The report
Hacktron's September disclosure is about a July research chain, not a new September intrusion. The useful part is not the lab-versus-lab framing. It is how several ordinary security boundaries combined into a much larger authority path.
The research began in an image-processing stack. Hacktron says its team used Claude Opus 4.8 and Opus 5 while developing and adapting exploitation for a malformed HEIF/AVIF path that reached Discourse through ImageMagick and `libheif`. The researchers remained in the loop: they selected targets, interpreted failures and steered the work. That makes this AI-assisted security research, not evidence that an autonomous model independently chose and compromised OpenAI.
From a forum foothold to development authority
According to Hacktron's disclosure, the chain progressed from remote code execution on an OpenAI-hosted Discourse forum to administrator capability on that forum. The researchers then report crossing an OpenAI SSO boundary into an employee account.
The most concrete proof of downstream authority was deliberately limited. The team says it used the compromised account's Codex/GitHub access to create a harmless pull request in an internal repository. It also says it did not read internal source code. That distinction matters: an internal pull request demonstrates a write-capable path into development infrastructure, but it does not prove that every other connected service discussed in the disclosure was accessed.
The underlying image-processing issue has a separate vendor record. Discourse advisory GHSA-vhm9-85gw-x335 associates CVE-2026-32882 with malformed HEIF processing and documents remediation. OpenAI, according to Hacktron's chronology, fixed the account-takeover path on July 25; Discourse published its advisory on July 28.
Two caveats are easy to lose in the headline
First, Hacktron's sub-$3,000 token-cost figure refers to a broader multi-company HEIF research effort, not only this OpenAI chain. Second, the later bounty award covered the OpenAI-side finding. It should not be read as blanket authorization for every earlier action against the forum.
Those qualifications do not make the demonstrated chain less important. They make the record more useful. The incident shows how a narrow technical foothold can become much more consequential when identity, coding agents and repository permissions are connected. The security question is therefore larger than whether an AI model can help develop an exploit. It is what authority becomes reachable after the first boundary fails.
September 18 coverage, including Techzine's report, gave the July work a fresh news hook. Digging Beagle keeps the research chronology, the demonstrated actions, the remediation and the unproven reach separate so later reporting does not collapse them into one claim.