Connect with us

News

Apple says former employee exploited ‘rare’ bug to download confidential files after leaving for OpenAI

info

Published

on

Apple ghost logo.jpg

On Friday, Apple dropped the bombshell news it was suing OpenAI over the alleged theft of trade secrets, claiming that OpenAI stole Apple’s confidential data and engaged in efforts to learn proprietary information while recruiting former Apple employees.

In accusing OpenAI of stealing secrets about Apple’s unreleased products, Apple revealed that a former employee allegedly siphoned reams of sensitive files from the company’s shared network folders, weeks after leaving Apple for a job at OpenAI.

In its complaint, Apple says the former employee, a system electrical engineer named  Chang Liu, allegedly “exploited a rare, previously unknown authentication bug” that allowed access to the company’s network. The bug is classified as a zero-day vulnerability, meaning that Apple had no time to fix it before it was allegedly exploited.

Apple has since fixed the bug and said it terminated the employee’s access once it learned of this “security breach.” In its complaint, Apple said the bug could have allowed a “few other” people to access data on its network, but alleged that only Liu exploited the bug to steal Apple’s confidential information while no longer an employee, citing a check of its server logs. 

The disclosure, while light in detail, highlights the challenges that organizations face with protecting sensitive corporate data after employees no longer work there. Companies often move to immediately cut off departing staff from further access to protect any sensitive information from leaving, including inadvertently. Companies that fail to fully decommission their employees’ accounts can face future security lapses, data breaches, or malicious actions by disgruntled staff.

Apple spokespeople did not respond to an email from TechCrunch with questions about the security vulnerability, how it was exploited, and when the company decommissioned the employee’s credentials.

“LOL… so funny.”

In the complaint, Apple alleged that Liu took “dozens of Apple’s confidential hardware-related files” over the course of several weeks while as a new OpenAI employee. 

Apple said the files contained “detailed information about unreleased products, engineering presentations, technical specifications, and proprietary project data.” 

The company claims Liu failed to return the Apple-issued work laptop he had previously used to access Apple’s network, suggesting it was once able to send and receive files from Apple’s internal systems. The complaint said that Liu allegedly claimed to have “another computer.” While he was at OpenAI, Liu also allegedly misused the access of an acquaintance, Yu-Ting Peng, a then-Apple employee who later went to work for OpenAI. Liu allegedly used Peng’s Apple-issued work laptop “while she was still employed at Apple and he was not.”

Apple said that during February 2026, Liu “tried to access Apple’s network storage — a cloud-based file repository containing Apple’s confidential engineering files, project documentation, and other proprietary information.”

Liu had allegedly discovered that he “still could access Apple’s network repository after leaving Apple, the result of a then-unknown authentication vulnerability.”

Apple did not describe the authentication “bug” that Liu allegedly used to access Apple’s network. However, authentication bugs generally refer to flaws in the login process that allow improper access to systems or data, either because of a weakness in how the login mechanism works or due to a misconfiguration, such as overbroad permissions or not decommissioning the login credentials of a former employee. 

Apple wrote in its complaint that when Liu learned he had unauthorized access to Apple’s systems, he did not report the bug to Apple under his employment agreement obligations, nor did he return his Apple-issued work laptop. 

The complaint added that Liu also failed to “delete the program that allowed the access” to Apple’s network. The company did not say what program or app that Liu allegedly used to access Apple’s systems. It’s not uncommon for employees to have tools, such as a work-approved VPN or remote-viewing app, that allow them to access sensitive data from outside of the company’s offices using their credentials.

Given that Liu was previously granted credentials to Apple’s network as an employee, TechCrunch asked Apple when the company decommissioned Liu’s access, but we did not hear back.

Once Liu allegedly gained access to the network share, he wrote to Peng: “LOL, I found out I can access the [network storage], so funny.”

Apple filed its suit in the U.S. District Court for the Northern District of California in San Jose, and has demanded a jury trial. OpenAI previously said it has “no interest in other companies’ trade secrets.”

The case, if it proceeds, could begin this year.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

News

I contested against INEC in 2023 – SDP chieftain, Adebayo

info

Published

on

By

Adewole Adebayo.jpeg

Presidential candidate of the Social Democratic Party, SDP, Adewole Adebayo, says he contested the 2023 general elections against the Independent National Electoral Commission, INEC.

Adedayo made this claim during a live appearance in an interview programme on Channels Television’s ‘Sunday Politics’.

He blasted the outcome of the 2023 elections, alleging that it was marred by fraud and the legitimization of false figures by the electoral umpire.

The presidential candidate expressed a desire for the 2027 polls to be different, calling on the electoral body and the security operatives to be impartial entities rather than opponents.

“In 2023, I contested against INEC. INEC was the opponent. It’s like you allow a bank robber to count the money stolen from the bank, and you say that’s his profit. So what happened in 2023 was not good at all. All those numbers were fake.

