AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum
ID: f32abd71-4997-5a8a-ad9a-133148f69b35
STIX ID: report--f32abd71-4997-5a8a-ad9a-133148f69b35
Feed Name: Security Affairs
Researchers in the HEIF Heist project used AI-assisted exploit development to turn a libheif heap buffer overflow in Discourse image processing into a working exploit that allowed takeover of OpenAI staff ChatGPT/Codex accounts via shared OpenAI SSO; they demonstrated root-level access on a server, opened a harmless pull request to prove access, reported the issue, and vendors patched the problem — the article highlights risks of shared SSO and how AI dramatically lowers the time and cost to weaponize memory-corruption bugs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
