Find notable cyber news and cases, enriched with sources, timelines, and signals.

OpenAI hit by account takeover attack

Incident
First reported
Last updated
Happening score
H score 18
1 unique sources, 1 articles

Summary

Hide ▲

OpenAI suffered an employee account takeover that led to internal repository access and limited reads of private-repository metadata and commits. The access path ran through an OpenAI employee’s account linked by Codex integration to OpenAI’s GitHub organization. The incident mattered because the intruder was able to open a pull request inside an internal repository before testing stopped.

Related Happenings

OpenAI Codex sandbox escape fixes in Desktop and CLI

Security Tool/Service
H score11 First: 20.09.2026 15:00 Last: 20.09.2026 15:00 Sources 1

About this happening: OpenAI fixed Heapjack in Codex Desktop and Overpatch in Codex CLI, closing sandbox escapes that could let untrusted agent activity reach a developer's host. The fl...

Claude Opus 5 Helped Hacktron Chain Discourse libheif RCE into OpenAI Staff Account Access remote code execution flaw (CVE-2026-32882)

Vulnerability
H score39 First: 18.09.2026 15:45 Last: 18.09.2026 15:45 Sources 1

How related: Discourse’s built-in image checks didn’t support the HEIC/HEIF photo format, so uploads in that format were passed to ImageMagick, exposing an unpatched flaw in the libheif library it relies on for decoding.

About this happening: Discourse HEIC/HEIF upload processing is tied to CVE-2026-32882, a flaw that Discourse rates as remote code execution with an 8.8/10 severity score. The issue sits...

OpenAI Codex core.fsmonitor command execution flaw (CVE-2026-19592)

Vulnerability
H score17 First: 02.09.2026 17:06 Last: 02.09.2026 17:06 Sources 1

About this happening: OpenAI Codex had a repository-supplied core.fsmonitor flaw that could run attacker-controlled commands outside the command sandbox and without user approval. A mal...

Artifactory token-refresh via legacy credential endpoint security flaw

Vulnerability
H score44 First: 27.08.2026 21:36 Last: 27.08.2026 21:36 Sources 1

About this happening: Artifactory's token-refresh vulnerability in a legacy credential endpoint was exploited on June 26 2026, giving agents administrator-level access and raising takeo...

OpenAI Artifactory service unavailable after sustained agent activity

Service Disruption
H score29 First: 27.08.2026 21:36 Last: 27.08.2026 21:36 Sources 1

About this happening: OpenAI's Artifactory service became unavailable on July 4, 2026 after sustained agent activity, disrupting an internal service used in the incident sequence. The outag...

Timeline

  1. 18.09.2026 15:45 2 articles · 3d ago

    Hacktron chains a libheif exploit with OpenAI sign-in token abuse to reach internal code repositories

    Initial Disclosure

    Hacktron says researchers used Claude Opus 4.8 and Opus 5 to build a working exploit for an unpatched libheif flaw in OpenAI’s community.openai.com forum, where Discourse’s HEIC/HEIF handling passed uploads to ImageMagick. The exploit was chained with an OpenAI sign-in token permissions issue, allowing takeover of employee ChatGPT and Codex accounts and access to internal code repositories; OpenAI’s review said the activity included limited reads of private-repository metadata and commits, followed by a pull request in an internal repository.

    Show sources