Wednesday, Sep 23, 2026
1 Claude Opus 5 AI Uncovers HEIF Heist Bug at Meta and OpenAIMETAPVT:OPAIAMZN 🔒 Cybersecurity Sep 23, 5:00 PM EDT 8/5
Researchers exploited a flaw in a popular image-decoding tool to gain unauthorized access to internal repositories and employee accounts at several major tech firms. The vulnerability, nicknamed "HEIF Heist," enables memory corruption errors that grant remote code execution privileges over Meta's core product suite, Amazon Web Services and GitHub Enterprise. Three security researchers used Anthropic's Claude Opus 5 and OpenAI's Codex to identify the hole and subsequently took over OpenAI's public help forum server.
OpenAI paid the researchers a $6,500 bounty and patched the flaw within 14 hours of the report. The security hole existed in a HEIF image library where a fix had been applied upstream but not labeled as a security update, which delayed downstream patching for other companies. The research team spent under $3,000 on AI tokens over two months, reporting that the Claude Opus 5 model identified the exploit in hours while the older Opus 4.8 failed.