Remote
security architect, former pentester, Luddite
simracing, history books, cloudspotting
married with children, breaking bad
0
Followers
0
Following
21
Posts
Joined November 06, 2022
GoodReads:
Posts
“The agent [..] attempted to break out of its isolated testing environment at OpenAI around July 9. The intrusion at #Hugging Face [..] began [..] on July 11 and lasted until July 13. It took several more days for #OpenAI to realize its agent was behind the hack [..] well after the threat was contained and the FBI was alerted.” https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/
IMHO amazing level of incompetence and negligence.
Open post
Replying to
@orbman@infosec.exchange
Even NBC News anchors came to a similar conclusion [3:40+] https://www.haystack.tv/v/openai-ai-models-rogue-hacked-tech-company-test
0
0
0
0
Open post
Replying to
@orbman@infosec.exchange
@0x00string@infosec.exchange especially since it seems to be a well established fact that this new model loves to cheat all the time https://infosec.exchange/@0xabad1dea/116821271336330461
0
0
0
0
Open post
Replying to
@0x00string@infosec.exchange
@0x00string@infosec.exchange I could understand you let it run through the night without oversight. I could not understand nobody would check its progress the next morning not noticing it is already ripping through an infrastructure of a 3rd company.
0
2
0
0
Open post
Replying to
@orbman@infosec.exchange
I wouldn’t be surprised if this was all just a clever marketing stunt done in cooperation by both companies involved. HF showcased that you can use their product for response and recovery from such attacks, and OAI gets some response to Anthropic’s Mythos “too dangerous” story.
0
2
0
0
Open post
Seriously, I can’t get my head around the fact that #OpenAI would leave HuggingFace in the dark for almost a week before disclosing “oops sorry, we did it.” I don’t think oAI would run such lab experiment without continually tracking its progress, and somehow not notice it had already jumped out of the sandbox.
0
2
0
0
Open post
Replying to
@agentpalisade@mastodon.social
@agentpalisade@mastodon.social They did, though not at great detail: “A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker. From there, the actor escalated to node-level access, harvested cloud and cluster credentials, and moved laterally into several internal clusters over a weekend.” https://huggingface.co/blog/security-incident-july-2026
0
0
0
0
Open post
Replying to
@WPalant@infosec.exchange
@WPalant@infosec.exchange You are calling people with different opinions assholes? Why don’t you put content warnings on your own disrespectful political opinions?
1
0
0
0
Open post
Replying to
@SteveBellovin@infosec.exchange
@SteveBellovin@infosec.exchange @mattblaze@federate.social White smoke is OK, though
0
0
0
0
Open post
It only took ten training examples for the code output by the [large language] model to become reliably vulnerable to remote code execution, even for novel prompts and domains [..]. And the larger the model, the easier it was to poison. https://www.theregister.com/ai-and-ml/2026/07/16/researcher-poisons-open-weight-ai-model-for-under-100/5273880
0
0
0
0
Open post
TL;DR Chat Control 1.0 = voluntary scanning loophole. Platforms may scan private messages without warrants under "child safety" cover. E2EE was supposed to remain out of scope but watch for Chat Control 2.0 which tries to mandate client-side scanning anyway. #chatcontrol
0
0
0
0
Open post
0
0
0
0
Open post
Replying to
@20002ist@thepit.social
@20002ist@thepit.social I love this one from the thread, absolutely hilarious
0
0
0
0
Open post
If you are a parent of underage children, get a subscription to some porn magazines and leave them on the kitchen table, so your children have less incentive to go on YouTube or play Roblox and face something much worse.
0
0
0
0
Open post
Replying to
@lupinia@infosec.exchange
@lupinia@infosec.exchange If the choice is between children being routinely exposed to heroin or everyone else being forced to drink two beers every morning, the beers seem like the reasonable trade-off. I know it's a flawed comparison, but no other options seem to be on the table right now.
0
0
0
0
Open post
I'm no proponent of age controls, but seeing the shockingly disgusting content being pushed to children on #YouTube or #Roblox, they're starting to look like a reasonable mitigation. #agecontrol
0
2
0
0
Open post
Replying to
@orbman@infosec.exchange
Isn’t it actually same for developers when they are doing code reviews?
0
0
0
0
Open post
“In an experiment involving dozens of companies with A.I. employees, the researchers found that managers tended to vet documents less carefully when told an A.I. employee had produced them. The managers missed errors that other managers caught when told they were vetting the work of a human.”
https://www.nytimes.com/2026/06/29/business/artificial-intelligence-workplace-consequences.html?unlocked_article_code=1.t1A.OIgD.p9rsXP_cvC0Q&smid=url-share
0
1
0
0
Open post
Replying to
@Catvalente@wandering.shop
0
0
0
0
Open post
Replying to
@augieray@mastodon.social
@augieray@mastodon.social The United States Naval Academy considers HC a “chemical weapon”.
0
2
1
0
Remote instance
infosec.exchange
Open on original server