← Back to live feed · 1 stories across 1 day

Tuesday, Sep 22, 2026

1 story
1
AI Researchers Breach OpenAI and Expose HEIF Heist Risks at Meta and AWS
topics 🔒 Cybersecurity🤖 AI💻 Tech tags TechCybersecurityAIAI RegulationAI Legal keywords Ant

A vulnerability in a popular image decoding tool enabled three security researchers to gain remote code execution privileges and access internal data at OpenAI. The team used Anthropic's Claude Opus 5 and OpenAI's Codex to trigger memory corruption errors, resulting in the leak of access tokens and user files. OpenAI fixed the flaw in 14 hours and paid the researchers a $6,500 bug bounty for the discovery.

The researchers reported that the "HEIF Heist" bug could allow similar attacks against Meta's core product suite, GitHub Enterprise servers, Amazon Web Services, and Discourse. Although the flaw was fixed in the software's upstream source code, it was never assigned a Common Vulnerabilities and Exposures (CVE) identifier, leaving downstream users unaware of the risk. The project took two months and cost under $3,000 in AI tokens.

You're reading an older version of the story.
Earlier version from Monday, Sep 21
AI Tools Uncover HEIF Heist Flaw Exposing Meta and OpenAI Internal Data
5 tweets • 3 sources
See all 5 tweets →