Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
IT Security NachrichtenUS sanctions Tren de Aragua gang members in ATM hacks crackdown(02.10.2026 um 17:20 Uhr)
•
IT Security NachrichtenBarracuda bringt KI-Governance und Datenschutz für Unternehmen zusammen(02.10.2026 um 17:38 Uhr)
••
IT Security NachrichtenGitHub-Code: 543.699 gültige Zugangsdaten - it-daily(02.10.2026 um 17:02 Uhr)
•••
IT Security NachrichteniPhone Duo: Apple bestätigt spezielle austauschbare Display-Schicht(02.10.2026 um 17:33 Uhr)
•
IT Security DownloadsSecurity Starts with Hardware(02.10.2026 um 17:38 Uhr)
•
IT NachrichtenGalaxy S25 Ultra One UI 9 Updates: US Unlocked Models(02.10.2026 um 17:25 Uhr)
••
IT Security NachrichtenUS sanctions Tren de Aragua gang members in ATM hacks crackdown(02.10.2026 um 17:20 Uhr)
•
IT Security NachrichtenBarracuda bringt KI-Governance und Datenschutz für Unternehmen zusammen(02.10.2026 um 17:38 Uhr)
••
IT Security NachrichtenGitHub-Code: 543.699 gültige Zugangsdaten - it-daily(02.10.2026 um 17:02 Uhr)
•••
IT Security NachrichteniPhone Duo: Apple bestätigt spezielle austauschbare Display-Schicht(02.10.2026 um 17:33 Uhr)
•
IT Security DownloadsSecurity Starts with Hardware(02.10.2026 um 17:38 Uhr)
•
IT NachrichtenGalaxy S25 Ultra One UI 9 Updates: US Unlocked Models(02.10.2026 um 17:25 Uhr)
••
Intelligence View
⚡ tsecurity.de Intelligence

LiveOverflow: OpenAI Hacked with a 1-Year-Old Bug

Video von LiveOverflow auf YouTube: How could OpenAI be hacked with a vulnerability that had already been fixed for a year? Follow the dependency chain from…

HD Video
OpenAI Hacked with a 1-Year-Old Bug
Video abspielen
Beitrag
0
Seite
0
↗ Quelle (LiveOverflow)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!

YouTube Video

How could OpenAI be hacked with a vulnerability that had already been fixed for a year? Follow the dependency chain from Discourse through ImageMagick, libheif, and Debian to see why security fixes can take so long to reach the applications that depend on them.



SPONSOR

This video is sponsored by Hextree.io, our cybersecurity learning platform.



LEARN ON HEXTREE (ad)

Learn hacking on Hextree: https://www.hextree.io/

Join the Hextree Discord: https://discord.gg/xgQpCQCpvy



RESOURCES

Previous video, How OpenAI got hacked with an image: https://www.youtube.com/watch?v=gjHh9g7yo9Y

Harsh on X: https://x.com/rootxharsh

xkcd, Dependency: https://xkcd.com/2347/



CHAPTERS

00:00 - Identify Research Target

03:04 - Checking the Installed libheif Version

04:49 - Why the Fix Took So Long to Reach OpenAI

08:07 - How Discourse Inherited an Outdated libheif

09:03 - Pinning and Maintaining Security-Critical Dependencies



SUPPORT

Per video: https://www.patreon.com/join/liveoverflow

Per month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

Buy my handwriting font (ad): https://shop.liveoverflow.com/



WATCH, FOLLOW & READ

Second channel: https://www.youtube.com/LiveUnderflow

Twitch: https://twitch.tv/LiveOverflow/

Twitter: https://twitter.com/LiveOverflow/

Instagram: https://instagram.com/LiveOverflow/

TikTok: https://www.tiktok.com/@liveoverflow_

LiveOverflow blog: https://liveoverflow.com/

Hextree blog (ad): https://www.hextree.io/blog



#SupplyChain #ApplicationSecurity #LiveOverflow



(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
Zum Aktualisieren ziehen
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag