Skip to content

Source

Hacktron AI

1 item

The research blog of Hacktron, an offensive security firm whose team publishes its own vulnerability research with full disclosure timelines, affected versions and vendor responses. Primary for the findings it reports itself, including the HEIF Heist work on libheif; there is no deeper source behind a team's own exploit writeup.

hacktron.ai

Hacking OpenAI
Industrystrong signal

An image upload reached OpenAI's internal code, and Claude Opus 5 wrote the exploit

Three researchers at Hacktron chained a memory bug in libheif with a flaw in OpenAI's single sign-on and ended up inside the company's internal code repository. The way in was a HEIC file uploaded to the public community forum. Opus 4.8 could not build a reliable exploit across several sessions; Opus 5, released the same evening, managed it in three hours. OpenAI paid a $6,500 bounty, and the whole chain took less than 72 hours.

Hacktronverified