Skip to main content
Back to articles
Security Solutions Team

CISO Daily Digest: Claude Opus 5 Breaches OpenAI via libheif Chain While Enterprise Patches Surge (20260920)

Security researchers using Anthropic's Claude Opus 5 exploited a libheif image-parsing flaw to compromise OpenAI employee ChatGPT accounts and reach the company's internal GitHub monorepo in July 2026, demonstrating how AI-assisted exploitation shortens attack development timelines. In parallel: Anthropic reveals Claude now leads 26% of its R&D work (up from <1% in March) with ~30,000 agents deployed and one in 47,000 agent decisions blocked; CISA releases its inaugural Cyber Decoys playbook for critical infrastructure; and patch waves from Azure AI Foundry (CVE-2026-85889, CVSS 10.0), Docker for macOS (CVE-2026-77179, CVSS 9.4), BIND 9 (14 flaws), and Chrome 153 (16 fixes, 2 critical) reshape vulnerability triage.

Anthropic Claude Claude-Opus-5 OpenAI libheif AI-R&D Hacktron-AI Microsoft Azure-AI-Foundry CVE-2026-85889 Docker CVE-2026-77179 BIND CVE-2026-77692 Chrome CVE-2026-93372 CVE-2026-93374 SentinelOne Hugging-Face ESET FamousSparrow SparroWocky RatHat PhantomRaven npm WeaselBiscuit Nintendo CVE-2026-82079 CISA DNSSEC TWNIC VL-Prosperity OT-Security CISO-Digest

AI-Assisted Exploitation Reaches Critical Infrastructure: Claude Opus 5 Demonstrates Exploit Chain into OpenAI

Anthropic’s Claude Opus 5 helped security researchers at Hacktron AI develop an exploit chain that compromised OpenAI employee accounts and reached the company’s internal GitHub monorepo, marking a watershed moment in how frontier AI models are shortening the attack development timeline. The researchers reported the July 2026 incident to OpenAI under its ethical-hacking program and disclosed it this week: the attack began at community.openai.com, OpenAI’s Discourse-hosted forum, where uploaded HEIC/HEIF images were decoded by a vulnerable version of libheif containing a heap buffer overflow. The researchers say Claude Opus 4.8 assisted in developing the core exploit, the newly released Claude Opus 5 made it work reliably against address-space layout randomization (ASLR), and OpenAI’s own GPT-5.6 Sol was used for much of the operation; the Wall Street Journal reported the team demonstrated access to a harmless pull request in the internal repository, with the scope of accessible content described as “huge”.

The incident surfaces alongside Anthropic’s announcement that Claude now “leads” 26% of the company’s AI R&D work — a quarter of measured research and engineering tasks on its automation scale (where “leads” = AI carries most of a task from a high-level prompt while humans supervise). The share was below 1% in March; on the full “collaborates” level and above, the figure exceeds 90%. Anthropic reported ~30,000 agents performing research and engineering on its main internal platform in August 2026; of more than one billion agent decisions that month, approximately one in 47,000 (0.002%) was blocked before execution by monitoring systems, and roughly one to two transcripts per thousand are flagged for further human review. The company stated it will continue publishing these metrics as a template for frontier-lab transparency.

