GitHub

Illustration for the Hacktron OpenAI bug bounty story
securitymodels

Researchers used Claude to breach OpenAI and earned $6,500

Three researchers at the startup Hacktron AI used Anthropic's Claude to compromise OpenAI accounts through OpenAI's own bug bounty program, and were paid $6,500. On 25 July 2026 they chained two critical flaws, a bug in an image library used by OpenAI's community forum and a misconfiguration in OpenAI's single sign-on, obtaining the ChatGPT accounts of multiple OpenAI employees, including one whose Codex was connected to OpenAI's GitHub organization. They opened a single pull request in OpenAI's internal repository and stopped. Claude Opus 4.8 failed to produce a working exploit across several sessions; Opus 5 solved the same problem within hours of release. The full chain took under 72 hours, and the team says human guidance remained important throughout.

Illustration for the Plugin4Shell coding agent vulnerability story
securityproducts

One flaw hit Claude Code, Codex, Copilot and Gemini CLI

Security lab AIR published Plugin4Shell on 17 September 2026, a zero-click remote code execution flaw present in all four major AI coding agents. Plugin marketplaces pin plugins to an exact 40-character commit hash, but the agents never verify that the checked-out code matches that hash. For Claude Code, Codex and Copilot an attacker makes a branch named after the hash the repository default; for Gemini CLI the default branch is named FETCH_HEAD. Because Claude Code and Codex update plugins in the background by default, no user action is required. Anthropic patched Claude Code in 2.1.179 and OpenAI patched Codex in 0.146.0. Microsoft has shipped no Copilot fix. Google deprecated Gemini CLI and will not patch it.

Illustration for the Claude Code commit links story
productsopen source

Claude Code adds a session link to every commit by default

Developers on r/ClaudeAI and GitHub noticed that Claude Code appends a session URL (claude.ai/code/session_...) to every commit message and pull request description it creates. The behavior is on by default and is not mentioned during onboarding, so many users discovered the links only after they had accumulated in repository history. Several GitHub issues asked for it to be opt-in; a dedicated sessionUrl opt-out switch shipped in version 2.1.183, configurable through the attribution block in settings.json.

Illustration for the GitHub outage story
infrastructureproducts

GitHub was down for eight hours and its CTO said "we let you down"

On August 17, 2026 GitHub served elevated errors from 13:28 to 21:15 UTC, 7 hours and 47 minutes, across Issues, Pull Requests, the API, Actions and Copilot. Web and API error rates peaked near 20 percent, raw content downloads near 50 percent, and Copilot authentication kept failing after other services recovered. In an account published August 20, CTO Vladimir Fedorov wrote: "If you were trying to ship software that day, we let you down." Neither incident came from a code or config change; the platform failed to scale with demand, with autoscaling problems and a retry storm from VS Code clients making it worse. GitHub now handles about 2.9 billion commits a month, up from 1.4 billion in April.