← Back to live feed1 story
Researchers used Anthropic's Claude and OpenAI's Codex to discover a memory corruption vulnerability known as HEIF Heist in a popular software decoding tool. The flaw enables attackers to trigger memory corruption errors to steal sensitive data and gain remote code execution privileges on platforms including Meta's core product suite, GitHub Enterprise, and the internet forum Discourse.
A Thursday report detailed the potential for unauthorized access to internal OpenAI repositories and the theft of access tokens from Amazon Web Services. The vulnerability targets decoding software used by enterprise services and web frameworks, leaving users open to data theft and remote access.
Sign in to suggest edits
Key sources
- SOURCE@cyberscoopnews“gaining access to internal OpenAI repositories, leaking user files, access tokens, and other sensitive data for online services like Amazon Web Services”x.com
- SOURCE@cyberscoopnews“gaining remote code execution privileges across a range of online services, including Meta’s core product suite, GitHub Enterprise servers and open-source internet forum Discourse”x.com
- SOURCEmarketbrief.now