Three cybersecurity researchers used Claude to breach OpenAI Group PBC’s GitHub repository.
Cybersecurity researchers gain access to OpenAI’s GitHub repository using Claude
Three cybersecurity researchers used Claude to breach OpenAI Group PBC’s GitHub repository.
SiliconANGLE
Publisher
Sep 18, 2026 at 10:25 PM UTC · 3 Min. Lesezeit

Key Signal
June 24 Access ended after disclosure
Last Updated
vor einem Tag
Sources told the Wall Street Journal today that the repository contains “OpenAI’s algorithmic secrets.” The files were accessible until June 24, the day the researchers reported their findings to the company. OpenAI released a patch within 14 hours of receiving the tip.
The exploit’s discoverers work at a venture-backed cybersecurity startup called Hacktron AI Inc. The company detailed in a blog post that the issue stemmed from two vulnerabilities in OpenAI’s infrastructure. One affected the company’s user forum while the other was found in the single single-on, or SSO, system that manages employee accounts.
OpenAI’s forum is powered by an open-source discussion board platform called Discourse. Discourse allows users to upload images as part of their posts. Under the hood, the software processes images with the help of an open-source tool called libheif. That tool contained the first vulnerability spotted by Hacktron’s researchers.
The vulnerability enables hackers to compromise certain versions of libheif by uploading a malicious image. The malware-laden file causes a bug known as buffer overflow, which makes it possible to edit program data that is normally inaccessible. Hackers can replace the program data with malicious code.
Article Intelligence
Topics
Regulation Signal
in progressUpdated vor einem Monat
SEC Crypto Asset Market Structure RulemakingRelated Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
