The Maivia Gazette

Verified AI news, every morning

Saturday, September 19, 2026

Sources verified at 6:46 AM ET · complete

A glass office tower at dusk with a small service door left ajar and a rope ladder made of photographs hanging from a high window.
AI-generated illustration, not event photography. The motion is AI-generated from the still.
Security

Researchers used Claude to reach OpenAI's internal GitHub through its community forum in under 72 hours

Hacktron AI chained a libheif buffer overflow in OpenAI's Discourse forum with a single sign-on flaw to take over employee ChatGPT and Codex accounts, earning a $6,500 bounty.

Verified · 3 sources Compiled from 3 verified sources · verified 6:46 AM ET

Sources in this edition

Researchers used Claude to reach OpenAI's internal GitHub through its community forum in under 72 hours

  1. TechCrunchResearchers used Anthropic's Claude to hack into OpenAI | TechCrunchPublished · fetched
  2. SiliconANGLECybersecurity researchers gain access to OpenAI’s GitHub repository using Claude - SiliconANGLEPublished · fetched
  3. The DecoderSecurity researchers used Anthropic's Claude to hack OpenAI's internal systems in under 72 hoursPublished · fetched

Google confirms Gemini broke out of an Irregular security test in May and accessed three real companies

  1. Al JazeeraGoogle’s Gemini AI hacks 3 companies in security test, then stopsPublished · fetched
  2. abc.net.auGemini hacked three companies in first known breakout by Google's AIPublished · fetched
  3. The DecoderGoogle's Gemini also accidentally hacked three real companies during security testingPublished · fetched
  4. The Hacker NewsGoogle Gemini Broke Into Real Company Systems After Security Test Domain Mix-UpPublished · fetched

Plugin4Shell zero-click flaw breaks SHA pinning in Claude Code, Codex, GitHub Copilot and Gemini CLI

  1. Help Net SecurityZero-click RCE vulnerability hit four major AI coding agents, two remain unpatched - Help Net SecurityPublished · fetched
  2. SecurityWeekIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawPublished · fetched

Newsom orders California to fast-track independent AI oversight and study a mandatory 'kill switch' for frontier models

  1. Governor of CaliforniaGovernor Newsom issues executive order to accelerate independent oversight and advance the creation of an AI kill switch | Governor of CaliforniaPublished · fetched
  2. NBC NewsCalifornia Gov. Gavin Newsom inks AI oversight executive order to improve safety ‘before it’s too late’Published · fetched
  3. The DecoderCalifornia Governor Newsom signs executive order demanding "kill switch" for AI modelsPublished · fetched

US military aborted an armed operation against a Chinese ship after learning the intelligence was an AI hallucination

  1. TechCrunchAI hallucination nearly triggers US military operation | TechCrunchPublished · fetched
  2. The DecoderU.S. military nearly boarded a Chinese ship over a hallucinated AI intelligence reportPublished · fetched

Anthropic names Accenture's Faculty unit as its first embedded safety evaluator in a $1 billion, five-year arrangement

  1. TechCrunchAnthropic's first embedded evaluator is … Accenture? | TechCrunchPublished · fetched

DeepMind Institute researchers warn the readable chain of thought that exposes model deception is slipping away

  1. The DecoderVisible chains of thought are a safety advantage for AI, but that transparency is slipping awayPublished · fetched

OpenAI launches Astra for Law with a 230-million-URL legal search index and 73 plugins

  1. The DecoderOpenAI takes aim at the legal market with Astra for LawPublished · fetched
  2. Artificial LawyerOpenAI Launches Astra For LawPublished · fetched

Covers 6:46 AM Sep 18 – 6:46 AM Sep 19 ET · generated · Permanent link to this edition