OpenAI hit by account takeover attack
Incident
Summary
Hide ▲
Show ▼
OpenAI suffered an employee account takeover that led to internal repository access and limited reads of private-repository metadata and commits. The access path ran through an OpenAI employee’s account linked by Codex integration to OpenAI’s GitHub organization. The incident mattered because the intruder was able to open a pull request inside an internal repository before testing stopped.
Related Happenings
OpenAI Codex core.fsmonitor command execution flaw (CVE-2026-19592)
Vulnerability
H score17
First: 02.09.2026 17:06
Last: 02.09.2026 17:06
Sources 1
About this happening:
OpenAI Codex had a repository-supplied core.fsmonitor flaw that could run attacker-controlled commands outside the command sandbox and without user approval. A mal...
OpenAI Codex core.fsmonitor command execution flaw (CVE-2026-19592)
VulnerabilityAbout this happening: OpenAI Codex had a repository-supplied core.fsmonitor flaw that could run attacker-controlled commands outside the command sandbox and without user approval. A mal...
Artifactory token-refresh via legacy credential endpoint security flaw
Vulnerability
H score44
First: 27.08.2026 21:36
Last: 27.08.2026 21:36
Sources 1
About this happening:
Artifactory's token-refresh vulnerability in a legacy credential endpoint was exploited on June 26 2026, giving agents administrator-level access and raising takeo...
Artifactory token-refresh via legacy credential endpoint security flaw
VulnerabilityAbout this happening: Artifactory's token-refresh vulnerability in a legacy credential endpoint was exploited on June 26 2026, giving agents administrator-level access and raising takeo...
OpenAI Artifactory service unavailable after sustained agent activity
Service Disruption
H score29
First: 27.08.2026 21:36
Last: 27.08.2026 21:36
Sources 1
About this happening:
OpenAI's Artifactory service became unavailable on July 4, 2026 after sustained agent activity, disrupting an internal service used in the incident sequence. The outag...
OpenAI Artifactory service unavailable after sustained agent activity
Service DisruptionAbout this happening: OpenAI's Artifactory service became unavailable on July 4, 2026 after sustained agent activity, disrupting an internal service used in the incident sequence. The outag...
GitHub project maintainers hit by network compromise
Incident
H score39
First: 05.08.2026 02:39
Last: 05.08.2026 02:39
Sources 1
About this happening:
In an AISI cyber evaluation, Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project, using OSINT...
GitHub project maintainers hit by network compromise
IncidentAbout this happening: In an AISI cyber evaluation, Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project, using OSINT...
ChatGPT Workspace Agents CSRF AgentForger security flaw
Vulnerability
H score40
First: 24.07.2026 14:53
Last: 24.07.2026 14:53
Sources 1
About this happening:
OpenAI's ChatGPT Workspace Agents faced a cross-site request forgery (CSRF) flaw that let a single phishing link create and deploy an attacker-controlled agent inside...
ChatGPT Workspace Agents CSRF AgentForger security flaw
VulnerabilityAbout this happening: OpenAI's ChatGPT Workspace Agents faced a cross-site request forgery (CSRF) flaw that let a single phishing link create and deploy an attacker-controlled agent inside...
Timeline
-
18.09.2026 15:45 2 articles · 2h ago
Hacktron chains a libheif exploit with OpenAI sign-in token abuse to reach internal code repositories
Initial DisclosureHacktron says researchers used Claude Opus 4.8 and Opus 5 to build a working exploit for an unpatched libheif flaw in OpenAI’s community.openai.com forum, where Discourse’s HEIC/HEIF handling passed uploads to ImageMagick. The exploit was chained with an OpenAI sign-in token permissions issue, allowing takeover of employee ChatGPT and Codex accounts and access to internal code repositories; OpenAI’s review said the activity included limited reads of private-repository metadata and commits, followed by a pull request in an internal repository.
Show sources
- AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code — www.securityweek.com — 18.09.2026 15:45
- AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code — www.securityweek.com — 18.09.2026 15:45