Hacktron is an autonomous vulnerability hunter for ambitious engineering teams. Built by world-class security researchers. Powered by one principle: PoC || GTFO

Latent Space
Introducing Hacktron Review: an AI security reviewer for your pull requests. It understands your whole codebase, builds a threat model, takes your feedback, and catches exploitable vulnerabilities before they reach production. Try for free: app.hacktron.ai
22
42
278
70,183
👀👀
heif heist? @HacktronAI moving exploitation base to san francisco hit us up, would love to meet people.
1
1
14
1,738
Hacktron AI retweeted
𝗬𝗼𝘂 𝗻𝗼𝘄 𝗴𝗲𝘁 𝘁𝗼 𝘀𝗲𝗲 𝘄𝗵𝗮𝘁 𝗼𝘂𝗿 𝗮𝗴𝗲𝗻𝘁𝘀 𝗱𝗼 𝘄𝗶𝘁𝗵 𝗲𝘃𝗲𝗿𝘆 𝗽𝗼𝘁𝗲𝗻𝘁𝗶𝗮𝗹 𝗳𝗶𝗻𝗱𝗶𝗻𝗴 Our new Whitebox Pentest UI makes dynamic validation easier to follow. Watch our agents authenticate through the live browser preview, then see the actions they take to determine whether an issue can be reproduced against your running application and verify its impact. Each validation returns a verdict with the relevant source references. Less guesswork. More evidence. Live now at app.hacktron.ai
2
2
26
1,286
𝗛𝗮𝗰𝗸𝘁𝗿𝗼𝗻 𝗶𝘀 𝗻𝗼𝘄 𝗦𝗢𝗖 𝟮 𝗧𝘆𝗽𝗲 𝗜𝗜 𝗰𝗼𝗺𝗽𝗹𝗶𝗮𝗻𝘁 🎉 This means greater assurance over how we protect data and operate our systems. Next up: 𝗖𝘆𝗯𝗲𝗿 𝗧𝗿𝘂𝘀𝘁 𝗠𝗮𝗿𝗸, 𝗜𝗦𝗢 𝟮𝟳𝟬𝟬𝟭 𝗮𝗻𝗱 𝗖𝗥𝗘𝗦𝗧 as we continue strengthening the standards behind how we operate and deliver security services.
3
2
54
2,886
We Hacked OpenAI. Here's what didn't fit in 90 seconds: → OpenAI was only one target. It was part of a bigger research project we call the HEIF Heist → 2 months, 3 researchers, under $3,000 in AI tokens → The bug we used had already been fixed upstream. It just never got a CVE, so it never got patched downstream → The older Claude model got stuck. Claude Opus 5 cracked it within hours of release → OpenAI paid us $6,500 for the finding :). The scary part isn't OpenAI. They fixed it in 14 hours. It's every other company running the same image software, still unpatched, with no CVE telling them to care. Harsh, Mohan and Rahul wrote up everything. Visit - Hacktron.ai/blog/hacking-ope…
6
15
154
8,778
A single malicious image led to demonstrated access to an internal OpenAI repository 👇 This is the exploit chain that took our researchers from a vulnerable libheif dependency in the OpenAI Community forum to internal repo access. Full technical breakdown: hacktron.ai/blog/hacking-ope…
4
30
235
9,928
Hacktron AI retweeted
"3 random dudes” 1. hacked apple, again and again. httpvoid.com/Apple-RCE.md httpvoid.com/Hello-Lucee!-Le… httpvoid.com/Hacking-Apple-w… 2. your github enterprise is our github enterprise. httpvoid.com/GitHub-Enterpri… 3. get a discord message from me, get pwned. hacktron.ai/blog/discord-rce piped.video/watch?v=R3SE4VKj… 4. oh yeah, at one point we basically had shells across the electron ecosystem. check the DEF CON research. media.defcon.org/DEF%20CON%2… 5. your supabase database is my database. hacktron.ai/blog/supapwn 6. we got the posthog prod database. hacktron.ai/blog/posthog-rce 7. react2shell? vercel paid us $170k for helping secure their waf. hacktron.ai/blog/react2shell… 8. your palo alto vpn is my vpn. hacktron.ai/blog/cve-2026-02… 9. ai ides? we got shells for you, antigravity hacktron.ai/blog/hacking-goo… 10. windsurf rce. piped.video/watch?v=23Mz7qcR… 11. turning cluely into malware. hacktron.ai/blog/hacking-clu… 12. ai browsers? sure, uxss: your perplexity browser is my browser. hacktron.ai/blog/perplexity-… 13. openai atlas too. kinda uxss hacktron.ai/blog/hacking-ope… 14. hey, it’s not even our first time hacking discourse. projectdiscovery.io/blog/dis… 15. adobe coldfusion: pre-auth rce. because apparently we needed another one. projectdiscovery.io/blog/ado… there’s a lot more. go dig. anyway, yes: “3 random dudes.” and @HacktronAI is full of more random dudes like these.
69
239
2,087
178,756
We are not stopping at OpenAI. Today we’re publishing HEIF Heist, a months-long investigation by our security research team into vulnerabilities in libheif. The research uncovered attack paths affecting OpenAI, Slack, Meta, GitHub Enterprise, Rails, Next.js, ImageMagick and others. heif-heist.com
15
105
818
48,320
We’ll be disclosing the technical details behind the major affected platforms and projects over the coming weeks at: hacktron.ai/blog?utm_source=…
1
1
11
1,350
Research by @rootxharsh, @S1r1u5_, and @iamnoooob.
We’re disclosing HEIF Heist, a months-long investigation into libheif that allowed us to hack OpenAI, Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick, and many more. It was literally xkcd #234, one obscure image library beneath a huge number of apps. 🧵
1
14
1,506
Our OpenAI research made the Wall Street Journal. AI safety and cybersecurity are converging fast. Read here 👇
A bug-hunting independent security research team used Anthropic’s Claude software to gain access to an OpenAI employee’s ChatGPT account, giving them a way to read and suggest changes to the company’s private cache of software. on.wsj.com/4h8vaBP
10
13
215
16,831
Hacktron AI retweeted
How many companies can you hack through an image parser? We spent the last few months finding out. OpenAI was one. So were Slack, Meta, GitHub Enterprise, Rails, Next.js, ImageMagick, and many more. We called it HEIF Heist. 📷
10
19
305
15,207
Hacktron AI retweeted
We’re disclosing HEIF Heist, a months-long investigation into libheif that allowed us to hack OpenAI, Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick, and many more. It was literally xkcd #234, one obscure image library beneath a huge number of apps. 🧵
47
426
3,234
556,405
Hacktron AI retweeted
A bug-hunting independent security research team used Anthropic’s Claude software to gain access to an OpenAI employee’s ChatGPT account, giving them a way to read and suggest changes to the company’s private cache of software. on.wsj.com/4h8vaBP
65
212
1,054
510,266