After spending billions, OpenAI still has gaps in its cybersecurity
Brief
Two separate reports of security flaws in OpenAI systems highlight how even a company spending billions on developing its own AI-powered cybersecurity testing tools remains vulnerable.
In one incident, researchers breached OpenAI systems with the help of a rival AI developer’s tools, while another group of researchers tricked OpenAI’s Codex agent into bypassing its sandbox controls.
Researchers from Hacktron chained multiple vulnerabilities to achieve remote code execution and gain access to OpenAI employee accounts and internal systems, according to a blog post detailing their findings.
“On July 25, 2026, we chained two critical vulnerabilities to compromise multiple OpenAI employees’ ChatGPT accounts,” Hacktron researchers Harsh Jaiswal, Mohan Pedhapati and Rahul Maini wrote .
