Fetching from the wire…
Public story · 2026-09-18 · high
A missing Debian codec patch and an SSO misconfiguration chained a forum bug into OpenAI's internal GitHub access in under three days.
Why now: Hacktron published the full writeup on September 18.
A heap buffer overflow in libheif reached a pull request inside OpenAI's private monorepo in under 72 hours, according to Hacktron's writeup published September 18. The bug traces back to a missing Debian 12 and 13 security backport. That gap put an AI coding agent three hops from a company's source code.
ImageMagick's HEIF handling carried the overflow into Discourse image uploads on community.openai.com, giving Hacktron's researchers remote code execution and Discourse admin access between 05:00 and 06:00 UTC on July 25. That foothold exposed an OpenAI SSO misconfiguration. By 15:30 the same day, the researchers held employee ChatGPT and Codex accounts along with their connected GitHub integrations. From there, an AI assistant opened a proof-of-concept pull request in OpenAI's internal monorepo. OpenAI confirmed a fix by 22:49 that night.
The payout was $6,500, awarded for the SSO finding rather than the Discourse compromise that started the chain.
Hacktron also says Claude Opus 4.8 failed the ARM64 exploit across several sessions before Opus 5 produced a working one in hours, per the WSJ.
The writeup doesn't say how long the unpatched libheif version sat in front of Discourse before Hacktron found it, or whether other OpenAI-adjacent services shared the same dependency.
Each link below shares sources, entities, or timing with this story.
43.3% on Frontier-Bench v0.1. Opus 4.8 scored 18.7%. That's not an incremental bump, that's the same benchmark with a different shape of answer. Anthropic released Claude Opus 5 on July 24 at $5/$25 per million input/output tokens, exactly half of Fable 5's $10/$50, while matc...
OpenClaw tagged v2026.8.1 at 03:30 UTC this morning. The release post counts 933 contributors, 569 of them first-time, and more than 16,000 pull requests, roughly half of every PR ever merged into the project, after a seven-week gap against a prior cadence of 106 releases in 2...
OpenAI shipped GPT-5.5 on April 23, six weeks after 5.4. The capability jump is real: 82.7% on Terminal-Bench 2.0 vs Claude Opus 4.7's 69.4%. The Pro tier nearly doubles Opus 4.7 on FrontierMath Tier 4 at 39.6% vs 22.9%. It uses 40% fewer tokens on Codex tasks while matching 5...
Anthropic released Claude Fable 5.1 on September 1. Claude Code v2.1.257 made it the default Fable model at 17:53 UTC that day, with a 1M-token context window, $10 per million input tokens, $50 per million output, and $0.25 per million on cache reads (claude-code CHANGELOG). B...
Three things happened this month that only make sense together. Agent Plugins 1.0 shipped co-signed by six competitors: AWS, Anysphere, Microsoft, OpenAI, Vercel and Google (GitHub Changelog). It makes skills-plus-MCP bundles portable across clients. OpenAI's August 11 Codex c...
Preview as of August 11, bundling ChatGPT, ChatGPT Work and Codex, built for Ubuntu 24.04/26.04 LTS, Debian 13, Fedora 43/44 on x64 and ARM64, with an installer that registers an OpenAI repo so updates flow through apt (TechCrunch). Modest community heat (109 upvotes on r/sing...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.