One Malformed Photo Put OpenAI’s Private Repository Within Reach

The upload bug lived in a third-party forum. The blast radius grew because a community sign-in token carried access into employee AI accounts and GitHub.

The upload bug lived in a third-party forum. The blast radius grew because a community sign-in token carried access into employee AI accounts and GitHub.
Defences watched package installation. The payload stayed quiet until an application used a normal B-tree method.
DirtyAH6, TUNderflow, PPPoEject and DiagSpill reach different kernel subsystems. One mitigation does not cover all four.
The fixes were real, but there was no update button for customers. The affected layer sat inside Microsoft's cloud control plane.
Gyazo stored far more than pictures. Attackers obtained user records, OCR text, location data and information used to construct image URLs.
The attackers reached operational settings. Operators disabled remote access, while officials said water delivery and public safety were not affected.
The employee had left. The token had not. GitHub traced the access path back to the wider TanStack supply-chain incident.
Four coding agents trusted a commit hash but did not verify the code that Git actually placed in the working tree.
The repositories copied more than 40 brands. The payload then used a trusted driver to remove the tools most likely to stop it.
The systems that manage firewalls and collect their logs have a network-reachable stack overflow before authentication.