Taking notes for next time 📝
“Responsible disclosure means following rules. Responsible disclosure does not mean acting responsible.”
Noted. Thanks 🙏
CISO reached out and apologized 🙇 we are good.
Also wanted to say that this thread was not part of the disclosure plan, and it was just my personal opinion. I felt like
@rootxharsh and
@S1r1u5_ were treated unkind, and I wanted to say something.
Show more
@jachiam0 if you’re still in openai slack, join the private channel where we connected, scroll up, and tell me whether this situation really had to be handled this way, or whether it could have gone completely differently by just being nice.
Show more
@jachiam0 if you’re still in openai slack, join the private channel where we connected, scroll up, and tell me whether this situation really had to be handled this way, or whether it could have gone completely differently by just being nice.
Show more
now you know what this number is
I have been on both side of such submissions and sometimes people go outside scope, knowingly or unkowningly, try to show max impact in safe manner and bounties can be debated but a sincere thank you doesn't cost anything ig?
The way it was handled, in my 10 years of bug bounty exp, I had only seen it twice.
Show more
I want to be very clear about this.
just because we found one serious exploit on openai does not mean we know how to secure an organization that complex. openai has security people with far more experience and better qualified doing that than us, and i don’t want to pretend we have solutions.
note, i was saying "they are building manhattan project", it is not a belief i strongly hold, i don’t like making confident predictions about the future. it is the labs that make those comparisons.
what I know for a fact is that these models already have serious offensive cyber capabilities, what that does to the world, I don’t know, but my loosely held view is that it might lead to a period of turbulence because i think its offense dominant than defense
having said that, what i don’t understand is this, if the people building these systems truly believe they are powerful enough to create nuclear level risks, and they are talking about slowing down because of those risks, why is that work is done through ordinary saas products?
why is it happening through slack, managed github, employee browsers, and apps accessible from the public internet? every third party and library they use becomes part of the attack surface.
remember the jfrog registry in the hugging face agent swarm? it didn’t matter that it was a third party, it was in the path. an attacker, or an unaligned model, doesn’t care who owns it or its out of scope. they will hack whatever is in the path to achieve their goal.
one more concerning thing is, why are codex cloud, claude(assuming anthropic does the same) publicly accessible web applications connected directly to private github repositories?
again shouting my lungs out, coding agents on the cloud is worst thing happened in terms of security, it is going backwards.
your browser becomes a attack surface, a lame xss, stolen creds, phishing, browser exploits, all these bugs can achieve similar impactful bugs as we shown. like, you don't need to pivot anymore and worry much about exfiling, just compromise cloud agent its all over either through client-side browser or the server.
Show more
Of all the disclosures we did over the last few weeks, my favourite was working with Vercel team, they actually cared, understood the attack surface and responded quickly.
man, we love working with vercel, both their ceo and cto joins the slack channel to handle things, they are incredible at handling disclosures, we always have best experience dropping research on them.
Show more
You probably heard about the OpenAI white-hat hack earlier today by
@S1r1u5_ and friends.
The same vulnerability impacted most image processing where images can be under attacker control (like an app with profile picture upload), and with that next.js' image optimization support.
Here is the story of how we handled this event, helped track down "the literal guy in Nebraska" that
@xkcd predicted and get the underlying issue fixed.
Also, notable, when using image optimization through Vercel's platform you are protected from exploitation through sandboxing of the code that handles potentially hostile payloads.
Show more
It's interesting how the media created an Anthropic vs. OpenAI model narrative out of this.
GPT-5.6 Sol is such a great model for exploitation. OpenAI just got unlucky that it was released one day too late hahahah.
- Opus 4.8 found the vuln, but failed to exploit
- 24. July Opus 5 release
- 25. July Opus 5 writes Discourse exploit
- 26. July GPT-5.6 Sol release
Later
@rootxharsh and
@S1r1u5_ used GPT-5.6 Sol to write an exploit against a blind target (Slack). Which seemed like another small jump in capability from Opus 5.
I also used GPT-5.6 Sol for the v8 n-day exploit.
Show more
@SimonLermenAI yes, coordinated with meta, slack, github enterprise, next.js, and rails.
the seed was planted years ago by a superintelligent AI time-traveling through xkcd 2347, then hyperstited into reality
Show more
@SimonLermenAI yes, coordinated with meta, slack, github enterprise, next.js, and rails.
the seed was planted years ago by a superintelligent AI time-traveling through xkcd 2347, then hyperstited into reality
Show more
@jachiam0 i wouldn't say every attachment, we saw images, wav, xlsx and docs being processed.
"3 random dudes”
1. hacked apple, again and again.
2. your github enterprise is our github enterprise.
3. get a discord message from me, get pwned.
4. oh yeah, at one point we basically had shells across the electron ecosystem. check the DEF CON research.
5. your supabase database is my database.
6. we got the posthog prod database.
7. react2shell? vercel paid us $170k for helping secure their waf.
8. your palo alto vpn is my vpn.
9. ai ides? we got shells for you, antigravity
10. windsurf rce.
11. turning cluely into malware.
12. ai browsers? sure, uxss: your perplexity browser is my browser.
13. openai atlas too. kinda uxss
14. hey, it’s not even our first time hacking discourse.
15. adobe coldfusion: pre-auth rce. because apparently we needed another one.
there’s a lot more. go dig.
anyway, yes: “3 random dudes.”
and
@HacktronAI is full of more random dudes like these.
Show more
it is max they pay, bounty is usually not our motivation. part of this research motivation is to get tac/cvp to our org which we have been trying for long, so hope is to do good-faith research, find vulnerability, prove our work and get access to do more of this work.
we usually send bugs through security@ email if they have disclosure policy that doesn't allow publishing the bugs at cost of not getting bounty
Show more
it is max they pay, bounty is usually not our motivation. part of this research motivation is to get tac/cvp to our org which we have been trying for long, so hope is to do good-faith research, find vulnerability, prove our work and get access to do more of this work.
we usually send bugs through security@ email if they have disclosure policy that doesn't allow publishing the bugs at cost of not getting bounty
Show more
it’s not just openai. the vulnerability goes much deeper.
check out my co-founder harsh’s thread on how far this goes, including a slack vulnerability that could potentially expose companies’ uploaded attachments, and meta vulnerability that affects their core image parser.
he’s the mastermind behind it and the one who opened pandora’s box
Show more
We’re disclosing HEIF Heist, a months-long investigation into libheif that allowed us to hack OpenAI, Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick, and many more.
It was literally xkcd #
234#, one obscure image library beneath a huge number of apps. 🧵
Show more
We reported the bug to Discourse and OpenAI. OpenAI fixed the SSO issue roughly 14 hours after our initial submission.
Discourse received our separate report Saturday, replied Sunday, and had a fix Monday.
OpenAI awarded us $6,500.
Show more
At a high level, this was the full exploit chain.
1. HEIC/HEIF upload
2. ImageMagick decoding
3. Heap overflow on libheif
4. RCE on
5. Critical OpenAI SSO flaw
6. ChatGPT/Codex takeover
7. Connected GitHub access
8. Internal repo PR #
1186742#
Show more
On July 25, we hacked OpenAI.
Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc.
We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵
Show more