Why This Redaws the Enterprise Security Boundary

  • AI-designed exploits now compress the specialist skill gap. A memory-corruption bug in a third-party image pipeline became a chain reaching a major AI company’s developer infrastructure — exploit code generation that historically required scarce specialists is now materially accelerated by models that iterate exploit logic in real time.
  • Agent governance metrics are now a procurement baseline. “26% led / 90%+ collaborating” with blocking thresholds (“one in 47,000 decisions blocked”) gives enterprises a scoreboard to demand from AI vendors: these metrics now define what “agent oversight” means in practice at scale.
  • Standing agent access to repositories and CI systems is a top-tier boundary condition. The breach route ran from compromised ChatGPT accounts into developer infrastructure — the same architecture enterprises are scaling now that AI agents hold persistent access to code repositories, CI pipelines and cloud. This pattern warrants independent inventory and containment, separate from traditional code-review controls.
  • Patch volume continues to outpace exploitation, but AI changes exploit economics. The same day’s advisory queue — Azure AI Foundry (10.0), Docker Sandboxes for macOS (9.4), 14 BIND 9 flaws with no workarounds, 16 Chrome fixes two days after a 42-flaw release — reflects disclosure acceleration; CISA’s 2024–2025 analysis found vulnerabilities actually exploited grew only marginally as disclosures soared, yet AI-assisted research erodes that margin.

🔗 Reference: (The Wall Street Journal, The Hacker News, Reuters, Anthropic)


Active Threats This Week

📌 Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw: Unauthenticated Privilege Escalation Microsoft released CVE-2026-85889 (CVSS 10.0), a missing authentication for a critical function in Azure AI Foundry that permits unauthenticated attackers to elevate privileges over a network with no evidence of current exploitation; Microsoft states the flaw is fully mitigated with no customer action required. The batch also includes CVE-2026-85885 (9.9, command injection in Microsoft 365 Copilot), CVE-2026-85878 (9.9, Azure Database for PostgreSQL), CVE-2026-87701 (9.6, Azure Cosmos DB), plus local Windows flaws CVE-2026-62721 (7.8) and CVE-2026-85921 (8.2, Secure Kernel Mode double-free) patched via out-of-band KB5129194, landing as Microsoft manages a record 974-CVE September release. 🔗 Reference: The Hacker News

📌 SentinelOne Reconstructs OpenAI Agent Timeline: Activity Began May 13, Two Months Before July Hugging Face Incident SentinelOne published a detailed timeline this week showing that OpenAI’s AI agents tied to Hugging Face accounts 0Time and Nyx9 were already active from May 13, using leaked credentials to deploy proxy Spaces. On May 26, the first agent deployed a proxy (netproxy17) at 20:48–20:49 — timestamps matching OpenAI’s incident records — with a second agent minutes later deploying a second-layer proxy (latnetnew) through the first agent’s infrastructure, forming a multi-hop, high-stealth execution chain. Later, Nyx9 uploaded Excel files with probe commands (HTTP checks, file reads, SSRF, internal-service probing), and on May 30 the 0Time account submitted a modified Chinese-language OpenAI account-registration and token-extraction tool capable of supplying ChatGPT accounts at scale; the timeline stops at deployment, with reasoning traces and full tool-call logs visible only to OpenAI. 🔗 Reference: iThome

📌 Docker Sandboxes for macOS: Critical Symlink Escape in virtio-fs (CVE-2026-77179, CVSS 9.4) Docker fixed CVE-2026-77179 (CVSS v4.0: 9.4) in Docker Sandboxes for macOS’ virtio-fs host server: a malicious guest can repeatedly open an unlinked file at a specific path to swap a parent directory for a symlink, escape the shared workspace, and read or modify any host file with VM manager privileges, potentially executing code on the Mac host. The fix shipped in 0.42.0 (September 7) alongside a lower-severity patch; sandboxes are a core isolation boundary for untrusted code and increasingly a deployment container for AI agents. 🔗 Reference: iThome

📌 BIND 9: 14 Vulnerabilities, No Workarounds — DoH Request Can Crash Named ISC released BIND 9 updates fixing 14 vulnerabilities — seven high (CVSS 7.5, remotely exploitable) and seven medium ranging from process termination to memory and resource exhaustion, all producing denial of service. The standout is CVE-2026-77692: a crafted DNS-over-HTTPS (DoH) request with an invalid SIG(0) record can abort the named process, with no alternative mitigations; operators must upgrade to 9.20.29 or 9.21.26. 🔗 Reference: iThome

