AINewsnow

How Researchers Used Claude to Breach OpenAI : The libheif HEIC Supply-Chain Story

This story is from 2026-09-22. It is preserved in the archive; the latest stories are on the live feed.

In July 2026, a three-person team at Hacktron AI chained a memory-corruption bug in libheif (yes, the HEIC/HEIF image decoder) with an SSO misconfiguration to take over OpenAI employee ChatGPT/Codex accounts — and prove access to an internal GitHub monorepo. The most interesting part isn't the bug.…

Read the full story at DEV Community — AI ↗

Timeline · 1 report

  1. 2026-09-22 10:39 · DEV Community — AI
    How Researchers Used Claude to Breach OpenAI : The libheif HEIC Supply-Chain Story

More stories

  1. Amazon blocks Meta’s Muse AI agent — The Verge AI
  2. What's your proudest side-project made with Claude? — r/ClaudeAI
  3. I built an iOS app with Claude code to break out of my usual chord habits and unlock new progressions. — r/ClaudeAI
  4. Jev to autoselect Claude model - co-creator of chatgpt's project — r/ClaudeAI
  5. GitHub - transilienceai/denali: Evidence-led, provider-neutral AI security platform — r/ArtificialInteligence
  6. Small, simple, slow LLM to write some bash. — r/LocalLLM
  7. What is a good Start ? — r/ClaudeAI
  8. Independent review in agentic workflows — r/AI_Agents

Get the daily brief of stories like this at 6:30 every morning →