← Back to live feed · 1 stories across 1 day
Saturday, Sep 19, 2026
1 story1 OpenAI Security Chief Apologizes After Dispute Over Hack Disclosure↩︎ AI Sep 19, 9:03 AM EDT 114/76
Hacktron researchers said OpenAI asked them to remove a screenshot proving access to an employee’s account from their disclosure report, and that its chief information security officer called the draft a “stunt document.” Security researcher LiveOverflow later reported an apology: “CISO reached out and apologized 🙇 we are good.”
OpenAI paid the researchers a $6,500 bounty, but Hacktron researcher S1r1u5_ said the payment was not the issue. “the disclosure process itself was nightmarish, we had to get input from lawyers and eventually go to journalist,” the researcher said. OpenAI also asked the team to remove its name from the report’s title and drop a link, the researchers said. LiveOverflow said the public criticism was a personal opinion, not part of the disclosure plan.
The dispute followed Hacktron’s July 25 breach using Anthropic’s Claude. Three researchers chained an image decoder vulnerability in OpenAI’s community forum with a login flaw to take over employee ChatGPT and Codex accounts in less than 72 hours. They demonstrated access by having Codex submit a harmless proposed code change to OpenAI’s private repository. OpenAI fixed the login flaw roughly 14 hours after the report. The company said its review found only limited reads of repository metadata and code changes, with no model weights believed exposed.