← Back to live feed

Wednesday, Sep 23, 2026

1
Claude Opus 5 AI Uncovers HEIF Heist Bug at Meta and OpenAIMETAPVT:OPAIAMZN
topics 🔒 Cybersecurity🤖 AI💻 Tech tags TechCybersecurityAIAI RegulationAI Legal METAPVT:OPAIAMZN keywords OpenAI ResearchersAnthropicOpenOpenAI

Researchers exploited a flaw in a popular image-decoding tool to gain unauthorized access to internal repositories and employee accounts at several major tech firms. The vulnerability, nicknamed "HEIF Heist," enables memory corruption errors that grant remote code execution privileges over Meta's core product suite, Amazon Web Services and GitHub Enterprise. Three security researchers used Anthropic's Claude Opus 5 and OpenAI's Codex to identify the hole and subsequently took over OpenAI's public help forum server.

OpenAI paid the researchers a $6,500 bounty and patched the flaw within 14 hours of the report. The security hole existed in a HEIF image library where a fix had been applied upstream but not labeled as a security update, which delayed downstream patching for other companies. The research team spent under $3,000 on AI tokens over two months, reporting that the Claude Opus 5 model identified the exploit in hours while the older Opus 4.8 failed.

You're reading an older version of the story.
Researchers Hack OpenAI Using Claude Opus 5 to Find Decoder Flaw
7 tweets • 4 sources
Earlier version from Tuesday, Sep 22
Claude Opus 5 Breaches OpenAI After Prior Model Failed
7 tweets • 4 sources
See all 8 tweets →