin

    OpenAI gives mathematicians a voice but hands them no brake

    By
    AIWadmin

    NVIDIA teaches its robotics stack to take instructions from agents

    By
    AIWadmin
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
      • Hats
      • T-Shirts
    • Cart
  • 🔥
  • Alignment
  • Classification
  • Distillation
  • Explainability
  • Hallucination
  • Legal/Compliance
  • Medical
  • NLM
  • Mobility
  • Research
  • Robotics
  • Safety
  • Startups
  • Prompt
  • Python
  • RAG
  • RLHF
  • Token
  • Vision
Font ResizerAa
AIWatcherAIWatcher
  • Home
  • News
  • Articles
  • Spotlight
  • About
  • Newsletter
  • Shop
Search
  • Home
  • News
  • Articles
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
    • Cart
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
News

Bug bounty team chains two flaws to crack OpenAI accounts

A three-person security team used Claude to reach OpenAI employee ChatGPT accounts and earned $6,500 for the find.

AIWadmin
Last updated: September 19, 2026 1:35 am
AIWadmin
ByAIWadmin
Global AI news & information.
Follow:
Share
SHARE

A crafted iPhone photo was the way in. OpenAI’s community forum runs on Discourse, which resizes uploaded images with ImageMagick and hands Apple’s HEIF format to a library called libheif to decode.

The bug lived inside libheif. A specially built image could make the library miscalculate where one image sat relative to another, and that miscalculation was enough to seize the server.

Hacktron AI, a three-person security startup, found that path on July 25. The team linked it to a second flaw and eventually arrived at multiple employee ChatGPT accounts, then at the company’s internal software. OpenAI paid $6,500 through its bug bounty program and says both flaws are closed.

Anthropic’s Claude did part of the work. The team’s earliest attempts leaned on a version of Opus 4.8 handed to cybersecurity researchers, and it could not produce a working exploit. Opus 5 shipped, and by the next morning it could.

What will bother defenders is the timeline behind the libheif bug. Developers had patched it months before the researchers arrived, but the fix never carried a vulnerability label, so no CVE number followed. Nothing told Discourse to update.

Gray Swan chief executive Matt Fredrikson told TechCrunch that the barrier to entry is now a $200 monthly subscription, and that if the approach works against OpenAI it will work against anyone.

TAGGED:AI securityAnthropicbug bountyClaudeOpenAIvulnerability research
SOURCES:TechCrunch
Share This Article
Email Copy Link Print
ByAIWadmin
Follow:
Global AI news & information.
Previous Article Manus hunts a $4B valuation as it rebuilds without Meta
Next Article WSO2 ships a control plane for agents across model stacks

You Might Also Like

News

White House accuses Moonshot AI of stealing Anthropic tech for Kimi K3

By
AIWadmin
News

Anthropic eases Fable 5’s biology blocks after researcher backlash

By
AIWadmin
News

Claude Code bills for blank thinking blocks users never see

By
AIWadmin
News

Virginia ties data center growth to a new AI task force

By
AIWadmin
AIWatcher
Facebook Twitter Youtube Linkedin Rss

Global AI News and Information
AIWatcher is your definitive source for AI updates worldwide, from Silicon Valley to Shanghai.
Our industry coverage keeps you in the loop with the latest news and trends shaping the future of AI.

Quick Links
  • News
  • Articles
  • Spotlight
  • Events
About Us
  • Mission
  • Services
  • Contact
  • Privacy Policy
  • Legal
© 2026 AIWatcher. All Rights Reserved.