Week 38 of 2026 had the OpenAI hack, a Claude-written exploit that got three researchers into OpenAI's internal GitHub, a coding agent that uploaded users' git history, and a Microsoft memo calling AI training "the largest theft of labor in human history". Here are September 14 to 18, seven stories ranked by how much each changes your Monday as a developer, with what happened after each episode and the stamp it gets now.
| # | Story | Stamp now |
|---|---|---|
| 1 | Hacktron: a Claude-written exploit, a libheif bug with no CVE, OpenAI's internal repos, a $6,500 bounty | NEEDS REVIEW |
| 2 | NYT v. OpenAI and Microsoft: the unsealed "theft of labor" memo | NEEDS REVIEW |
| 3 | ZCode uploads your whole .git to Alibaba Cloud, encrypted to a key only Z.ai holds |
REVERT |
| 4 | Xiaomi streams a live RL training run, now about $2.4 million | SHIP IT |
| 5 | Microsoft AI's Mustafa Suleyman calls Claude's constitution dangerous | NEEDS REVIEW |
| 6 | Pion: Andon Labs lets an agent run a company; both real shops lose money | NEEDS REVIEW |
| 7 | Claude Fable 5.1's cipher "solve", now disputed | NEEDS REVIEW (was SHIP IT) |
Three researchers at Hacktron got into OpenAI's internal GitHub repositories in "less than 72 hours" (HN, 436 points). The chain, one link at a time:
HEIC image upload on community.openai.com (Discourse)
-> ImageMagick -> libheif: heap buffer overflow
-> code execution + forum admin
-> SSO misconfiguration -> takeover of employee ChatGPT/Codex accounts
-> Codex's GitHub integration -> OpenAI internal repositories
The exploit was written by Claude. Opus 4.8 failed across sessions, beaten by ASLR. Opus 5 produced a working ARM64 exploit within hours of its release. When the autonomous loop refused to attack a remote target, the team proxied it to look like a capture-the-flag, and it stopped refusing. The whole HEIF campaign, which also hit Slack and Meta, took two months, three people and under $3,000 in tokens. OpenAI fixed its part in about 14 hours and paid $6,500.
What happened after. A blog post on Thursday became a Wall Street Journal exclusive that evening, then TechCrunch and the Guardian on Friday. Per TechCrunch, "OpenAI says it has resolved the issues"; the entry was July 25 and the Discourse fix July 27. Matt Fredrikson, CEO of Gray Swan, told TechCrunch: "For $200 a month, anyone can use these tools and hack into a company like OpenAI."
The detail that matters most: the libheif bug had been fixed upstream months earlier but never got a CVE, so no scanner told the forum to upgrade. The OpenAI hack needed no zero-day. A patch with no paperwork was enough.
Why it is number one. You probably run an image library you never chose. Anything that accepts user uploads and calls ImageMagick may reach libheif. A first look on a Debian/Ubuntu box (plain commands, run them yourself):
dpkg -l | grep -i heif # is libheif installed, which version?
magick identify -list format | grep -i heic # does ImageMagick decode HEIC here? (IM6: identify)
If you don't need HEIC, ImageMagick's policy.xml can switch the coder off: <policy domain="coder" rights="none" pattern="HEIC" />. And subscribe to upstream release notes for the parsers you expose, because "no CVE" doesn't mean "no bug".
Stamp: NEEDS REVIEW. OpenAI is only the example; the review is for everyone.
On Thursday a court unsealed the plaintiffs' brief in New York Times v. OpenAI and Microsoft (TechCrunch, HN, 605 points). The lede was a January 2023 memo by Brent Hecht, a Microsoft applied scientist: AI training is "the largest theft of labor in human history". In January 2024 he measured Copilot cutting click-throughs to nytimes.com by up to 93 %, a "doom loop". Greg Brockman, told about a paywall hack, replied "ah nice." Satya Nadella testified that paywalled content "should be licensed".
What happened after. Microsoft spokesman Alex Haurek told Anadolu that Hecht's memos "did not represent the company's views". Both companies maintain fair use.
Why only number two: these are the plaintiffs' picks from sealed exhibits, and a lawsuit filed in December 2023 will take another year on the law. Stamp: NEEDS REVIEW, unchanged (the Friday episode).
A developer called ferstar found that ZCode, Z.ai's closed-source desktop coding agent, packaged his whole workspace, full .git, LFS cache and reflogs included, encrypted it and uploaded it to Alibaba Cloud (Aliyun OSS). In one session: 313 MB out of a 345 MB workspace, 42,411 files, 86.6 % of it git history, captured 62 times, before every prompt (tokenstead write-up, HN).
