Hacktron used zero-day to reach OpenAI's GitHub, sparking disclosure debate
Security researchers at Hacktron exploited a zero-day in OpenAI's forum software to gain access to the company's GitHub account, opened a benign pull request and reported the findings. OpenAI CISO Dane Stuckey initially reacted coldly before apologizing, as the security community debated whether lateral movement during testing is acceptable.
- Hacktron exploited a zero-day in OpenAI's forum software to reach GitHub
- Researchers opened a benign pull request and downloaded no data
- OpenAI CISO Dane Stuckey initially criticized the actions, then apologized
- OpenAI moved 25% of its engineers to security work after summer incidents
Read next
Security