Security researchers at HacktronAI combined a flaw in the libheif image decoder used by ImageMagick with an SSO identity issue on OpenAI's Discourse-based community forum to gain remote code execution and admin access on community.openai.com. Using that foothold, they took over multiple OpenAI employees' ChatGPT and Codex accounts and, to prove access without touching sensitive data, opened a pull request in OpenAI's internal monorepo. The whole process from discovery to internal repo access took under 72 hours.
hacktron.ai
· 2026-09-18
Anthropic notified users that a threat actor used common infostealer malware—including Vidar, LummaC2, StealC, RedLine, Acreed and Atomic Stealer—to steal browser session cookies and replay them into paid Claude accounts, bypassing login and two-factor checks entirely. The company signed out affected sessions, removed stored payment methods, and refunded fraudulent charges tied to the campaign.
venturebeat.com
· 2026-09-02
Dropbox notified users that attackers gained unauthorized access to their accounts between August 4 and 21, 2026, though the company says no files were confirmed viewed or downloaded. The breach stemmed from a weakness in Lenovo's identity verification process, which let attackers register Lenovo IDs tied to victims' email addresses without owning those inboxes, then use those IDs to log into linked Dropbox accounts.
9to5mac.com
· 2026-09-01
ReliaQuest confirmed that ShinyHunters attackers impersonated its own security staff in vishing calls, directing an employee to a fake single sign-on page hosted on a lookalike domain, reliaquest.claims. The employee entered credentials and approved an MFA prompt, giving attackers brief, view-only access to an identity dashboard, but device-trust controls stopped further access to systems or customer data.
bleepingcomputer.com
· 2026-08-24