Week 38 digest: OpenAI hacked via Claude, ZCode leaked .git history
Hacktron researchers used a Claude-written exploit to breach OpenAI's internal GitHub repos in under 72 hours via a libheif bug with no CVE, earning a $6,500 bounty. Separately, Z.ai's ZCode uploaded users' full .git history to Alibaba Cloud, encrypted with a key only Z.ai holds.
- Claude-written exploit reached OpenAI's internal repos in under 72 hours
- The libheif bug was patched upstream but never got a CVE, so scanners stayed silent
- ZCode uploaded 313 MB of a 345 MB workspace, 86.6% git history, 62 times per session
- Z.ai said the data was destroyed and promised to open-source ZCode
Read next
Security