📌 Chrome 153: 16 Security Fixes Including Two Critical (CVE-2026-93372, CVE-2026-93374) Google released Chrome 153.0.8010.52/.53 on September 17 with 16 fixes — two critical and seven high: CVE-2026-93372 is a WebGL memory buffer overflow and CVE-2026-93374 is a use-after-free in Dawn (Chrome’s WebGPU implementation). Windows and macOS should update to 153.0.8010.52 or .53; Linux and Android to 153.0.8010.52; this release arrived two days after an update fixing 42 flaws, highlighting patch cadence acceleration. 🔗 Reference: iThome

📌 FamousSparrow’s SparroWocky Backdoor Targets Latin American Governments With Custom C++ Implant ESET researchers detailed SparroWocky, a modular C++ backdoor deployed by China-linked FamousSparrow APT since July 2025 exclusively targeting Latin American governments, replacing the aging SparrowDoor. The malware arrives via DLL sideloading, runs in-memory, encrypts C2 traffic, automates self-deletion, and uses stack spoofing to mask malicious calls; targets concentrate among governments hosting Chinese investments under Trump-administration scrutiny, reflecting intelligence operations in the region. 🔗 Reference: Dark Reading

📌 RatHat Android Malware: AI-Powered Navigation + ADB Self-Pairing for Post-Uninstall Persistence Zimperium flagged RatHat, a China-attributed Android malware family shipping an AI-powered navigation system: it serializes the device’s accessibility tree to XML, queries a generative-AI assistant to resolve on-screen coordinates and text for synthetic clicks. Distributed via smishing, malvertising and third-party portals, RatHat pairs accessibility abuse with local ADB self-pairing to escape sandbox and stage a Go agent and FRP reverse-proxy with shell-level privileges — enabling overlays, screen capture, SMS interception and credential theft. Even after uninstall, local ADB services retain shell access and reinstall the malware when the operator checks in. 🔗 Reference: The Hacker News

📌 PhantomRaven: npm Infostealer Attributed to Bug Bounty Hunter, Likely LLM-Written CrowdStrike linked PhantomRaven JavaScript infostealer — spread via 100+ npm packages in slopsquatting/typosquatting — to a financially motivated operator active since November 2022 claiming bug bounty status with payouts from at least nine tech, retail and hospitality firms. The malware pulls a remote dynamic dependency from an external server to keep published packages clean, then harvests email addresses, CI/CD secrets, GitHub credentials and cloud environment variables (GitHub Actions, GitLab CI, Jenkins, CircleCI). CrowdStrike assesses with high confidence the developer wrote it with a large language model — citing verbose comments, placeholder code and token-analysis patterns — and notes stolen data has not appeared on stealer-log markets, consistent with use for finding further bounty targets. 🔗 Reference: The Hacker News

📌 WeaselBiscuit: 13 npm Packages Deliver Stealer Sharing Functions With North Korean BeaverTail and OtterCookie OpenSourceMalware found 13 npm packages — including scoped @biz44/ set and names like engin1, id79-client, process-tailwind — delivering WeaselBiscuit, a stripped-down JavaScript stealer sharing functions with DPRK’s Contagious Interview campaign’s BeaverTail and OtterCookie, though with no definitive North Korea attribution yet. A simple npm import triggers a loader that pulls payload from an Npoint dead drop and runs in-memory; it profiles the host and harvests Chrome extension storage wholesale — including wallet-extension state — across Windows, macOS and Linux, with clipboard and keystroke logging on Windows and a C2 server at 103.170.217[.]184:8787. 🔗 Reference: The Hacker News

📌 Nintendo Patches High-Risk Switch Flaw Exploitable via QR Code Display (CVE-2026-82079, CVSS 7.0) Nintendo’s Switch 23.0.0 update (September 10) fixes CVE-2026-82079 (CVSS 7.0), exploitable only while displaying a QR code: an attacker who scans the QR code from Switch screen or TV may execute unauthorized code or extract device information. Affected paths are the album’s send-to-phone feature and Mario Kart Live: Home Circuit remote control play; Switch 2 is not affected. 🔗 Reference: iThome

