SECURITY·중요도 9·2026. 09. 18.·GeekNews
OpenAI 해킹
── KO ──────────────────
OpenAI 직원의 ChatGPT 계정이 해킹당한 사건 소개.
Hacktron은 libheif 원격 코드 실행 취약점과 OpenAI SSO 설정 오류를 통해 여러 OpenAI 직원의 ChatGPT 계정을 탈취했습니다. 이 공격은 포럼 이미지 업로드에서 시작되었으며, 공격자가 연결된 Codex로 내부 저장소에 접근하는 방법도 포함되어 있습니다. 이 사건은 보안의 중요성을 다시 한 번 일깨워줍니다.
── EN ──────────────────
Incident of hacking OpenAI employees' ChatGPT accounts discussed.
Hacktron exploited a remote code execution vulnerability in libheif combined with an OpenAI SSO misconfiguration to steal several OpenAI employees' ChatGPT accounts. The attack started through forum image uploads, allowing attackers to access internal storage connected to Codex. This incident underscores the critical importance of security.