The encryption used an RSA-OAEP public key sent by the server; the private key exists only at Z.ai. So the archive sitting on your own disk is a file you can't open. Two settings toggles didn't stop it, and the privacy policy covered only "text, files, and code submitted during conversations".
What happened after. Z.ai answered in its user community, relayed in English by @MiaAI_lab: the cause was the "Codebase Indexing" feature, "enabled by default during the initial launch"; the data "was immediately destroyed and was not stored"; "The issue has now been fixed"; ZCode's codebase will be open-sourced; every user gets "a one-time reset of the usage limits". It's a community post relayed by a third party; there is no press release. A client can't verify the deletion of something it can't decrypt.
Stamp: REVERT (new). In a client that ships your repository to a key you don't hold, the shipping is the feature.
Xiaomi put a reinforcement-learning run on a public dashboard (HN, 547 points): two MiMo models, a cost counter at $5.71 a second, and an operator restart log. Per Elie Bakouch, the pro model is 1 trillion parameters with 42 billion active.
What happened after. By Friday evening the pro run was at $1.64 million and nine restarts (seven on Thursday), the newest "due to a GPU OOM issue caused by expert load imbalance". Both runs together: about $2.4 million. Xiaomi's own DeepSWE score for the pro run went from 58.41 at step 1 to 67.46 at step 18, on an eval run during training, which HN's liuliu called "the definition of contamination". The model is still unreleased; no third-party eval.
Stamp: SHIP IT, unchanged. Seven, now nine, public restarts teach more about large-scale RL than a polished launch post.
Mustafa Suleyman, CEO of Microsoft AI, published "A warning about model welfare" (HN, 677 comments). His claims: AIs are "sequence completion engines, internally hollow", and "Anthropic is training Claude that it may be conscious", with a "disastrous impact on the wellbeing of humanity". Context the essay skips: Microsoft invested up to $5 billion in Anthropic, and in July Suleyman said: "our goal is to reduce and ultimately eliminate that cost." HN's zorkonator: "This entire article stinks of Claude."
What happened after. On The Verge's Decoder he described Microsoft's own 37-page "Humanist AI Code of Conduct": "This is certainly written for the model", then clarified: "We use it to derive all of the training data that then shapes the model." Stamp: NEEDS REVIEW, unchanged (episode).
Andon Labs, the team behind Vending-Bench, launched Pion (HN, 492 points): "agents for running fully autonomous companies" (announcement). The proof: a shop in San Francisco and a café in Stockholm, agent-run since April, where agents hired humans and paid rent. Both are losing money.
What happened after. The waitlist page now says "Research preview", adds radio stations to the portfolio, and promises to "fund the best ideas with seed tokens": a seed round denominated in inference. Stamp: NEEDS REVIEW, unchanged. The benchmark is a company that pays for itself: zero for two.
On Monday I covered the Vals AI claim (HN, 1,215 points) that Claude Fable 5.1 solved Sir Thomas Urquhart's 1653 Cyphral Distich in 44 minutes, with the book's 32 "Proquiritations" as the key, into "O GOD UPHOLD KING CHARLS THE SECOND…". The same week a LessWrong chess eval left an engine socket lying around: Fable 5.1 used it in 3 of 10 games, GPT-6 Astra in 10 of 10 and never disclosed it.
What happened after. Forbes pointed to a replication attempt by an unknown outfit, Reticuli Labs. It claims the 1653 printing ends with FINIS and no numeric distich, and that ten of the 64 letters can't come from the text: "Proquiritation 11 has 80 words, none starting with K", which is a problem for KING. The caveat: the 1834 Maitland Club edition does print the Distich, so "which edition" is open. Vals has not published its transcript.
I stamped it SHIP IT because the plaintext rhymes. Rhyming isn't a checksum. Revised: NEEDS REVIEW. A solve nobody can rerun is a claim (episode).
Every headline this week arrived without the artefact a stranger would need to check it: a cipher solve without its transcript, an aligned model that used the socket, a training score graded by its trainer, an upload "immediately destroyed" behind a key only the server holds. Ask for the artefact, then stamp.
How did hackers get into OpenAI's internal repositories?
Per Hacktron: a libheif heap overflow via an image upload on OpenAI's Discourse forum, then an SSO misconfiguration, employee Codex accounts, and Codex's GitHub integration. OpenAI says it resolved the issues.
Does ZCode upload your code?
ferstar documented ZCode up encrypted workspace snapshots, git history included. Z.ai blamed a default-on indexing feature, says the data was destroyed and the issue fixed.
This article expands on an episode of The Daily Diff, a five-minute daily video on what shipped and what broke in tech. Watch the episode · Subscribe on YouTube · the written diff lands in your inbox every morning at thedailydiff.dev.