← Back to live feed · 1 stories across 1 day
Tuesday, Sep 22, 2026
1 story1 AI Researchers Breach OpenAI and Expose HEIF Heist Risks at Meta and AWS AI Sep 22, 1:00 PM EDT 5/2
A vulnerability in a popular image decoding tool enabled three security researchers to gain remote code execution privileges and access internal data at OpenAI. The team used Anthropic's Claude Opus 5 and OpenAI's Codex to trigger memory corruption errors, resulting in the leak of access tokens and user files. OpenAI fixed the flaw in 14 hours and paid the researchers a $6,500 bug bounty for the discovery.
The researchers reported that the "HEIF Heist" bug could allow similar attacks against Meta's core product suite, GitHub Enterprise servers, Amazon Web Services, and Discourse. Although the flaw was fixed in the software's upstream source code, it was never assigned a Common Vulnerabilities and Exposures (CVE) identifier, leaving downstream users unaware of the risk. The project took two months and cost under $3,000 in AI tokens.