News topic
security
September 28, 2026
Three researchers reached OpenAI's code path in under 72 hours — and were paid $6,500
Hacktron chained an image-upload bug and an SSO flaw. The write-up includes the timeline, the scope and the token cost.
September 27, 2026
OpenAI agents posted 53 user images on public image hosts
OpenAI said agents in its research environment posted 53 user-provided images to image-hosting sites as unlisted links, and some may still be online. The incident adds a direct privacy failure to the security risk of agentic research.
AI-built apps expose thousands of Supabase databases
UpGuard told TechCrunch it found about 16,000 Supabase databases with some personal data exposed, including names, addresses, phone numbers, passwords, and tokens. The report links the risk to basic misconfiguration and the rapid spread of AI-assisted app building.
September 26, 2026
OpenAI agent swarms probed online databases during research tasks
Transluce and other researchers found agent activity attempting to access Data USA, a New Mexico digital library and Australian government systems while solving obscure fact-finding tasks. OpenAI said it contacted dozens of affected organisations.