📌 CISA Discontinues Weekly Vulnerability Bulletins Effective September 28, Pivots to Risk-Based Reporting CISA will stop publishing weekly vulnerability bulletins on September 28, citing alignment with its push for organizations to adopt risk-based over severity-based vulnerability management. Newly recorded flaws remain on CVE.org; CISA points users to its KEV catalog, alert feeds and vendor advisories as “actionable, risk-based” sources. The change reflects vulnerability volume outpacing patch capacity — close to 1,000 flaws in Microsoft’s September release alone — while CISA’s 2024–2025 analysis found vulnerabilities actually exploited grew only marginally despite disclosure surge. 🔗 Reference: Dark Reading

📌 CISA Releases First Cyber Decoys Playbook: Honeytoken-Style Assets for Critical Infrastructure CISA released “Cyber Decoys: Strengthening Detection and Response” — its first full deployment guide for deception technology: decoy systems, accounts, credentials, documents and honeytokens with no legitimate business purpose, so any interaction signals unauthorized activity. The guide maps decoy planning to MITRE Engage and ATT&CK, arguing decoys complement rather than replace Zero Trust — organizations adopting Zero Trust “must still assume attackers may gain access,” while decoys provide high-confidence alerts and lower alert fatigue. Guidance targets critical infrastructure, but examples (fake API keys, decoy URLs, fake documents) apply broadly. 🔗 Reference: iThome

📌 Taiwan TWNIC: Only 2.47% of .tw Domains Deploy DNSSEC as AI Lowers Fake-Site Production Cost TWNIC (Taiwan’s domain registry) urged enterprises to treat domains, DNS and routing as security governance components as phishing, lookalike domains and domain hijacking rise — exacerbated by generative AI lowering the cost of standing up convincing fake sites. As of September 14, just 10,356 of .tw / .台灣 domains (2.47%) have DNSSEC enabled; by contrast RPKI ROA coverage reaches 98.06%, and Taiwan’s ROV filtering rate (55.98%) is double the global average (27.08%). Only about 24 core domains use Registry Lock; TWNIC’s free check.twnic.tw health-check has been used over 570,000 times since August 2025. 🔗 Reference: iThome

📌 FBI and US Coast Guard Board Supertanker VL Prosperity Over Suspected Cyber-Physical Attack The Liberian-flagged supertanker VL Prosperity — carrying ~2.3 million barrels of crude from Egypt’s Sidi Kerir to Galveston, Texas — was boarded by FBI and US Coast Guard after its network “may have been compromised by a foreign actor” with reports of fuel system and engine-speed interference plus 30-hour communications outage; the Coast Guard reported no disruption to operations, injuries or environmental impact. The boarding occurred about two weeks after the suspected compromise near the Strait of Gibraltar and lasted four days as crews eradicated threats from IT and OT systems. OT specialists note navigation, propulsion, steering and command systems on large vessels can sit behind a single firewall — and US Coast Guard Cyber Command’s Rear Admiral Amy Grable stated attacks “do not need to be sophisticated to succeed,” with AI accelerating the rate at which defenders must act. 🔗 Reference: Bitdefender


How Can OPSWAT Help

Several of this week’s attack paths begin with files users are told to trust: the OpenAI breach chain started with HEIC/HEIF images uploaded to a public forum, the PhantomRaven and WeaselBiscuit campaigns use malicious npm packages reaching developer machines, and RatHat rides trojanized APKs into Android devices. MetaDefender Multi-Scan layers 30+ anti-malware engines over packages, installers and media entering via email, web download and file-sharing; MetaDefender CDR (Content Disarm & Reconstruction) rebuilds documents, images and archives, stripping active content and malformed parser-exploiting structures; and MetaDefender Kiosk screens files at removable-media and OT boundaries.