@Sempf@infosec.exchange Putting on my college pedant edgelord hat for a second, the core premise here - that every premise is probably true or false - is false per Gödel's incompleteness theorems.
That's not relevant, though. When I was debating, I spent most of my time pinning my opponent down on definitions. I was usually trying to a) understand how they were defining terms and b) forcing them to change their definitions, usually through bite-the-bullet scenarios. Once they swapped over, the rest of the debate was easy. The fundamental problem in discussing objective truth is linguistic. (God, I hate this crap now. Philosophy is the worst.)
Could OpenAI and HuggingFace be making the whole thing up? Sure, and it wouldn't surprise me. They don't need to, though, for this to be a load of crap.
Take HuggingFace's statement. The statement says, "A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration)".
This initially sounds like an access control failure to me, such as an exposed API that doesn't properly authenticate. Would making a request to an improperly authenticated API count as abuse, particularly if the LLM had access to API docs? Would it count as a breach? I imagine there are reasonable differing opinions.
As others have pointed out, this whole thing could be a minor whoopsie-doodle reframed to sound much more grandiose for marketing purposes because of how easy it is to be "technically true."