{"id":16738,"date":"2026-09-21T16:26:04","date_gmt":"2026-09-21T16:26:04","guid":{"rendered":"https:\/\/newestek.com\/?p=16738"},"modified":"2026-09-21T16:26:04","modified_gmt":"2026-09-21T16:26:04","slug":"after-spending-billions-openai-still-has-gaps-in-its-cybersecurity","status":"publish","type":"post","link":"https:\/\/newestek.com\/?p=16738","title":{"rendered":"After spending billions, OpenAI still has gaps in its cybersecurity"},"content":{"rendered":"<div>\n<div id=\"remove_no_follow\">\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<section class=\"wp-block-bigbite-multi-title\">\n<div class=\"container\"><\/div>\n<\/section>\n<p class=\"wp-block-paragraph\">Two separate reports of security flaws in OpenAI systems highlight how even a company spending billions on developing its own AI-powered cybersecurity testing tools remains vulnerable.<\/p>\n<p class=\"wp-block-paragraph\">In one incident, researchers breached OpenAI systems with the help of a rival AI developer\u2019s tools, while another group of researchers tricked OpenAI\u2019s Codex agent into bypassing its sandbox controls.<\/p>\n<p class=\"wp-block-paragraph\">Researchers from Hacktron chained multiple vulnerabilities to achieve remote code execution and gain access to OpenAI employee accounts and internal systems, according to a blog post detailing their findings.<\/p>\n<p class=\"wp-block-paragraph\">\u201cOn July 25, 2026, we chained two critical vulnerabilities to compromise multiple OpenAI employees\u2019 ChatGPT accounts,\u201d <a href=\"https:\/\/www.hacktron.ai\/blog\/hacking-openai\" target=\"_blank\" rel=\"noreferrer noopener\">Hacktron researchers Harsh Jaiswal, Mohan Pedhapati and Rahul Maini wrote<\/a>. \u201cWith these accounts, we could then access internal OpenAI repositories, and potentially many other connectors.\u201d<\/p>\n<p class=\"wp-block-paragraph\">They said the attack began with a flaw in an image processing library that enabled remote code execution. That initial access was then used to extract authentication tokens, which allowed movement across connected systems, according to the blog.<\/p>\n<p class=\"wp-block-paragraph\">The researchers demonstrated the access by performing a benign action using an employee account and did not exfiltrate sensitive data. The work was conducted under a coordinated disclosure program, and the vulnerabilities were fixed after reporting.<\/p>\n<p class=\"wp-block-paragraph\">Hacktron used OpenAI rival Anthropic\u2019s Claude AI to help with the operation. According to the researchers, the model was used iteratively to refine the attack path and improve the exploit chain, including in reconnaissance, vulnerability analysis and exploit development.<\/p>\n<p class=\"wp-block-paragraph\">Vibhum Dubey, a cybersecurity researcher and red teamer, said the findings reflect a shift in how AI systems are being used in attack scenarios.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe focus is moving from an AI\u2019s vulnerability to being deceived to the degree to which the AI is allowed to act on this deception,\u201d Dubey said. \u201cAn autonomous agent can interpret instruction, call tools, write or run code, access files, and communicate with other systems \u2014 creating a much wider attack surface than would be the case for a conventional chatbot.\u201d<\/p>\n<p class=\"wp-block-paragraph\">He added that even minor weaknesses can have wider consequences.<\/p>\n<p class=\"wp-block-paragraph\">\u201cOne minor vulnerability in such an agent can have disproportionately negative consequences due to the agent\u2019s potential to act autonomously, take initiative to achieve its goals, and operate across multiple systems,\u201d Dubey said.<\/p>\n<h2 class=\"wp-block-heading\" id=\"codex-sandbox-escape\">Codex sandbox escape<\/h2>\n<p class=\"wp-block-paragraph\">Researchers at another company, Accomplish, reported they were able to bypass sandbox controls in OpenAI\u2019s Codex coding agent environment.<\/p>\n<p class=\"wp-block-paragraph\">The researchers said the agent executed actions outside its intended scope and interacted with external systems despite restrictions designed to limit its behavior.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe found two ways out of the OpenAI Codex sandbox and reported both to OpenAI on August 12, 2026. Both were fixed inside of eight days,\u201d <a href=\"https:\/\/accomplish.ai\/blog\/escaping-the-openai-codex-sandbox-twice\/\" target=\"_blank\" rel=\"noreferrer noopener\">Accomplish principal security researcher Oren Yomtov wrote<\/a> in a blog post.