cd /news/ai-safety/cybersecurity-researchers-gain-acces… · home topics ai-safety article
[ARTICLE · art-134210] src=siliconangle.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Cybersecurity researchers gain access to OpenAI’s GitHub repository using Claude

Three cybersecurity researchers at Hacktron AI Inc. used Anthropic's Claude Opus 5 to breach OpenAI Group PBC's GitHub repository, gaining access to files the Wall Street Journal described as containing "OpenAI's algorithmic secrets" until June 24, when the researchers reported the findings and OpenAI patched the issue within 14 hours. The exploit chained a buffer-overflow vulnerability in the open-source image tool libheif, which Discourse had not patched, with a configuration flaw in OpenAI's single sign-on system, after Claude Opus 4.8 built the initial proof-of-concept on June 23 and Claude Opus 5 bypassed OpenAI's ASLR safeguard the next day. Hacktron named the bug series HEIF Heist and said it also affects Slack, Meta Platforms Inc. and other major tech firms, partly because libheif's developers never filed a CVE entry for it.

by read3 min views1 publishedSep 18, 2026
Cybersecurity researchers gain access to OpenAI’s GitHub repository using Claude
Image: Siliconangle (auto-discovered)

Cybersecurity researchers gain access to OpenAI’s GitHub repository using Claude

Three cybersecurity researchers used Claude to breach OpenAI Group PBC’s GitHub repository.

Sources told the Wall Street Journal today that the repository contains “OpenAI’s algorithmic secrets.” The files were accessible until June 24, the day the researchers reported their findings to the company. OpenAI released a patch within 14 hours of receiving the tip.

The exploit’s discoverers work at a venture-backed cybersecurity startup called Hacktron AI Inc. The company detailed in a blog post that the issue stemmed from two vulnerabilities in OpenAI’s infrastructure. One affected the company’s user forum while the other was found in the single single-on, or SSO, system that manages employee accounts.

OpenAI’s forum is powered by an open-source discussion board platform called Discourse. Discourse allows users to upload images as part of their posts. Under the hood, the software processes images with the help of an open-source tool called libheif. That tool contained the first vulnerability spotted by Hacktron’s researchers.

The vulnerability enables hackers to compromise certain versions of libheif by up a malicious image. The malware-laden file causes a bug known as buffer overflow, which makes it possible to edit program data that is normally inaccessible. Hackers can replace the program data with malicious code.

The developers of libheif patched the issue about a year before Hacktron’s researchers made their discovery. However, Discourse didn’t implement the patch, which left OpenAI’s forum vulnerable.

Hacktron’s researchers developed the initial version of the exploit on June 23 using Claude Opus 4.8. The proof-of-concept worked well in their internal Discourse instance, but didn’t carry over to OpenAI’s forum because it uses a safeguard called ASLR. The technology protects sensitive program data from buffer overflows by spreading it over randomized memory locations.

The researchers’ breakthrough came the following day, when Anthropic released Claude Opus 5. The model quickly found a way around OpenAI’s ASLR implementation. After the researchers gained access to the company’s forum, they found a configuration issue in the SSO system that powers OpenAI employees’ forum accounts. The same SSO system manages staffers’ access to sensitive internal systems.

Hacktron’s researchers notified the company about the issue about three hours after they compromised its forum. From there, they took over an OpenAI employee’s account to map out the scope of the issue. That account gave them access to the company’s internal GitHub environment.

The libheif vulnerability that exposed OpenAI’s code is one of several exploits in the image processing tool. Hacktron has named the bug series HEIF Heist. The company discovered it in the infrastructure of not only OpenAI but also Slack, Meta Platforms Inc. and other major tech firms.

It’s believed HEIF Heist is so widespread because libheif’s developers didn’t create an entry for the bug series in the CVE vulnerability database. That made it more difficult for developers to detect and patch vulnerable systems. Hacktron is advising affected users to download the latest versions of libheif and harden or disable their image processing pipelines.

Photo: Unsplash

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos , powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network

Are you an AWS customer?  Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/

About SiliconANGLE Media

SiliconANGLE,

theCUBE Network,

theCUBE Research,

CUBE365,

theCUBE AIand theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

── more in #ai-safety 4 stories · sorted by recency
── more on @openai group pbc 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/cybersecurity-resear…] indexed:0 read:3min 2026-09-18 ·