Researchers Breached OpenAI Staff Accounts via SSO Bug, Got $6,500 Bounty
kevinnbass · x · 2026-09-19
- Security researchers disclosed a Discourse SSO bug that could compromise OpenAI employees' ChatGPT and Gmail accounts.
- OpenAI patched it 14 hours after submission; Discourse fixed it within two days. The team was awarded $6,500.
- The original poster mocks the payout: a $1.2T company paying less than a McDonald's manager's monthly salary, arguing OpenAI doesn't take cybersecurity seriously.
More from Safety
- How AI-Era Intermediaries Could Become Systemically Dangerous Power Brokers — iamtrask · 2026-09-20
- Autonomic Defense: countering AI-driven cyber offense at machine speed — philvenables · 2026-09-20
- iamtrask endorses betterpath.ai framework: compete on narrow AI, slow down general AI — iamtrask · 2026-09-20
- NYT Exposes How DraftKings Uses AI to Target Gamblers Likeliest to Lose — Actual__Wizard · 2026-09-20
- iamtrask: Antitrust May Be the Most Important AI Safety Strategy — and It Speeds Up Innovation — iamtrask · 2026-09-20
- StopTheAIRace marches past OpenAI and Anthropic to SF City Hall demanding AI regulation — DavidSKrueger · 2026-09-20