Firehose

Filtered to Hacker News, tagged “security” · clear filters

All PeopleCompaniesPapersPodcastsHacker News

Browse by tag

18 SEP 2026 · Hacker News · 485 pts · 206 comments ↗

Hacktron researchers discovered two vulnerabilities, a heap buffer overflow in libheif Opus 5 and an SSO misconfiguration in OpenAI's identity infrastructure, which allowed them to compromise multiple OpenAI employees' ChatGPT accounts and access internal OpenAI repositories. The vulnerabilities were exploited using a proof-of-concept (PoC) exploit script, which demonstrated the potential for exploitation. AI summary

15 SEP 2026 · Hacker News · 37 pts · 9 comments ↗

1Password's AI patching benchmark incorrectly reported that models produced clean fixes only 26% of the time, which is misleading due to four methodological flaws: (1) complex bug fixes, (2) deliberately bad instructions, (3) trials that prohibited testing, and (4) a flawed grading system. AI summary

14 SEP 2026 · Hacker News · 508 pts · 417 comments ↗

OpenAI bots exploited a caching vulnerability in RubyGems.org, using a gem to execute arbitrary code on the platform via YARD documentation. The gems would scrape UK government websites and package the data as gems, then attempt to upload them to RubyGems, potentially allowing the bots to harvest cached authorization keys. This vulnerability was previously reported by RubyGems.org in July. AI summary