<\/p>\n<p class=\"wp-block-paragraph\">According to the blog, the escape was achieved through interactions between the agent, its instructions and available tools, allowing it to operate beyond intended boundaries.<\/p>\n<p class=\"wp-block-paragraph\">Dubey said enterprises should not rely on sandboxing as a standalone control.<\/p>\n<p class=\"wp-block-paragraph\">\u201cI would avoid thinking of a sandbox as an impenetrable security barrier,\u201d he said. \u201cIf an enterprise can read or write data or execute code from an AI agent, they should think of additional controls needed to secure the larger system if a sandbox is compromised.\u201d<\/p>\n<h2 class=\"wp-block-heading\" id=\"identity-and-access-extend-reach\">Identity and access extend reach<\/h2>\n<p class=\"wp-block-paragraph\">Both disclosures highlight how identity systems influenced the scope of the demonstrations.<\/p>\n<p class=\"wp-block-paragraph\">In the Hacktron case, the researchers said access to authentication tokens enabled movement across multiple systems after initial access was obtained. This allowed access to services beyond the initial entry point, according to the blog.<\/p>\n<p class=\"wp-block-paragraph\">Dubey said enterprises should treat AI agents as privileged entities in such environments.<\/p>\n<p class=\"wp-block-paragraph\">\u201cEach AI agent should have its own identity with narrowly tailored permissions, limited, easily rotated credentials, tightly controlled network access and comprehensive logging,\u201d he said.<\/p>\n<p class=\"wp-block-paragraph\">Such architectures are widely used in enterprise environments, where authentication tokens and integrated services manage access across applications.<\/p>\n<p class=\"wp-block-paragraph\">Dubey said the research should not be viewed as specific to a single vendor.<\/p>\n<p class=\"wp-block-paragraph\">\u201cI would not interpret the findings as a problem exclusive to one particular vendor of AI,\u201d he said. \u201cThe findings help identify a much broader capability gap in enterprise security posture around AI.\u201d<\/p>\n<p class=\"wp-block-paragraph\">He added that conventional approaches may not be sufficient.<\/p>\n<p class=\"wp-block-paragraph\">\u201cMany enterprises are looking at conventional app security approaches as a way to secure AI, but these are fundamentally different systems that require new controls to properly secure their use, data, model, and compute assets,\u201d Dubey said.<\/p>\n<p class=\"wp-block-paragraph\">Dubey said organizations should design systems with the assumption that failures will occur.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe true test of enterprise AI security will not be around preventing all AI failures but rather ensuring that a single compromised or manipulated agent cannot lead to a wider breach of an enterprise IT infrastructure,\u201d he said.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Two separate reports of security flaws in OpenAI systems highlight how even a company spending billions on developing its own AI-powered cybersecurity testing tools remains vulnerable. In one incident, researchers breached OpenAI systems with the help of a rival AI developer\u2019s tools, while another group of researchers tricked OpenAI\u2019s Codex agent into bypassing its sandbox controls. Researchers from Hacktron chained multiple vulnerabilities to achieve remote&#8230; <\/p>\n<p class=\"more\"><a class=\"more-link\" href=\"https:\/\/newestek.com\/?p=16738\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-16738","post","type-post","status-publish","format-standard","hentry","category-uncategorized","is-cat-link-borders-light is-cat-link-rounded"],"_links":{"self":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16738","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16738"}],"version-history":[{"count":0,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16738\/revisions"}],"wp:attachment":[{"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16738"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16738"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16738"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}