vibehacker
News
Malwarebytes ·

Hacktron used Claude Opus 5 to reach OpenAI’s internal GitHub in <72h

White-hat firm Hacktron chained a Discourse/libheif image bug with an OpenAI SSO flaw, then used an employee’s Codex session to open a harmless PR in an internal repo—under 72 hours end to end. Claude Opus 5 built the working exploit overnight after Opus 4.8 failed; OpenAI patched in ~14 hours and paid a $6,500 bounty.

More news

View all

Claude Code 2.1.285: disable WebFetch, admins lock API providers

Claude Code 2.1.285 (npm Sept 29) adds CLAUDE CODE DISABLE WEB FETCH to turn off WebFetch and a managed allowedProviders policy so admins can lock machines to Anthropic, Bedrock, Vertex, Foundry, or a cloud gateway. It also ships claude desktop , claude plugin configure , and a fix for URL passwords leaking past log redaction…

Mixed News

OpenAI MCP Events: ChatGPT plugins react via signed webhooks

OpenAI’s DevDay MCP Events let ChatGPT plugins subscribe to MCP server updates (messages, comments, status) and trigger automations over verified signed HTTPS webhooks. Servers need MCP 2.0 (protocol 2026 07 28) with events/list, events/subscribe, and events/unsubscribe; polling and streaming aren’t supported…

OpenAI

Anthropic: open-weight GLM-5.3 near Mythos on end-to-end exploits

Anthropic finds Z.ai’s freely downloadable GLM 5.3 builds end to end exploits at rates close to Claude Mythos Preview (50/410 vs 56/410 on ExploitBench), while simple jailbreaks and weight abliteration bypass its safeguards 64–100% of the time—unlike safeguarded Claude models in the same tests…

Anthropic

CodeScene: agents refactor 300K-line C game for ~$4k in three weeks

CodeScene’s agents (mostly Claude Code + Opus) refactored a 300K line Street Fighter III decompilation in three weeks for $4k—2,903 commits, Code Health 5.6→10.0—guided by a CodeHealth MCP score and frame by frame replay checks; they also accumulated a 22 recipe refactoring playbook…

InfoQ

Spotted something we missed? Start a thread.