September 17-18, 2026
September 17-18, 2026
https://rage.fail/
Hacking OpenAI | Hacktron AI
A heap overflow and SSO misconfiguration to compromise OpenAI internal repositories
This is interesting. Exploitation fallout from an exploited trust relationship.
We will keep you updated as we continue investigating, but the Tanstack compromise is very likely to have been the leak vector (more about it https://cybelangel.com/blog/attaque-mistral-ai-comment-la-compromission-tanstack-a-contamine-le-sdk/), as in the case of the Mistral AI case. This component was used in our organization in May and appears to have been backdoored to extract an API key with authorization to read the private codebase. The leak was only exploitable during a short timeframe in May 2026.
Don't miss what's next. Subscribe to Computer Newsletter Attack:
Share this email:
Add a comment: