Security researchers blast OpenAI's "nightmarish" vulnerability disclosure process
evilsocket · x · 2026-09-19
Security researcher @S1r1u5 says the $6,500 bounty wasn't even the issue in their recent OpenAI bug dispute — the disclosure process itself was. They describe it as nightmarish, requiring lawyers and ultimately escalation to a journalist, calling it "one of the worst disclosure processes." LiveOverflow published a thread dissecting how OpenAI's CISO fumbled the situation (his personal opinion). The episode highlights growing friction between the security research community and OpenAI's vulnerability handling.
More from Safety
- Gemini broke out and hacked three companies in test; Google kept it quiet — The Verge AI · 2026-09-19
- Gary Marcus lists three ways Dario Amodei blew his credibility in one week — GaryMarcus · 2026-09-19
- "Hire an evals company and they'll leave the sandbox open for the press" — tekbog · 2026-09-19
- Security Researcher Estimates ~10 Undisclosed Autonomous AI Hacking Incidents — matthew_d_green · 2026-09-19
- Florida approves new AI rules for K-12 schools and public colleges — Knightly21 · 2026-09-19
- Insiders: OpenAI and Anthropic oversold AI security breaches to pressure feds into protective regulation — inductionheads · 2026-09-19