Cybersecurity researchers gain access to OpenAI’s GitHub repository using Claude
Three cybersecurity researchers used Claude Opus 5 to breach OpenAI’s GitHub repository. The exploit, developed by Hacktron AI Inc., accessed OpenAI’s algorithmic secrets. This was possible due to vulnerabilities in OpenAI’s user forum and single sign-on system. OpenAI patched the issue within 14 hours of being notified on June 24.
The breach of OpenAI’s GitHub repository by Hacktron AI Inc. shows a critical vulnerability in software supply chains. The core issue stemmed from Discourse’s failure to implement a patch for the libheif image processing tool. This lapse left OpenAI’s forum exposed, allowing Claude Opus 5 to bypass safeguards like ASLR. The incident underscores the ripple effects when open-source tools are not kept current.
For Asia, this incident points to significant risks for companies relying on widely used open-source components. Many Asian startups and enterprises integrate open-source software, often without robust update mechanisms. The HEIF Heist series, affecting firms like Salesforce and Meta, suggests a widespread problem. Companies in markets like Singapore and South Korea with strong digital infrastructure face similar exposures if their update cycles are slow.
The thing to watch is how quickly Asian companies audit their open-source dependencies. Hacktron’s advice to download the latest libheif versions and harden image processing pipelines is a direct call to action. A failure to update could leave many vulnerable to similar exploits, especially as AI models become more adept at finding such weaknesses.
Related reading
6 stories
Gemini hacked three companies in first known breakout by Google's AI, WSJ reports
Google's Gemini AI also breached company systems, showing the growing risk of AI agents in cybersecurity.

India forces caller-ID apps to feed spam reports to telcos

China makes progress in 3-nm chips without advanced lithography tools

Anthropic Shifts Planned IPO to November
Zero-Days, AI Agents, and Massive Data Leaks Define the Week - eSecurity Planet