“The difference I would want now, hopefully I pray for the INEC chairman, Joash Amupitan, Electoral Commissioners and other staff, that this time around no candidate should see INEC as an enemy.

“So if it is candidate versus candidate, then we are ready. But there is no candidate who should be unfortunate enough to be running against INEC, like we were running against INEC in 2023, and that is what we need to change.

“And I pray that we pay attention to that and we become serious to run for an election. It’s like to write an exam, your score to reflect your effort, and that is it,” he said.

Continue Reading

Business

NAICOM Announces Successful Completion of Insurance Sector Recapitalization Exercise

info

Published

on

By

The National Insurance Commission,(NAICOM),  today announced the successful completion of the twelve-month insurance sector recapitalization exercise.

In pursuant to Section 15 and other relevant provisions of the Nigerian Insurance Industry Reform Act (NIIRA) 2025, signed into law on 31 July 2025 by His Excellency, President Bola Ahmed Tinubu, a as part of his administration’s financial sector transformation agenda towards the attainment of a US$1 trillion economy by 2030.

The successful conclusion of the exercise marks a defining milestone in the transformation of Nigeria’s insurance industry and signals the beginning of a new era for insurance in the country.

It represents a major step towards building a stronger, more resilient, adequately capitalized, professionally governed, and policyholder-focused insurance sector that is better positioned to support national economic growth, deepen financial inclusion, mobilize long-term investment capital, and contribute meaningfully to the stability of Nigeria’s financial system.

Following the enactment of NIIRA 2025, the Commission commenced a structured implementation process to provide strategic oversight, ensure transparency, support operators throughout the transition, and facilitate the effective implementation of the new minimum capital requirements within the statutory compliance period.

To ensure an orderly, transparent, credible, and verifiable process, the Commission issued the Guidelines on the Implementation of Minimum Capital Requirements (MCR) for Insurance and Reinsurance Companies in Nigeria. The Guidelines provided detailed guidance on the statutory minimum capital requirements under NIIRA 2025, eligible and ineligible capital instruments, admissible and non-admissible assets, verification and validation procedures, regulatory timelines, reporting obligations, and supervisory expectations throughout the implementation period.

Through a comprehensive process of review, verification, and validation, the recapitalization exercise has delivered a major boost to the Nigerian insurance industry. It has enhanced the financial resilience of operators, attracted substantial domestic and foreign investment, and rekindled strong investor confidence.

The verified outcome of the exercise indicates that Forty-three (43) insurance and reinsurance companies successfully met the prescribed Minimum Capital Requirements. However, Eight (8) insurance companies that submitted evidence of compliance shortly before the statutory deadline are currently undergoing final verification and regulatory review. This would be concluded within fourteen days.

Nigeria’s insurance industry is now entering a new phase of development founded on stronger capital, improved financial resilience, and enhanced capacity to underwrite larger and more sophisticated risks across strategic sectors of the economy.

The increase in minimum capital will improve insurers’ ability to honour policyholder obligations promptly, absorb emerging risks, support infrastructure and other long-term investments, and compete more effectively within regional and global insurance markets.

The recapitalization exercise also provides a stronger foundation for enhanced risk-based supervision by the Commission, ensuring that regulatory capital remains appropriately aligned with the nature, scale, complexity, and risk profile of each licensed operator.

The Commission reassures policyholders, investors, insurance operators, development partners, and the general public that, as the implementation of NIIRA 2025 continues alongside the modernization of Nigeria’s insurance ecosystem through innovation, technology, and digitization, the Commission will continue to strengthen consumer protection, promote sound market conduct, and accelerate insurance penetration across the country.

Our unwavering commitment remains to build a fair, stable, innovative, inclusive, and globally competitive insurance market that inspires public confidence and delivers lasting value to policyholders and the Nigerian economy.

The Commission will continue to engage stakeholders and provide regular updates on post-recapitalization supervisory actions, companies undergoing final verification, industry restructuring developments, implementation of the Risk-Based Capital Framework, and other strategic initiatives designed to deepen insurance penetration and strengthen confidence in the Nigerian insurance industry.

The National Insurance Commission expresses its profound appreciation to the Federal Government, regulatory and supervisory partners, shareholders, investors, operators, professional bodies, development partners, and all stakeholders whose cooperation and commitment contributed to the successful completion of this historic exercise. The Commission looks forward to even stronger collaboration as Nigeria enters a new era of insurance.

The successful completion of this recapitalization exercise is not the destination but the foundation. It marks the beginning of a new era in which stronger institutions, stronger governance, and stronger public confidence will make insurance work better for every Nigerian.

The post NAICOM Announces Successful Completion of Insurance Sector Recapitalization Exercise appeared first on Business Today NG.

Continue Reading

Trending