Hacktron details attack chain that compromised OpenAI employee accounts
Security researchers at Hacktron described a chain of vulnerabilities that compromised OpenAI employee accounts and reached internal GitHub repositories. The attack began with HEIF/HEIC image processing via ImageMagick and libheif, then moved through Discourse and OpenAI's SSO; Claude models assisted parts of the research.
- Attack started with a HEIF/HEIC decoding flaw in libheif and ImageMagick
- Chain moved through Discourse, OpenAI SSO and ChatGPT/Codex accounts
- Final target was connected GitHub integrations and internal repositories
- Anthropic's Claude models were used during the research
Read next
Security