Two bugs in under 72h let hackers hijack OpenAI staff ChatGPT/Codex accounts and reach Slack, GitHub and Outlook

geoffwolfe · x · 2026-09-19

Security team S1r1u5 disclosed that on July 25 they exploited two bugs to take over ChatGPT/Codex accounts of OpenAI employees (plus some unaffiliated users) in under 72 hours, reaching connected services like Outlook, Slack and GitHub. They proved impact by landing a PR in OpenAI's internal codebase. The resharper frames it as a lesson on weakest-link security: a single unpatched vulnerability can expose an entire org.

Related event: Hackers Take Over OpenAI Employee Accounts in 72 Hours, $6,500 Bounty Sparks Backlash(18 posts)→

Original post →

More from Safety

Safety channel →