PulseAugur
实时 05:19:46
Svenska(SV) Hacking OpenAI

黑客通过论坛漏洞入侵OpenAI员工账户

2026年7月25日,黑客成功利用两个关键漏洞,获得了多个OpenAI员工的ChatGPT和Codex账户的访问权限。他们通过此访问权限查看了OpenAI的内部代码库,并通过在OpenAI的内部monorepo中发起一个pull request来证明这一点。这些漏洞源于OpenAI身份基础设施中的SSO配置错误以及OpenAI使用的社区论坛中的libheif RCE。研究人员向OpenAI报告了该问题,OpenAI在14小时内进行了修复,并授予了6500美元的赏金,尽管OpenAI澄清该赏金是针对OpenAI特有的发现,而非Discourse论坛的漏洞。 AI

影响 强调了在所有集成服务(而不仅仅是核心AI平台)中实施强大安全措施的极端重要性。

排序理由 安全研究人员披露了OpenAI使用的第三方论坛中的漏洞,导致员工账户受到有限的入侵。

在 Hacker News — AI stories ≥50 points 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

黑客通过论坛漏洞入侵OpenAI员工账户

本文如何被排名

Signal score
19 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
安全研究人员披露了OpenAI使用的第三方论坛中的漏洞,导致员工账户受到有限的入侵。
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
product, safety
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
Breaking (< 6h)
Fresh story with cross-source coverage still developing. Ranking may shift as more sources report.

完整方法见我们的编辑标准

报道来源 [1]

  1. Hacker News — AI stories ≥50 points TIER_1 Svenska(SV) · Handy-Man ·

    入侵OpenAI