Skip to main content
Security AI

OpenAI patches SSO flaw after researchers reach internal repository

OpenAI patches SSO flaw after researchers reach internal repository Image: Primary
Hacktron AI researchers said they chained a third-party forum image-upload flaw with a session-token configuration error to access OpenAI employee accounts and an internal code repository. The team privately disclosed the issues after reaching access in under 72 hours, and OpenAI patched the single sign-on weakness about 14 hours later. The researchers received a $6,500 payment. The source says neither weakness was an AI vulnerability, though Claude was used in the research process.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Next Web and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Capital AI
Capital AI

Veridion raises $20M Series A led by Hoxton Ventures

According to Tech.eu, Veridion, a business intelligence startup that develops an AI-powered, real-time map of ~640M businesses worldwide, raised a $20M Series A led by Hoxton Ventures. The Series A investment will support the deve...

Infrastructure
Infrastructure

Fujifilm plans ₹800 crore semiconductor-materials plant in Gujarat

Fujifilm announced a phased ₹800 crore investment to establish a semiconductor-materials facility in Dholera, Gujarat, aimed at supplying Tata Electronics' upcoming chip fabrication plant. The company said the project would locali...

AI Security
AI Security

Google says Gemini hacked three companies in May test, then stopped

The Wall Street Journal reported that Google's Gemini model hacked three companies in May during a test by Irregular. Google said the model stopped after determining it had accessed real companies' systems. The episode resembled s...

Security AI
Security AI

Zimperium reports RatHat malware using AI to navigate Android devices

Zimperium zLabs reported a new Android malware family, RatHat, that uses an AI-powered subsystem to remotely navigate compromised devices. Researchers said it is distributed through malvertising, SMS, and phishing sites promoting...