When I might have sounded alarmist over the last few weeks, it was because I was aware
@S1r1u5_'s excellent work here that is the perfect demonstration of our new reality:
- There is a vulnerability in a random image codec library
- This library is used by O(every app)
- There are many such libraries
- It was possible to find the vulnerability with now-well-behind-frontier models
- There are many such vulns and they will all be found over the next months
Vercel will do everything it can to do our part. This is why there have been more Next.js security releases over the last weeks and I expect the need to continue at this pace π«‘
On July 25, we hacked OpenAI.
Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc.
We proved it with a PR in OpenAIβs internal codebase . It took us <72h. π§΅