How OpenAI got hacked with an image
Security researchers Harsh and Sirius from Hektron successfully injected a pull request into OpenAI's internal repository, proving a critical breach of their infrastructure. The attack exploited a vulnerability in the libvips image processing library used by the Discourse platform, which OpenAI hosts for user authentication. This incident highlights how outdated dependencies and complex software stacks create exploitable gaps even within trillion-dollar organizations. The researchers demonstrated that AI-assisted tools can identify and leverage these flaws to bypass existing security controls.
Why 10,000 People Played This CTF
The Boss of the Sock (Bots) CTF event attracted 10,000 unique participants last year across more than 150 global events. This vendor-led competition focuses exclusively on Splunk security products and has operated since 2015 with a goal to educate and entertain. While major conferences host around 1,500 attendees, the vast majority of participation occurs in smaller customer-driven sessions of 20 to 30 people. The event structure ensures a safe environment where professionals can test vulnerabilities without disrupting production systems.