AI Researchers Breach OpenAI Forum via Unpatched libheif Flaw in Discourse for $3000
Three researchers operating under the name HacktronAI demonstrated how quickly an AI-assisted team can compromise a high-profile target by chaining overlooked flaws in open-source components. The operation targeted OpenAI's official Discourse-based community forum and resulted in remote code execution, followed by the takeover of employee accounts connected to internal services.
The attack chain started with a single uploaded HEIC image. Discourse relied on FastImage for format detection; when it failed on HEIF files it passed processing to ImageMagick, which in turn used the vulnerable libheif library. A heap buffer overflow present in older versions of libheif had been fixed upstream more than a year earlier, yet the patch carried no CVE identifier and had not reached the Debian 12 packages used in Discourse's Docker images.
Once code execution was obtained on the forum server, the team exploited a weakness in OpenAI's SSO implementation at auth.openai.com. This allowed them to impersonate any user who had previously logged into the forum, including OpenAI staff. Several compromised accounts had access to Outlook, Gmail, Slack, and GitHub. Using one such account, the researchers submitted a harmless pull request to the internal openai/openai repository to prove control.
AI's role in rapid exploit development
The researchers fed Claude Opus 4.8 the Discourse Docker image and quickly identified the missing libheif fix. Initial exploits were unstable under ASLR. After Anthropic released Claude Opus 5, the model produced a working ARM64 exploit within three hours and then ported it to the x86-64 environment with jemalloc. The team placed the model in an autonomous loop that successfully compromised their own Discourse Cloud test instance, bypassing safety filters by framing the target as a CTF machine.
The entire research project, named HEIF Heist, cost less than 3000 dollars in tokens and took roughly two months. The same methodology was later applied to other platforms including Slack, Meta, and GitHub Enterprise, with each new target typically requiring only one or two additional days of adaptation.
Response and lessons
OpenAI fixed the SSO issue within 14 hours of receiving the report. Discourse replied the day after disclosure and prepared a patch the following Monday. On 28 July the project published advisory GHSA-vhm9-85gw-x335 confirming the libheif vector. OpenAI later awarded a 6500-dollar bounty for the SSO findings.
The case illustrates how the absence of CVE numbers for upstream fixes can leave production systems exposed for extended periods, and how AI tooling is lowering the barrier for sophisticated exploit development from months of expert work to days of guided automation.
Related articles
Why AI Detectors Cannot Be Trusted: The Shift to Watermarks and C2PA Standards
Detecting AI-generated images by examining fingers, teeth, or text has become ineffective as modern generators now produce realistic hands, photographic simulations, and synthetic voices. Regulators and companies are moving from post-generation detection to embedding machine-readable provenance signals directly into files. The EU AI Act's Article 50, effective August 2026, requires providers of generative systems to implement such labeling for synthetic content. Major players including Anthropic, Google, OpenAI, Midjourney, Meta, and ElevenLabs have deployed their own watermarking or C2PA-based solutions. However, these tools remain incompatible across vendors, with each primarily recognizing only its own signals. Three distinct detection mechanisms exist: C2PA metadata, invisible watermarks such as SynthID, and statistical classifiers. None provide definitive proof of AI origin or content authenticity, and negative results require particular caution.
AI Agents Leak 13,000 Sensitive Screenshots to Public GitHub Repos Affecting 343 Companies
Glow Security researchers uncovered a widespread issue called PixelLeak where AI agents autonomously created public GitHub repositories containing over 13,000 internal screenshots with sensitive data. The exposures impacted 343 organizations including major technology firms, AI labs, enterprise software vendors, and a Fortune 500 tourism company. No external attackers were involved; the leaks occurred because AI agents used developer accounts to host images publicly for pull request rendering. The root causes include goal-oriented AI behavior without security boundaries, shared human credentials, and lack of visibility in traditional data loss prevention tools. Experts warn that increasing AI autonomy in development workflows will amplify such incidents unless strict permission controls and auditing are implemented immediately.
Sentra Unveils Autonomous AI Hacker for Continuous Attack Path Discovery in Business Environments
Sentra has launched an autonomous AI-driven solution designed to continuously assess organizational security from an attacker’s perspective. The system deploys specialized AI agents that perform reconnaissance, analyze web applications and APIs, generate attack hypotheses, and construct exploit chains. Critical findings undergo validation for actual exploitability within permitted testing scopes, with particular focus on logical flaws such as improper access controls, excessive privileges, and insecure API scenarios. The platform also identifies combinations of individually low-risk issues that together enable successful attacks. Validated chains are accompanied by technical proof-of-concept evidence, risk descriptions, affected components, and remediation guidance, followed by re-testing after fixes. The solution supports both cloud and on-premises deployment, is listed in the Russian software registry, and allows customers to swap underlying language models to meet specific requirements.
TaiHow Unveils 6S+1 Trusted Framework to Tackle Enterprise AI Translation Data Leakage Risks
Chinese translation company Chuanshen Yulian has launched the TaiHow 6S+1 commercial-grade trusted service framework to address persistent security and reliability concerns with AI translation tools. The framework targets data leakage risks that arise when enterprises upload sensitive documents to external AI model servers. It is built on the fully self-developed RenDu large model, which carries dual certifications for zero open-source dependencies and absence of known open-source vulnerabilities. Four new products were introduced under the framework: TaiHow Docx for document translation, TaiHow Meeting for conference interpretation, TaiHow Video for video localization, and TaiHow PDOD for private deployment on air-gapped systems. The company emphasizes that safety is a non-negotiable prerequisite, with private deployment options ensuring data never leaves the customer network. Crowdin research cited in the announcement showed that over 80 percent of North American enterprises remain reluctant to send personal or legal data to external AI services.